Privacy.
What is collected, and what is not.
Short, because there is little to say, and complete, because the law rightly asks for completeness.
No cookies. No trackers. No third-party requests.
This section is about these pages only. The App and the billing system are separate and are described below, because a sentence that is true of the website and false of the product is exactly the kind we will not write.
These pages are static files; fonts are served from this domain. Nothing on this site sets a cookie, loads a script from another origin, or sends a beacon anywhere. You can verify all three by opening the network tab, which is why the claim is worth making.
What we do look at, stated precisely. Our hosting provider processes IP addresses in standard server logs to deliver the site and defend it, on the lawful basis of legitimate interests, retained on the provider's rolling schedule. We read the aggregate counts those logs already produce: how many requests each page received. That is server-side, needs no code on the page, and records nothing that would not exist if we never looked.
We also use Google Search Console, which tells us which search queries surfaced this site and whether our pages are indexed. It reports on Google's own index rather than on you, and it gives us no information about a visitor that Google did not already hold from operating a search engine.
The earlier wording here said "no analytics", which was true of trackers and imprecise about server logs we have always had. We do not enrich, profile, follow or sell anybody, we cannot connect one request to another, and there is no other recipient for site traffic. That is a narrower claim than the one it replaces, and it has the advantage of surviving scrutiny.
If you write to us, we keep the thread.
Email to an arcifact.io address is processed on the lawful basis of legitimate interests, or of contract where you engage us, used to reply and to run the engagement, retained while the relationship and legal duties require, and shared with no one beyond our email provider acting as processor. We do not add you to lists.
If you install Gate, we read workflows and check results.
Installing the GitHub App grants read access to your workflow files, pull request metadata and check results, and write access limited to posting our own check run. We use that to compute what your required checks establish, on the lawful basis of contract, and we keep the analysis and the identifiers needed to attach it to the right commit. We do not clone your repositories and we do not read your source files. Being precise about what enforces that: GitHub's contents permission is repository-wide and the platform does not confine a token to selected paths, so what limits us is our own client, which is written and tested to fetch the workflow directory and nothing else. Private repository contents are never used as training data, which is a contractual and organisational control rather than a platform one.
It also looks for a file named WARRANT, at the repository root or in .github, in which a repository can declare what its own checks are meant to establish. That file is optional and most repositories do not have one; we look, and if it is absent we move on. Those five paths, the workflow directory and the four WARRANT locations, are the only contents we request.
Most of what we hold expires on its own. Cached analysis carries a time to live measured in hours, so it is gone without anybody doing anything, and we keep no database of your repository contents. The exception is a seal, which is a record of a warrant you approved: that persists because it is the thing a later analysis is compared against, and it belongs to you. Anything still held is deleted within thirty days of you uninstalling or terminating, except where we must keep something for legal or accounting reasons. Uninstalling stops all analysis immediately. GitHub, Inc. is a processor for this data in the sense that it is where the data comes from and where our check runs go; its own handling is governed by your agreement with GitHub.
Stripe takes the money. We never see your card.
If you subscribe, Stripe Payments Europe processes your payment on our behalf as a controller in its own right for fraud and regulatory purposes, and we receive your billing name, email, address, country and the last four digits of the card. We never see or store the card number. We keep invoices for the six years UK accounting law requires, on the lawful basis of legal obligation, and use your billing email to send receipts and renewal notices, on the basis of contract.
It plays a message and hangs up.
Our support number is operated by Twilio Ireland. Calling it plays a recorded message directing you to email; we do not record calls, take messages or answer live. Twilio holds standard call metadata, the number you called from and the time, on its own retention schedule, on the lawful basis of legitimate interests in operating a published support line. We do not use it to contact you.
Your committers did not install us. We still see their names.
When Gate reads a pull request and its check results, it sees the logins of the people who opened it and whose jobs ran. Those people did not install the App and have no relationship with us, which is exactly the case UK GDPR Article 14 exists for, so it is worth being plain about.
We hold a GitHub login and the identifiers needed to attach an analysis to the right commit. We do not hold email addresses, we do not build a profile of anybody, and we do not contact them. The lawful basis is legitimate interests, ours and the installing organisation's, in analysing that organisation's own build pipeline, which is a narrow and expected use of data already visible to everybody with access to the repository. Anybody named in an analysis has the rights in § 09 and can write to us directly.
Controller for the account. Processor for the analysis.
For your billing details, your correspondence with us and this website, we decide what happens and we are the controller. For the repository data the App reads on your instruction, you decide and we act as your processor: we process it only to provide the service, only on your documented instructions, under a duty of confidence, with the processors in § 08 and no others, and we return or delete it when you leave. If you need this as a signed data processing agreement, write to legal@arcifact.io and we will send one.
Every subprocessor, what it does, and where.
This page previously said "four processors and no others" while naming GitHub and our email provider elsewhere on it. A count is easy to write and easy to falsify, so here is the table instead.
Cloudflare, Inc. · serves this site and the webhook
receiver · IP addresses and request metadata · global
edge · provider's rolling log schedule
Modal Labs, Inc. · runs the analyser · workflow
files and commit identifiers · United States · for the
duration of an analysis
GitHub, Inc. · the source of the data and where our check
runs go · repository content and pull request metadata ·
United States · governed by your own agreement with GitHub
Stripe Payments Europe, Ltd. · payment · billing
name, email, address, country, card last four · Ireland and
United States · six years, UK accounting law
Proton AG · our email · correspondence you send us
· Switzerland · until you ask us to delete it
Twilio Ireland, Ltd. · the support telephone number
· calling number and time · Ireland · provider's
schedule
Each is bound by a data processing agreement, and by the UK International Data Transfer Addendum or standard contractual clauses where data leaves the UK. Adding one is a change to this page and we will tell account holders before it takes effect. We do not sell data and we do not share it for advertising.
UK GDPR applies, and we act like it.
ARCIFACT LTD, registered in England, is the data controller. You have the rights of access, rectification, erasure, restriction, objection, and portability, and the right to withdraw any consent you gave. Write to legal@arcifact.io; we answer within a month. If we get it wrong you may complain to the Information Commissioner's Office at ico.org.uk. Last revised August 2026.
Four short ones, answered because the law asks.
Is any of this required? Giving us billing details is a contractual necessity: without them we cannot take payment or issue a VAT invoice, and there is no subscription. Everything else is optional, and you can use the free public analysis without giving us anything.
Do you make automated decisions about people? No. Gate analyses configuration, not people. Nothing we do produces a legal or similarly significant effect on an individual, and there is no profiling.
What about children? This is a service sold to companies. It is not directed at children and we do not knowingly process their data. If you believe we hold a child's data, write to us and we will delete it.
Will this page change? Probably, as the product does. The revision date at the foot of § 09 is the one that counts, and where a change materially affects how we handle your data we will tell account holders by email rather than changing this quietly.
Encrypted in transit, least privilege, and a report within 72 hours.
Everything is served over TLS. The App holds the narrowest GitHub permissions that let it work: read on contents, pull requests and actions, and write only to post its own check run. Credentials are held as platform secrets rather than in code or configuration, and the analyser is rebuilt from source on each deployment. We do not run a database of your repository contents.
If we suffer a breach affecting personal data we will report it to the Information Commissioner's Office within 72 hours where the law requires, and we will tell you directly, without waiting to be asked, where the risk to you is high. We would rather tell you about a breach that turned out to be minor than have you learn about a serious one from somebody else.