Legal

Privacy & GDPR

What data ForkDeploy holds, why it holds it, and the rights you have over it. In plain language, and honest about being a small EU beta.

Last updated: 6 September 2026

The basics

Who runs this, and how to reach us.

ForkDeploy is a personal platform operated by TM Dev, an individual developer based in Belgium. It is the data controller for the information described here. You can see more about the person behind it at tm-dev.be.

For anything about your data, such as access, deletion, corrections, or questions, email gdpr@tm-dev.be. This is a small project, so requests are handled personally, normally within 30 days.

What we hold

What we collect, and why.

We keep the data needed to run your account and your deployments. We collect nothing for advertising, and we never sell it. Here is the full list.

Account details

Your email (required), an optional display name, and your password stored only as a salted hash, never in plain text. We use these to create and run your account.

Why we're allowed to: Contract. We need it to give you an account.

Sign-in session

A session token tied to your account, so you stay logged in between visits. Held in an essential cookie (see Cookies below).

Why we're allowed to: Contract. You cannot use a logged-in dashboard without it.

GitHub connection

If you connect GitHub, we store your GitHub identity and an access token (encrypted at rest) so ForkDeploy can read the repositories you choose to deploy. Nothing else in your GitHub account is touched.

Why we're allowed to: Your consent. You choose to connect, and you can disconnect any time.

Your projects and deploy logs

The project and service configuration you create, and the build/deploy logs the platform produces while running them.

Why we're allowed to: Contract. This is the service doing its job.

Your secrets and environment values

Secrets you add are encrypted at rest and only injected into the services you explicitly choose. They never appear in logs or the API in plain text.

Why we're allowed to: Contract. We need it to run your apps the way you configured them.

Visual API projects

If you use a Visual API (mocked-API) project, the canvas and mock definitions you build are stored as your project content, under the same encryption and retention as any other project.

Why we're allowed to: Contract. This is the service doing its job.

Activity log

A record of key actions (who did what, and when) tied to your email, kept as a security and audit trail for your own projects.

Why we're allowed to: Legitimate interest. It keeps the platform safe and accountable.

Feedback you send

Anything you submit through the feedback form, so we can improve the platform.

Why we're allowed to: Legitimate interest. We act on what you tell us.

Your IP address (briefly)

When you sign in or register, your IP is used in memory to rate-limit repeated attempts against abuse. It is not written to a database and not kept afterwards.

Why we're allowed to: Legitimate interest. It prevents brute-force attempts and abuse.

No billing data yet. ForkDeploy takes no payments during the beta, so it holds no card numbers or billing details. When paid plans launch, the billing information kept and the payment processor used will be listed here first, and our refund policy explains how cancellations and returns work.

Cookies

Only the cookies the site can't work without.

Session cookie

Lifetime

~30 days

What it's for

Keeps you signed in. HttpOnly, SameSite=Lax, and Secure over HTTPS.

GitHub-connect cookie

Lifetime

~10 minutes

What it's for

Secures the GitHub linking step against tampering, then expires on its own.

No tracking, no banner. We use no analytics, advertising, or third-party tracking cookies. Because the only cookies are strictly necessary to run the site and keep you signed in, there is nothing to consent to beyond that, so you won't find a cookie pop-up here.

Who else is involved

Who we share data with.

Running a hosting platform means a few trusted services handle parts of the job. Each one only gets what it needs for its task. We never sell your data.

GitHub

Sign-in and reading the repositories you choose to deploy.

When you sign in with GitHub or connect a repo.

Google (Gemini AI)

Generates plain-language explanations of failed deploys. We send the recent deploy logs, your repo’s root file names, and optionally selected files.

Only if you turn on AI explanations. Off by default; you can also use your own API key. Off means nothing is sent.

Let's Encrypt

Issues the TLS certificates for your URLs and custom domains.

Your domain names appear in public certificate-transparency logs, which is standard for any HTTPS site.

Cloudflare

DNS resolution only (DNS-only mode). It does not proxy or inspect your traffic.

For resolving platform and custom domains.

EU hosting provider

Runs the servers the whole platform lives on, inside the EU.

Always. This is where your data is processed and stored.

Transactional email (things like account notices) is minimal during the beta. If a dedicated email provider is added later, it will be listed here first.

Care

Where it lives, and how long we keep it.

Where it lives, and how it's protected

Everything runs on servers in the EU. Secrets and access tokens are encrypted at rest, traffic is encrypted with TLS, and every project is isolated from every other. The security page covers the how in more detail. Platform admins can see project metadata and resource usage across the platform to manage capacity and provide support, but secret values stay masked to anyone who isn't the project owner. See our permissions page for details.

How long we keep it

Account data is kept while your account exists. Deleting a project tears down its running services; deleting your account removes your profile, sessions, settings, secrets and projects. A minimal record (an internal id and a reason) is retained after deletion to prevent abuse and keep the audit trail honest. Logs are kept only for a limited time.

Your rights

What the GDPR gives you.

To use any of these, email gdpr@tm-dev.be. If you believe we've mishandled your data, you also have the right to complain to your data protection authority. In Belgium, that is the Gegevensbeschermingsautoriteit (APD/GBA).

Two last things

Children, and changes to this page.

Not for children

ForkDeploy is a tool for developers and is not intended for anyone under 16. We don't knowingly collect data from children.

Changes to this policy

As the platform grows, this page will be updated. The date at the top always reflects the latest version. Significant changes will be called out clearly.

Opens your browser's print dialog. Choose “Save as PDF” as the destination.