Data ProofLock processes
When installed, GitHub sends repository and installation identifiers, repository names, pull request numbers and commit identifiers, review usernames and states, changed file paths, and subscribed webhook metadata. ProofLock reads repository policy and the minimum GitHub API data needed to publish an integrity decision.
Why the data is processed
The data is used only to authenticate events, classify protected changes, verify eligible current-head approval, publish Check Runs, prevent duplicate processing, and recover failed evaluations.
Storage and retention
ProofLock runs on Cloudflare Workers, Queues, and Durable Objects. Installation tokens are held in memory and expire. Evaluation state is retained as needed for ordering, deduplication, and reliability. Failed evaluations may remain in protected dead-letter storage until an operator redrives or discards them.
ProofLock does not sell personal data. The website does not set analytics cookies or use third-party advertising trackers. Standard edge and service logs may process network and request metadata for security and operations.
Service providers
GitHub supplies App events and API data. Cloudflare provides compute, queueing, durable state, routing, and operational telemetry. Their processing is also governed by their respective terms and privacy policies.
Your choices
Repository administrators can restrict the installation to selected repositories or uninstall ProofLock in GitHub at any time. For access, correction, or deletion requests relating to retained operational data, contact info@haya.company.