Privacy policy
Copier Update processes GitHub data to update repositories from the Copier templates they configure and to let account owners request updates.
Data processed
The App may process GitHub account identity, organization membership, installation and repository identifiers, repository names and settings, branches, pull requests, and repository file contents. It reads a repository's Copier answers file, clones the repository, and fetches the upstream template recorded by that file. Manual requests use GitHub OAuth to identify the requester and confirm personal-account ownership or organization-owner status.
Use and retention
Repository contents are held in an ephemeral GitHub Actions workspace while Copier computes an update. Resulting branches and pull requests remain on GitHub under the repository owner's control. The control plane stores the OAuth access token only in an encrypted, secure, HttpOnly session cookie that expires within eight hours. Copier Update maintains no customer database.
GitHub Actions and Cloudflare may retain operational logs under the publisher's configured retention settings. Logs may include account and repository names, pull request URLs, update outcomes, and error messages.
Third-party services
- GitHub hosts the App, OAuth flow, update jobs, repositories, branches, and pull requests under the GitHub privacy statement.
- Cloudflare hosts the owner control plane, terminates network connections, and may process security and operational logs under the Cloudflare privacy policy.
- Configured template hosts receive normal Git requests when Copier fetches the upstream template selected by a repository. Their policies and retention practices are controlled by that host.
Sharing and sale
Copier Update does not sell personal data, use advertising, run analytics, or use repository data for generative AI or model training. Data is shared only with the services needed to run an update and the template host configured by the repository owner.
Control and deletion
Repository owners control access through the GitHub App installation and their Copier answers files. Suspending or uninstalling the App stops new processing. Owners can delete update branches and pull requests through GitHub. No customer profile or application database exists to delete. For privacy questions, use the support page.
Changes
Material changes will be published on this page with a revised effective date.