Privacy policy
Last updated: September 7, 2026
This policy covers the gocov.dev website and the hosted
gocov coverage service, including the gocov GitHub App and
Bitbucket integration ("the service"). gocov is also available as
self-hosted open-source software; when you run it on your own
infrastructure, we receive no data at all and this policy does not apply.
What we collect
- Waitlist signups (retired): while the early-access
form was live we stored the email address and answers submitted through it
(forge, team size, current tool, referral source). The form has been
removed and we no longer collect this; entries already stored can be
deleted on request — see Retention & deletion below.
- Account data: when you sign in with Bitbucket, GitHub
or GitLab, we store your name, email address, forge account ID and the
list of workspaces/organizations you belong to, as provided by the
forge's OAuth API.
- Coverage data: coverage reports your CI uploads —
file paths, line coverage counts, commit SHAs, branch and pull request
identifiers. Source code is fetched from your forge on demand to render
annotated views and is not permanently stored.
- Integration credentials: tokens you provide and
OAuth grants you authorize (encrypted at rest) so the service can post
statuses, checks and pull request comments on your behalf.
- Operational logs: standard server logs (IP address,
requested URL, timestamp), kept briefly for security and debugging.
- Usage analytics: page views on this website and in
the hosted app, and clicks on the sign-up links, sent to
PostHog's EU cloud. No
cookies or browser storage are used for this, and browsers that send Do
Not Track are left out. On this website,
visitors are counted by a hash of IP address, browser and site under a
salt PostHog rotates daily and deletes, so no lasting identifier exists;
IP addresses themselves are discarded on arrival. In the hosted app,
signed-in users are identified by their numeric gocov account id, never
by email. On the sign-in and workspace setup pages of the hosted app we
also record the screen as a session replay so we can see where setup
goes wrong; every input is masked, the upload token is blocked from the
recording, and no coverage report, upload or source page is ever
recorded. Replays are kept for 30 days.
What we don't do
- We do not sell your data or share it with advertisers.
- We do not use tracking cookies. The only cookie is the session
cookie that keeps you signed in; analytics runs without one.
- We do not read or retain your source code beyond rendering coverage
views you request.
Where data lives
The website runs on Cloudflare. The hosted service runs on
Amazon Web Services. Coverage data and account data are stored in the
service's database and are accessible only to the workspaces they belong
to. Usage analytics are processed by PostHog in the EU.
Retention & deletion
Coverage uploads are kept while your workspace is active. If you remove
a repository or workspace, its data is deleted. You can request deletion of
your account, workspace or waitlist entry at any time by emailing
[email protected] — we honor requests
within 30 days.
Your rights
You may request a copy of the personal data we hold about you, ask us to
correct it, or ask us to delete it. Contact
[email protected].
Changes
If this policy changes materially, we will note it here and update the
date above. Questions? [email protected].