Privacy policy
Information collected
Social login uses your selected provider's identifier, name, consented email and login/link timestamps. Login access tokens are used temporarily to retrieve your identity and are not stored. Provider emails are considered verified only when explicitly confirmed by that provider. Account records include the social provider identity, email when provided, the display name from the sign-in provider (editable in account settings), the time of each consent, encrypted authenticator secrets, and optional business details for tax invoices.
CI records include encrypted GitHub personal access tokens for runner registration, GitHub identities and repository names, hashed API keys, job metadata, usage and charges. Payment processors provide payment identifiers, approval times, card issuer and masked card information, issuing country and receipt URLs. Full card numbers are not stored. Signup, login and payment IP addresses and timestamps support fraud prevention and dispute handling.
Purposes
We use these records to run jobs, manage organizations and repository connections, process payments, respond to incidents, prevent abuse, handle disputes, issue invoices and meet legal obligations.
Retention and account closure
Accounts without CI organization ownership or membership may be cleaned up after one year without login. CI accounts are not automatically deleted solely because they have not logged into the browser. Closure requests are reviewed for organization ownership, members, active jobs, reservations, balances, pending payments and refunds. After settlement and any required ownership transfer, login identities, sessions, API keys and GitHub connections are revoked and account personal fields are anonymized.
Contract, payment, refund and related access evidence are retained for five years under applicable Korean electronic commerce requirements. Related order, CI ledger, refund and audit records are retained separately from anonymized account details. We do not collect phone numbers. Accounts that verified a number earlier keep it until the account is deleted, and it is used only to send account-recovery codes and to prevent duplicate free credits. Those codes expire after five minutes and are stored as HMACs. Temporary verification information is cleaned after success or expiry; anti-abuse HMAC and attempt records are cleaned after two days.
Execution data
Each job uses a fresh macOS VM. Its code, secrets, artifacts, commands and host runtime logs are deleted after termination. Job metadata remains. GitHub Actions logs follow GitHub policies. Legacy Linux runtime logs are deleted within 90 days. GitHub tokens are removed on disconnection. We use runtime data only for operation and incident response.
Service providers
Payment information is processed by PortOne and Toss Payments. Configured SMTP providers or Resend receive addresses and email content for delivery. Account-recovery codes for a previously verified number are sent by SOLAPI through Kakao AlimTalk only; SMS is not sent. Marketing messages are processed only when separately opted into. Other disclosures require a legal basis, including payment dispute submissions.
Your rights and contact
You may request access, correction or deletion. Available account fields can be edited in settings; contact play@xenoci.com for deletion requests, handled within three business days subject to the settlement and retention rules above. Privacy contact: Hyunsoo Joo.