Privacy Policy
Last updated: 10 August 2026
ActivityProof("we") respects your privacy. This policy describes what we collect when you use https://activityproof.site and how we use it.
1. Data we collect
- Account data: email, authentication identifiers (Firebase Auth), optional display name or photo from sign-in providers, and your public profile slug if you set one.
- Project data: product display name, optional website URL, theme preference, status mode settings, and snapshot fields derived from GitHub (such as last commit time, resolved status label, and sync errors).
- GitHub connection: installation ID, repository full name, default branch, and commit activity metadata needed to compute shipping status. We do not store your full repository source code.
- Billing data: plan status and Stripe customer identifiers. Card details are processed by Stripe; we do not store full card numbers.
- Technical data: IP address, browser type, cookies needed for sessions and CSRF protection, and security logs (rate limits, audit events).
2. How we use data
- Provide authentication, dashboard, and live SVG embeds
- Sync repository activity and refresh badge status
- Process one-time payments and fulfill plan entitlements
- Send transactional email (magic link, password reset, receipts)
- Protect the service against abuse and improve reliability
- Comply with legal obligations
Public embeds only expose the badge image and the link you configure (your website or an ActivityProof referral URL). Visitors who load the SVG do not receive your email address.
3. Subprocessors
We use trusted providers to run ActivityProof. Some are based outside the EEA/UK, so data may be transferred under appropriate safeguards (such as Standard Contractual Clauses where required).
- Google Firebase: authentication and Firestore database
- GitHub: repository metadata via the GitHub App you install
- Stripe: payment processing
- Resend: transactional email
- Vercel: hosting and edge delivery of the site and embeds
4. Cookies and sessions
We use essential cookies for signed-in sessions and CSRF protection. We do not run third-party advertising trackers on the core product. Hosting providers may collect standard request logs.
5. Retention
We keep account and project data while your account is active. You may ask us to delete your account. We may retain limited billing and security records as required for legal, tax, or abuse prevention purposes.
6. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you,
- request correction of inaccurate data,
- request deletion,
- object to or restrict certain processing,
- receive a portable copy of data you provided.
Contact support@activityproof.site to exercise these rights. You may also uninstall the GitHub App or disconnect a repository from the dashboard.
7. Children
ActivityProof is intended for adults building software products. We do not knowingly collect data from children under 16.
8. Changes
We may update this policy. The "Last updated" date at the top will change when we do. Material changes may also be noted by email or in-product notice.
9. Contact
Privacy questions: support@activityproof.site. See also our Terms of Service.