Skip to content

Privacy Policy

Last updated: July 7, 2026

This policy describes what data Overwire collects through the overwire.io website and the Overwire desktop application, why it is collected, and who processes it. The short version: your workflows, repositories, secrets, and run logs stay on your machine; the website collects an email address only if you give us one; and crash reporting in the app is the only telemetry, and you can turn it off.

Who we are

Overwire is a local workflow workbench for working with GitHub Actions workflow files, developed and operated as a sole proprietorship based in Ontario, Canada. That sole proprietorship is the data controller for the personal data described in this policy. For anything in this policy, contact [email protected].

What the website collects

Email signup

If you submit your email address to be notified about Overwire, we store the address and the time you subscribed in Cloudflare Workers KV. We use it solely to send you product announcements. We do not sell it, share it with advertisers, or enrich it with other data. Every announcement email includes a way to unsubscribe, and you can request deletion at any time by writing to [email protected].

To prevent abuse, the signup endpoint briefly records a rate-limit entry keyed by your IP address. It expires automatically within one minute and is not used for anything else.

Hosting

The website, the documentation site (docs.overwire.io), and the download host (releases.overwire.io) are served by Cloudflare (Pages and R2). Cloudflare may process standard request metadata (such as IP addresses) to deliver them. We measure traffic on the website and the documentation site with Cloudflare Web Analytics, which is cookieless, collects only aggregate visit and performance metrics, and does not track you across sites. Downloads and update checks are visible to us only as aggregate counts derived from Cloudflare's server-side metrics, never as individual profiles. We do not run any other analytics scripts or advertising trackers. The website sets no advertising or analytics cookies; the only cookies you may encounter are strictly necessary ones Cloudflare sets to serve the site securely (for example, bot protection), which is why there is no cookie banner.

What the desktop app collects

Your workflows stay local

Overwire runs on your machine. Your workflow files, repository contents, configuration, secret values, event payloads, and run logs are read and written locally and are never transmitted to us. Secret values are additionally redacted from captured logs by default.

Crash reporting (opt-out)

Packaged builds of the app can send crash reports to Sentry so we can fix defects. The app asks you the first time you launch it, and you can change your choice at any time in Settings → Privacy; the change takes effect on the next launch. Crash reports are scrubbed of home-directory paths before sending and do not include your workflow contents, configuration files, log output, or secret values. Development builds send nothing.

Update checks

The app periodically checks releases.overwire.io for updates. This is a standard HTTPS request for a version manifest; it does not carry personal data beyond what any web request includes.

License validation

If you purchase a paid license, the app validates your license key against Polar's license API on launch and periodically thereafter. The request carries your license key and a device activation identifier, not your workflow data. Purchases themselves are processed entirely by Polar as merchant of record (see below).

No other telemetry

The app does not track feature usage, does not fingerprint your machine, and does not phone home beyond the three purposes above.

Processors

  • Cloudflare, Inc.: website hosting (Pages), email signup storage (Workers KV), and download delivery (R2).
  • Functional Software, Inc. (Sentry): crash report processing for the desktop app, only when crash reporting is enabled.
  • Polar Software Inc. (Polar): independent merchant of record for paid licenses. Polar processes your payment details, billing address, and order history as a controller in its own right, under its own terms and privacy policy; we receive order and license metadata, never your payment card details.

Legal bases (GDPR)

Where the GDPR or similar laws apply, we process personal data on the following bases:

  • Consent: the email signup list, and crash reporting in the app (it asks on first launch, and you can change your choice in Settings). You can withdraw consent at any time by unsubscribing, turning crash reporting off, or emailing us.
  • Contract: license validation, delivering your license key, and providing updates for a license you bought.
  • Legitimate interests: rate-limiting and abuse prevention on the signup endpoint, and the standard server logs and security measures needed to operate the website and download hosts.

International transfers

We are based in Canada, and the providers listed above process data in the United States (Cloudflare also operates a global network). Cloudflare and Sentry are certified under the EU-U.S. Data Privacy Framework, including its UK and Swiss extensions, and their data-processing terms incorporate the European Commission's Standard Contractual Clauses. Where personal data of EU, UK, or Swiss residents is transferred to a provider not covered by an adequacy decision, we rely on Standard Contractual Clauses or equivalent safeguards in that provider's data-processing terms.

Data retention

We keep signup emails until you unsubscribe or ask us to delete them. Crash reports are retained on Sentry for 90 days and then deleted automatically. Signup rate-limit entries expire within one minute. Order records are kept by Polar for as long as tax and accounting law requires.

Your rights

You can request access to, correction of, deletion of, or a portable copy of your personal data, ask us to restrict or object to its processing, and withdraw any consent, at any time, by writing to [email protected] from the email address your request concerns (that is how we verify requests). We respond within one month, and we will never treat you differently for exercising a privacy right. If you are in the EU, UK, or Switzerland, you also have the right to lodge a complaint with your local data-protection authority. We do not use your personal data for automated decision-making or profiling.

California privacy disclosures (CCPA)

We do not sell or “share” personal information as those terms are defined in the California Consumer Privacy Act, we do not use or disclose sensitive personal information, and we do not knowingly collect personal information from anyone under 16. Because we never sell or share personal information, there is no “Do Not Sell or Share My Personal Information” link to offer.

In the preceding 12 months we have collected only: identifiers (your email address, if you subscribe, and IP addresses handled transiently for rate-limiting and hosting); commercial information (order and license metadata from Polar, if you buy a license); and diagnostic data (crash reports, if you enable them). Everything is collected directly from you, used for the purposes described above, and disclosed only to the providers listed above. California residents can exercise their rights to know, delete, and correct, without being discriminated against for doing so, by emailing [email protected].

Changes

We will update this policy as the product evolves, for example when paid licensing launches. Material changes will be reflected in the “last updated” date above.