Legal
Privacy policy
Last updated 30 September 2026
This policy explains what KaribaCore collects when you use karibacore.com, why, and how long it is kept. KaribaCore, operated from Ireland, runs the service and decides how this information is used. You can reach us at [email protected].
What we collect
- Your GitHub identity. When you sign in, GitHub gives us your user ID, username, display name and avatar address. We do not receive or store your GitHub password.
- Workspace records. Workspace names, members and their roles, and invitations, which include the GitHub username invited.
- Repository and deployment records. The repositories you import, branch names, commit identifiers, deployment history, and build and runtime output.
- Your code. We read the repositories you choose in order to build them, and we keep the built application images needed to run and roll back your releases.
- Configuration. Environment variables, stored encrypted, and the domains you add.
- Activity records. A record of actions taken in a workspace, such as deployments and access changes.
- Technical information. Your IP address is processed to limit request rates and protect the service.
We do not use analytics or advertising trackers, and the pilot does not collect payment details.
Why we use it
- To sign you in and keep your workspace separate from others
- To build, run and route your applications
- To show you what happened when something fails
- To keep the service secure and to answer support requests
Who else handles it
- GitHub provides sign-in and repository access. Microsoft Graph processes transactional emails when you request an invitation email, verify an address or enable notifications. We store your notification address, verification status and preferences. In-app notifications and email delivery records are retained for 30 days. Message payloads are encrypted while queued and removed after a final delivery result.
- Cloudflare carries traffic to the service and to hosted applications, and issues certificates for custom domains.
We do not sell your information.
How long we keep it
- Build output: 30 days
- Runtime output: 7 days
- Sign-in sessions: up to 8 hours, or until you sign out
- Other records: while your account or workspace exists
If a workspace is suspended, its data is retained until it is reactivated or you ask us to delete it.
Your choices
You can ask for a copy of your information, for a correction, or for deletion, by emailing us. If you are in the European Economic Area or the United Kingdom, the General Data Protection Regulation gives you these rights and others, including the right to object to some processing and to complain to a supervisory authority. Our supervisory authority is the Data Protection Commission in Ireland.
Where it is processed
The service runs on infrastructure operated from Ireland. GitHub and Cloudflare process information in their own locations under their own terms.
Applications you host
If your application collects information from its own visitors, you are responsible for that information and for telling those visitors how you use it.
Changes
When this policy changes, we will update the date at the top of this page.
Contact
Questions about this page: [email protected].