Legal
Privacy & GDPR
What data ForkDeploy holds, why it holds it, and the rights you have over it. In plain language, and honest about being a small EU beta.
Last updated: 6 September 2026
The basics
Who runs this, and how to reach us.
ForkDeploy is a personal platform operated by TM Dev, an individual developer based in Belgium. It is the data controller for the information described here. You can see more about the person behind it at tm-dev.be.
For anything about your data, such as access, deletion, corrections, or questions, email gdpr@tm-dev.be. This is a small project, so requests are handled personally, normally within 30 days.
What we hold
What we collect, and why.
We keep the data needed to run your account and your deployments. We collect nothing for advertising, and we never sell it. Here is the full list.
Account details
Your email (required), an optional display name, and your password stored only as a salted hash, never in plain text. We use these to create and run your account.
Why we're allowed to: Contract. We need it to give you an account.
Sign-in session
A session token tied to your account, so you stay logged in between visits. Held in an essential cookie (see Cookies below).
Why we're allowed to: Contract. You cannot use a logged-in dashboard without it.
GitHub connection
If you connect GitHub, we store your GitHub identity and an access token (encrypted at rest) so ForkDeploy can read the repositories you choose to deploy. Nothing else in your GitHub account is touched.
Why we're allowed to: Your consent. You choose to connect, and you can disconnect any time.
Your projects and deploy logs
The project and service configuration you create, and the build/deploy logs the platform produces while running them.
Why we're allowed to: Contract. This is the service doing its job.
Your secrets and environment values
Secrets you add are encrypted at rest and only injected into the services you explicitly choose. They never appear in logs or the API in plain text.
Why we're allowed to: Contract. We need it to run your apps the way you configured them.
Visual API projects
If you use a Visual API (mocked-API) project, the canvas and mock definitions you build are stored as your project content, under the same encryption and retention as any other project.
Why we're allowed to: Contract. This is the service doing its job.
Activity log
A record of key actions (who did what, and when) tied to your email, kept as a security and audit trail for your own projects.
Why we're allowed to: Legitimate interest. It keeps the platform safe and accountable.
Feedback you send
Anything you submit through the feedback form, so we can improve the platform.
Why we're allowed to: Legitimate interest. We act on what you tell us.
Your IP address (briefly)
When you sign in or register, your IP is used in memory to rate-limit repeated attempts against abuse. It is not written to a database and not kept afterwards.
Why we're allowed to: Legitimate interest. It prevents brute-force attempts and abuse.
Cookies
Only the cookies the site can't work without.
Session cookie
~30 days
Keeps you signed in. HttpOnly, SameSite=Lax, and Secure over HTTPS.
GitHub-connect cookie
~10 minutes
Secures the GitHub linking step against tampering, then expires on its own.
Who else is involved
Who we share data with.
Running a hosting platform means a few trusted services handle parts of the job. Each one only gets what it needs for its task. We never sell your data.
GitHub
Sign-in and reading the repositories you choose to deploy.
When you sign in with GitHub or connect a repo.
Google (Gemini AI)
Generates plain-language explanations of failed deploys. We send the recent deploy logs, your repo’s root file names, and optionally selected files.
Only if you turn on AI explanations. Off by default; you can also use your own API key. Off means nothing is sent.
Let's Encrypt
Issues the TLS certificates for your URLs and custom domains.
Your domain names appear in public certificate-transparency logs, which is standard for any HTTPS site.
Cloudflare
DNS resolution only (DNS-only mode). It does not proxy or inspect your traffic.
For resolving platform and custom domains.
EU hosting provider
Runs the servers the whole platform lives on, inside the EU.
Always. This is where your data is processed and stored.
Transactional email (things like account notices) is minimal during the beta. If a dedicated email provider is added later, it will be listed here first.
Care
Where it lives, and how long we keep it.
Where it lives, and how it's protected
Everything runs on servers in the EU. Secrets and access tokens are encrypted at rest, traffic is encrypted with TLS, and every project is isolated from every other. The security page covers the how in more detail. Platform admins can see project metadata and resource usage across the platform to manage capacity and provide support, but secret values stay masked to anyone who isn't the project owner. See our permissions page for details.
How long we keep it
Account data is kept while your account exists. Deleting a project tears down its running services; deleting your account removes your profile, sessions, settings, secrets and projects. A minimal record (an internal id and a reason) is retained after deletion to prevent abuse and keep the audit trail honest. Logs are kept only for a limited time.
Your rights
What the GDPR gives you.
- ✓ Access: get a copy of the personal data we hold about you.
- ✓ Rectification: have inaccurate details corrected.
- ✓ Erasure: have your data deleted (the “right to be forgotten”).
- ✓ Portability: receive your data in a portable form.
- ✓ Restriction and objection: limit or object to certain processing.
- ✓ Withdraw consent: for anything based on consent, such as the GitHub connection or AI explanations.
Two last things
Children, and changes to this page.
Not for children
ForkDeploy is a tool for developers and is not intended for anyone under 16. We don't knowingly collect data from children.
Changes to this policy
As the platform grows, this page will be updated. The date at the top always reflects the latest version. Significant changes will be called out clearly.
Opens your browser's print dialog. Choose “Save as PDF” as the destination.