Legal
Privacy Policy
Last updated: August 10, 2026
pkgr.app is built by HexaOne Labs ("we", "us"). This policy explains what data we collect when you use pkgr.app and how we handle it.
Data we collect
- Account information: your email address and authentication details.
- GitHub data: the repositories and branches you authorize via the pkgr.app GitHub App, and metadata needed to trigger and track builds (commits, branches, run status).
- Signing secrets: certificates, provisioning profiles, and keystores you upload to the Secret Vault, used solely to sign your own builds.
- Build artifacts and logs generated when your app is compiled.
How we protect it
Secrets are encrypted at rest and transmitted over TLS. They are never exposed to the client and are only decrypted transiently, scoped to the run that needs them. Data is hosted in the EU to align with GDPR data residency requirements.
Sub-processors
We rely on a small number of infrastructure providers to operate pkgr.app, including GitHub (repository access and Actions execution) and our cloud hosting and storage providers. Formal data processing agreements with each sub-processor are maintained as part of our ongoing compliance work.
Your responsibility for keystores
Android keystores you upload cannot be recovered by us if lost — losing your keystore means you will be unable to publish updates to an existing app listing. We strongly recommend keeping an independent backup.
Retention
We retain build artifacts, logs, and secrets for as long as your project remains active, or until you delete them. You can revoke pkgr.app's GitHub access and remove stored secrets at any time.
Contact
Questions about this policy? Contact us.