Skip to content

Privacy policy

How PCX IT collects, uses, and protects personal data when you use Pushin.eu.

Last updated 5 September 2026

1. About PCX IT

PCX IT operates the website https://pushin.eu and the Pushin source-code hosting service. This policy explains how we collect, use, and protect personal data under the General Data Protection Regulation (GDPR) (EU) 2016/679.

PCX IT is the data controller. We are responsible for handling personal data safely and only for the purposes described in this policy.

2. Personal Data We Collect

We collect and process these categories of personal data:

  • Account and profile data: username, email address, display name, biography, avatar, and social links you choose to add.
  • Credentials: Password hashes and personal access token hashes are stored instead of the original secrets. We also store each TOTP secret, passkey credential ID and public key, SSH public keys, and credential usage timestamps. Access tokens used for an active external provider connection are encrypted at rest.
  • Repositories and Git data: repository settings, refs, commits, trees, blobs, tags, Git author and committer details, imports, mirrors, forks, and access permissions.
  • Collaboration data: issues, pull requests, comments, reviews, labels, reactions, mentions, assignments, and related activity history.
  • Continuous integration data: workflows, runner activity, job metadata, logs, caches, and artifacts.
  • Waitlist data: your email address, invitation status, and the proof-of-humanity profile link you submit.
  • External provider data: when you sign in through an external source-code hosting provider, we receive your provider login, numeric account ID, email address, and avatar. Imports and mirrors contain the repository data you ask us to retrieve.
  • Technical and security data: IP address, browser and operating-system details, request records, error information, security events, and timestamps needed to operate and secure the service.
  • Payment and invoice data: when paid plans become available, payment details will be collected and processed by our payment processor. We will store the processor customer reference, subscription plan, and invoice records, not full payment-card details.

We limit collection to data needed to provide, secure, and improve Pushin.

3. Data about people who are not Pushin users

A repository can contain personal data about people who do not have a Pushin account. This includes commit author and committer names and email addresses in pushed Git history, authors of issues or pull requests imported from another forge, and identities recorded in mirrored repositories.

We receive this data from Pushin users who push repositories or start an import or mirror. We process it on the basis of our legitimate interest in operating a version-control hosting service. Git history is designed to preserve authorship and cannot always be changed without rewriting the repository. Developers can reduce exposure by using a private commit email address.

If this section describes you, email get@pushin.eu to object or ask a question about the data.

4. Public by design

Public profiles, public repositories, and their public issues, pull requests, and comments are visible to anyone. Public repository data may be cloned, forked, and indexed by search engines or other services.

Deleting or changing public content on Pushin does not recall copies that other people already hold. Private repository content is available only to authorized users and the limited operational access described in our Terms.

5. How and Why We Process Your Data

We process personal data to:

  • Create and secure accounts and authenticate requests.
  • Host Git repositories and provide collaboration, import, mirror, and CI features.
  • Apply repository visibility and access controls.
  • Send account, security, waitlist, and collaboration notifications.
  • Provide support, moderate content, and enforce our Terms.
  • Diagnose errors, prevent abuse and fraud, and maintain service reliability.
  • Administer subscriptions and meet financial record-keeping duties when billing launches.

If we need to use data for a new purpose that is not compatible with the purpose for which it was collected, we will provide the required notice or seek consent first.

7. Data Sharing and Processors

We do not sell personal data or share it with third parties for their own marketing. Processors act only on our instructions and are bound by data-processing agreements under GDPR Article 28.

Pushin subprocessors
Provider Purpose Location Safeguard
Scaleway Hosting, databases, object storage, and transactional email European Union Article 28 agreement and EEA processing
Sentry Error reports, application logs, and diagnostic context EU region Article 28 agreement and EU-region project
Private Captcha Proof-of-humanity verification and waitlist abuse prevention European Union Article 28 agreement and EU verification endpoint

We may also disclose data when required by law or when necessary to establish, exercise, or defend legal claims. We will add the payment processor here before paid subscriptions launch.

8. International Data Transfers

We store and process personal data within the European Economic Area (EEA).

When you sign in through an external source-code hosting provider or import from one, we receive data from that provider. We do not send your Pushin data to external providers as part of repository imports or mirrors.

If our transfer practices change, we will update this policy and put appropriate safeguards in place before the change takes effect.

9. Data Retention

We keep data only as long as needed for the purpose described here or to meet a legal obligation.

Retention by category

  • Account and profile data is kept while the account is active and while an erasure request is handled.
  • Issues, pull requests, comments, reviews, and reactions remain until they are deleted or an applicable erasure request is completed, subject to the Git and third-party-copy limits below.
  • Repository metadata and Git objects remain until the repository owner deletes the repository. Git history can retain author details because changing them requires rewriting history.
  • CI log retention is selected in repository settings, with a maximum of 24 hours. Artifact retention is selected by the repository, with a maximum of 90 days. Expired data is removed by scheduled cleanup workers.
  • Unsaved, completed notifications are retained for 150 days. Saved notifications remain until unsaved or deleted. Processed notification events and completed email batches are retained for 30 days.
  • Waitlist entries remain while we administer an invitation. You may ask us to erase a waitlist entry under the rights process below.
  • Access and application logs, error reports, and backups follow operational rotation schedules and are removed when no longer needed for security, diagnosis, or recovery.
  • Invoice records will be retained for 7 years once paid plans are available, as required for tax and accounting records.

When data is no longer needed, we securely delete or anonymize it.

10. Your Rights Under GDPR

Depending on the circumstances, you may have rights of access, rectification, erasure, restriction, portability, and objection, as well as the right to withdraw consent and complain to a supervisory authority.

Deleting your account and data

Account deletion is not currently available as a self-service action. Please email get@pushin.eu to request erasure or account closure. We will respond within one month and explain any data we must retain or cannot remove.

Git history may contain author names and email addresses and cannot be changed without rewriting the repository. A private commit email address can reduce exposure in future commits. Erasure also cannot recall forks, clones, search indexes, mentions, or other copies held by third parties. Backup copies disappear through the normal backup rotation rather than immediately.

Access and portability

You can export repositories with git clone at any time. For a copy of other personal data, or to exercise another right, email get@pushin.eu.

11. Cookies and Tracking Technologies

Pushin sets only cookies required for security and sign-in state.

We do not use analytics or advertising cookies, so no consent banner is shown.

12. Security Measures

Pushin uses TLS in transit, access controls, hashed passwords and personal access tokens, encrypted stored external-provider credentials, and encrypted production storage for the on-disk Git pack cache and Git working data. Access to object storage is restricted to the service.

Accounts can use two-factor authentication with an authenticator app or passkey. No online service can guarantee absolute security, so please report suspected account or data exposure promptly.

13. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal or similarly significant effects about you.

14. Children's Privacy

Our services are only available to individuals who are 18 years of age or older.

We do not knowingly collect personal data from anyone under the age of 18. If you believe a person under 18 provided us with personal data, contact us and we will take appropriate steps to remove it.

15. Changes to This Policy

We may update this policy when our service, providers, or legal obligations change. For material changes, we will post the updated policy, change the date below, and provide an additional notice when appropriate.

Last updated: 5 September 2026

16. Contact Us

For questions about this policy or your personal data, contact:

PCX IT
Kwikstaartlaan 42, Box A6252
3704GS Zeist
The Netherlands
get@pushin.eu

Privacy contact

Peter Ullrich

get@pushin.eu

You may also complain to the supervisory authority where you live or work. A list is available on the European Data Protection Board website.