Workspace / Privacy policy
Sign in
MIGREADY

Privacy policy

Policy version: 2026-09-19

Who operates the service

migready is the working name of this service. Contact the migready operator on GitHub for privacy questions or requests. This beta draft will be updated with the legal operator's identity before paid launch.

Account and operational information

We store GitHub account and installation identifiers, repository configuration, workspace access roles, encrypted login credentials, billing identifiers and subscription state, and aggregate usage counters. If you enable email notifications, we store the address and preferences needed to deliver them. Service monitoring uses aggregate queue and availability information and does not collect SQL or analysis payloads.

Zero retention — default

SQL, source contents, findings, PR payloads, commit identifiers and per-analysis context are processed in memory and are not saved by this service in zero-retention mode. We retain opaque run/job IDs for deduplication and aggregate usage for billing. Those IDs have no stored SQL, outcomes, timestamps, repository names, or PR details attached. Analysis payloads are excluded from application logs and notification emails. After interruption, current work may be reconstructed from GitHub; automatic retries reuse the original usage receipt.

Optional report history

If a workspace enables history, encrypted findings and check metadata are retained for up to 30 days. Switching to zero retention purges that workspace's analysis records from the active database and clears SQLite free pages and its write-ahead log. Infrastructure backups, if enabled, expire according to the backup schedule; deleting active data does not retroactively erase existing backup snapshots. Contact us for the current backup schedule before enabling history if this affects your requirements.

How information is used

Account and configuration information enables authentication, authorization, migration checks, billing, recovery, and support. Contact details are used for requested account, trial, usage, billing, and service notifications. We do not use migration contents for advertising or model training. Processing grounds and any required international-transfer provisions will be finalized for the legal operator before paid launch.

Service providers and external records

GitHub authenticates users, hosts source and workflows, and stores the check results we publish. GitHub Actions artifacts remain on GitHub according to repository settings; generated workflows request one-day artifact retention. Railway hosts the application and persistent account/configuration database. Stripe processes payments and maintains its own billing records; card details are entered on Stripe and are not stored by migready. Resend delivers transactional notifications and processes recipient addresses and message delivery records. These providers apply their own retention policies; zero retention does not delete their records. Hosting and network providers may retain routine access metadata.

Cookies and preferences

An essential secure session cookie keeps you signed in for up to eight hours. A local browser preference remembers your light, dark, or system theme. The interface uses system fonts. We do not install advertising cookies or session replay.

Security and retention of other records

Credentials and retained reports are encrypted in the application database. Access is checked against GitHub and workspace roles. Sessions expire automatically. Account/billing notifications are retained for up to 90 days; operational job records are normally removed after seven days once no longer pending. Usage counters, opaque deduplication IDs, and necessary account/billing records remain while needed to operate the account, prevent duplicate processing, or meet applicable obligations.

Your choices and requests

Workspace owners can change retention and notification preferences. You can remove GitHub App access in GitHub and cancel billing through Stripe. Uninstalling the app does not cancel a subscription automatically. Contact the migready operator on GitHub to request account deletion, access to your information, or correction. We verify authority before fulfilling requests and explain any records that must remain. Do not send repository contents or secrets in support requests unless separately agreed.

Policy changes

The version date appears above. We will communicate material changes through the service or account contact channels.