Privacy Policy
What we hold about you, why, and how to get it removed
Who is responsible for your data
EKOHACKS OÜ, registered in Estonia, company number 17182181, of Järvevana tee 9, 11314 Tallinn, Estonia, is the data controller for the Dojo.
For anything about your data, email connect@ekohacks.com.
What we collect, and why
When you sign in with GitHub
- Your GitHub username, numeric GitHub ID, display name and avatar URL, to identify your account and show you to yourself and to your cohort.
- Your email address, to identify you, to match your account to your subscription, and to contact you about the service.
- The date you first signed in, to tell a person who has joined apart from one who has only been imported by a repository owner.
From the repositories you connect
- Commits and pushes: author, timestamp and commit reference, to measure how often and how steadily you ship.
- Pull requests: title, open and merge times, size and review timings, to measure review turnaround, rework and right sizing.
- Builds and check runs: pass, fail and duration, to measure delivery health.
- Deployments and incidents, to calculate DORA metrics.
We read repository activity. We do not store the contents of your source code.
If you connect optional integrations
- WakaTime: coding time totals and which editors you used, to show coding time and award experience points for it. Connecting WakaTime is your choice, and we store the API key you give us in order to keep syncing.
- Code scanning reports: summary results and issue counts, to show code health and award experience points for improvements.
When you pay
- Your Paddle customer ID and subscription ID, the plan, its status and any scheduled change, so we know what your account is entitled to without calling Paddle on every page.
We never see or store your card details. Those are entered on Paddle's systems and stay there.
Automatically
Server logs, which include IP address, request path and timestamp, kept for 30 days for security and debugging.
Page views, counted by Plausible so we know which pages are read and where visitors come from. Plausible uses no cookies, keeps no personal data and records no IP address; it stores the page, the referrer, the country and the browser family, in aggregate.
Why we are allowed to hold it
- Running your account and providing the service: performance of a contract with you.
- Taking payment: performance of a contract with you.
- Computing and showing your metrics: performance of a contract, since it is the service itself.
- Showing your metrics to the cohort you joined: performance of a contract. Joining a cohort is your choice and you can leave.
- Security logging and preventing abuse: our legitimate interests in keeping the service safe.
- Service emails about your account or billing: performance of a contract.
Who else sees it
- Paddle.com Market Ltd: selling, payment, invoicing and tax, as merchant of record and a controller in its own right for that purpose. United Kingdom.
- HostStack: hosting the application and its database. Frankfurt, Germany (EU).
- GitHub, Inc.: sign in, and the repository activity you ask us to read. United States.
- WakaTime: coding time, and only if you connect it. United States.
- Plausible Insights OÜ: page view counts, in aggregate. Estonia, hosted in the European Union.
We do not sell your data. We do not share it for advertising.
The application and its database run in Frankfurt, Germany (EU). Where data reaches the United States, through GitHub or through WakaTime, we rely on the transfer safeguards those providers publish, which are the EU to US Data Privacy Framework or the European Commission's Standard Contractual Clauses.
How long we keep it
We keep your account and your metrics for as long as you have an account.
If you ask us to delete your account, we delete it and the metrics derived from your activity within 30 days. Records we must keep for tax and accounting are held by Paddle for the period the law requires.
Server logs are kept 30 days.
Your rights
You have the right to:
- See what we hold about you.
- Correct anything wrong.
- Delete your account and data.
- Take your data with you, in a machine readable form.
- Object to processing based on our legitimate interests.
- Restrict processing while a dispute is resolved.
Email connect@ekohacks.com and we will respond within one month. There is no charge.
If you think we have handled your data badly, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), or to the supervisory authority where you live. In the UK that is the Information Commissioner's Office.
Security
What is true today, and all that we claim:
- Sessions are signed cookies.
- Webhook deliveries are verified by signature and restricted to the sender's published network.
- API keys and secrets are held as encrypted environment variables and stay out of source control.
- Access to the production database is restricted to the application.
Children
The Dojo is for people aged 16 and over. If you believe a child has given us data, tell us and we will delete it.
Changes
If we change how we use your data in a way that affects you, we will tell you by email before it takes effect.
Contact
For anything about your data, email connect@ekohacks.com. To have your account and metrics deleted, ask us and we will confirm when it is done.
Last updated 22 August 2026.