privacy

Privacy Policy

Last updated October 8, 2026.

Codemany is made by Rainbow Labs Inc. ("we"). In short: your code, workflows, job logs and GitHub token stay on your Mac and with GitHub. We get only what licensing and billing need, plus anonymous usage stats (counts and sizes, never names, code or tokens) unless you turn them off. There are no ads or tracking cookies, and we do not sell your data.

What stays on your Mac

What leaves your Mac

To GitHub, directly

The app and daemon call GitHub with your token to sign you in, list your repositories, register a fresh runner for each job, watch workflow runs and download the GitHub Actions runner. GitHub's privacy statement covers this.

To us: starting a trial or subscribing

The app sends your GitHub token to api.codemany.com once, so we can confirm your GitHub account. We use it for two GitHub API calls (your profile and your email addresses) and then drop it: it is not stored, logged or sent to Stripe. From GitHub we keep your user id, login and email address (your primary verified email, or else your public email, or else your GitHub no-reply address).

The app also sends a device id and your Mac's name (for example "Ann's MacBook"). The device id is a SHA-256 hash of the Mac's hardware UUID, never the UUID itself. It ties your license to one Mac.

To us: license checks

About once a day, the app (or the daemon, if the app is closed) sends its license and device id to api.codemany.com to renew the license. Listing or moving your Mac's seat and opening the billing portal send the same.

To us: bug reports, only when you send one

A report contains the title and description you type, the app and macOS versions and, only if you turn it on, a diagnostics summary. The summary is reduced to counts, states, versions and error text, with owners, repos, branches, run titles, runner names, hostnames, URLs and IPs removed. The form shows exactly what will be sent. We file the report as an issue in our private GitHub repository, without your email or subscription ids.

To Stripe

When you subscribe, you pay on Stripe's checkout page. Stripe collects your payment and billing details; we never see your card number.

To PostHog: anonymous usage stats

Unless you turn them off, the daemon sends anonymous usage events to PostHog. What is sent, and how to turn it off.

Update checks

The app checks codemany.com/updates/appcast.xml for updates. Like any web request this reveals your IP address and app version. No system profile is sent.

Your local network

The daemon serves a status dashboard on your local network (port 8825, advertised as codemany.local). It shows repo and workflow names, branches, run titles and runner state to anyone on that network. It is never sent to us. Set "lanDashboard": false in ~/.codemany/config.json to keep it on this Mac only.

Anonymous usage stats

Why: to see how Codemany is used so we can improve it, and to publish combined totals for all Macs on codemany.com (jobs run, minutes, dollars saved, the kinds of Mac, and a top-10 list under anonymous names like "Mac a1b2").

Where: PostHog, US cloud. The daemon sends events in batches, about once a minute.

On by default. The first time the app opens with this feature, and during setup, it tells you so with Turn Off and OK. To turn it off at any time:

Turning it off stops sending at once: nothing is kept to send later. Events already sent are not recalled.

Identity: a random install ID (a UUID) created on first run and kept in ~/.codemany/analytics-id. It is not derived from your Mac's hardware or your account. Turning stats off keeps the file, so counts continue if you turn them on again; delete it to start a new ID.

Every event also carries the app version, the macOS version (major.minor) and the processor architecture.

EventWhenWhat it carries
install_activeWhen the daemon starts, then every 24 hoursCPU cores, performance cores, memory in GB, disk size in GB (rounded to 10), chip (for example "Apple M2 Pro"), how many runners, isolation mode (host, user or vm)
repos_connectedAt start and when the watched repos changeHow many repos, organisations and workflows (counts only)
job_scheduledThe first time a job queued for this Mac is seenA run key, and whether the job is Linux or macOS work
job_finishedA job that ran on this Mac completesA run key, Linux or macOS, result (success, failure or cancelled), duration in seconds, billed minutes, the estimated dollars saved (standard and larger GitHub runners), and whether the repo is public
runner_failedA runner fails to start, crashes, goes offline or its VM failsWhich of those it was, and the isolation mode
runner_recoveredA runner that failed is back onlineSeconds since the failure

The run key is the first 16 hex characters of a SHA-256 hash of your install ID, the repo and the run's id. It lets the same run count once, but cannot be turned back into a repo.

Never sent: repository, organisation, workflow, job, branch, runner or host names; URLs; tokens; logs; file paths; GitHub user names; email addresses; license keys. PostHog is told not to look up a location from your IP address; like any web request, the connection itself shows PostHog your IP address.

What we store

This website

codemany.com sets no cookies and has no analytics or third-party scripts. Its font (JetBrains Mono) loads from Google Fonts, so Google receives your IP address and browser details when you visit.

Who processes data for us

ServiceWhat for
StripeCheckout, subscriptions, invoices, the billing portal and our customer records.
Google CloudRuns codemany.com and api.codemany.com, stores their logs and hosts the app downloads. Google Fonts serves the site's font.
CloudflareDNS, CDN and security for codemany.com and api.codemany.com. All traffic passes through it.
PostHog (US cloud)Receives the anonymous usage stats, unless you turn them off.
GitHubSign-in, and the issue tracker that receives bug reports. Your jobs run under your own GitHub account.

We do not sell, rent or share your data for advertising, and we share it with no one else unless the law requires it.

Your choices

Codemany is not meant for children under 13.

Changes and contact

We will post changes here and update the date at the top. Questions: send a direct message to @arpwal on X. See also the Terms of Service.