Last updated 2026-10-06.
This policy explains what personal data the Moatline website (moatline.dev) and the hosted Moatline service (the "Service") process, why, and what rights you have. The controller is TODO: company name, TODO: street, postcode city, Austria, TODO: hello@moatline.dev.
A self-hosted Moatline sends us nothing: whoever runs it is responsible for the data in it.
Analytics. We count visits with Plausible Analytics, which we run ourselves (plausible.janikhalder.at). It sets no cookies and stores no IP addresses or other identifiers; visits are counted as anonymous totals (page, referrer, country, browser). Legal basis: our legitimate interest in knowing which pages are read (Art. 6(1)(f) GDPR).
Server logs. When you open a page, the web server briefly processes your IP address and browser details to deliver it and to fend off attacks.
| What | Why | Kept |
|---|---|---|
| Account: name, email address, password (hashed), second-factor secret (encrypted), sessions with IP address and browser | Sign-in and security | Until you delete the account; sessions expire |
| Organizations, members, roles, invitations | Working together | Until the organization is deleted |
| Audit log: who did what, when, from which IP address | Security and traceability for the organization | Until the organization is deleted |
| Repository data: URLs, branches, dependency names and versions, findings, pull requests opened | The core of the Service | Until the repository is removed |
| Server reports from the agent: hostname, operating system, packages and updates, containers, disk and memory use, firewall and login events, error lines from container logs | Watching your servers | Reports are replaced by newer ones; metrics are kept for 14 days, storage history for 90 days |
| Access tokens for GitHub, GitLab, Bitbucket, Gitea, Dokploy, Coolify and others | Acting on your behalf where you asked | Encrypted; until you remove them |
| Live checks of the URLs you enter | Uptime and deploy checks | Until the repository is removed |
Legal basis: performing the contract with you (Art. 6(1)(b) GDPR) and, for security logs, our legitimate interest in a secure Service (Art. 6(1)(f) GDPR). Server reports may contain personal data of third parties (for example user names in login events); you decide what the agent runs on, and we process that data on your behalf.
The Service does not execute code from your repositories and does not read the contents of your databases.
We do not sell data and do not use it for advertising.
You have the right to access, rectify and erase your data, to restrict or object to processing, and to receive your data in a portable format. Most of it you can change or delete yourself in the Service; for anything else write to TODO: hello@moatline.dev. You may also complain to a supervisory authority — in Austria the Datenschutzbehörde (dsb.gv.at).
We update this policy when the Service changes; the date at the top shows the current version.