Legal
Privacy Policy
Last updated 28 August 2026
Kuppit LLC ("Kuppit", "we") operates the Kuppit Cloud application platform. This policy describes what we collect while Kuppit is in private alpha, why we collect it, and who else processes it. It applies to kuppit.run, app.kuppit.run and applications you deploy through us.
What we collect
Your identity
Kuppit only supports signing in with GitHub. When you sign in we request the read:user and user:email scopes, and we store the resulting account identifier, your name, and your email address. We do not receive or store your GitHub password.
Your repositories
If you install the Kuppit GitHub App, we receive the installation's identifier and metadata about the repositories you grant it access to. When you deploy, we read the source of the selected repository in order to build it. We store the commit identifiers, branch names and commit messages associated with each deployment.
Your configuration
Environment variables and secrets you configure for a service are stored so we can supply them to your running application. Values marked as secret are encrypted at rest and are not returned to the browser after they are saved.
Operational data
- Build and runtime logs produced by your applications.
- Deployment history, status and timings.
- Resource usage measurements used to show you what your applications consume.
- Domains you attach and their verification state.
Website analytics
kuppit.run uses Plausible Analytics, which is cookieless and does not collect personal data or track visitors across sites. We use it to see which pages are read and which links are clicked. We do not run advertising or cross-site tracking anywhere on Kuppit.
Cookies
app.kuppit.run sets a session cookie when you sign in. It is required for the application to work and is not used for tracking or advertising. The marketing site sets no cookies.
Who else processes your data
Kuppit is built on third-party infrastructure. These subprocessors handle data on our behalf:
- Google Cloud — compute, container builds, image storage, databases and logging.
- Cloudflare — DNS, TLS and routing for deployed application hostnames.
- GitHub — authentication and source access.
- Stripe — payment processing, where billing is enabled. Kuppit does not store card details.
- Plausible Analytics — marketing site analytics.
How long we keep it
Account, project and configuration data is retained while your account exists. Logs and usage measurements are retained for a limited operational period and then discarded. When you ask us to delete your account, we delete your projects, configuration and secrets; backups and billing records required for accounting are retained for as long as the law requires.
What we do not do
- We do not sell your data.
- We do not use your source code to train machine learning models.
- We do not read your secrets except to supply them to your running application.
Your choices
You can revoke the Kuppit GitHub App's access from your GitHub settings at any time, which stops us reading your repositories. You can ask us to export or delete your data by getting in touch.
Security
Secrets are encrypted at rest. Access to production systems is limited to Kuppit personnel who need it. Kuppit is in private alpha and has not undergone a third-party security audit; you should weigh that before deploying anything sensitive.
Changes
Kuppit is early and this policy will change as the product does. Material changes will be reflected in the "last updated" date above.
Contact
Questions about this policy can be raised through the Kuppit GitHub organisation while we are in private alpha.