// Privacy policy
Privacy policy: GitHub Actions Monitor
Last updated: 2026-10-01
GitHub Actions Monitor is a Chrome extension that shows the status of GitHub Actions workflow runs for repositories you choose: a colored toolbar icon, a popup with each workflow's latest run, and optional desktop notifications. This policy explains what it handles and where that data goes.
In short: the extension has no server and sends nothing to its developer or any third party. It talks only to GitHub's API, using your own token, and keeps its data in your browser.
What the extension handles
| Data | Where it comes from | Why |
|---|---|---|
| Your GitHub personal access token | You paste it into the settings page | To read workflow runs from GitHub's API. |
| Your GitHub login name | GitHub's API, when you test or save a token | To confirm which account the token belongs to. |
| The repositories (and branches) you monitor | You | To know what to check. |
| Workflow run details: workflow names, status, conclusion, branch, commit title, run links, start and finish times | GitHub's API | To show status in the icon, popup and notifications. |
| HTTP ETags and the last results | GitHub's API responses | To re-check with conditional requests, which do not use your API rate limit. |
| Rate-limit counters | GitHub's API response headers | To show your remaining API requests on the settings page. |
| Settings: polling interval, notifications on/off, token sync on/off, paused repositories | You | To remember your choices. |
The extension does not read web pages, does not use cookies, and does not collect browsing history, analytics or usage statistics.
Where data is stored
Chrome Sync (
chrome.storage.sync, only when you use Chrome Sync): the repository list, polling interval, notification preference and token-sync preference, so they follow you to your other Chrome devices. Your token is synced only if you turn on "Sync token across devices" (off by default). Chrome Sync is operated by Google under Google's privacy policy.This device (
chrome.storage.local): your token (unless you sync it), the last results shown in the popup, the ETag cache and the rate-limit counters. This storage is not encrypted by Chrome; websites and other extensions cannot read it.
Where data is sent
Only to GitHub's API (api.github.com) over HTTPS, with your token in the Authorization header, to read workflow runs, branches and the repositories your token can see. The extension has no backend server; no data is sent to its developer or to any other party. Data is never sold or used for advertising, credit or any purpose unrelated to the extension's single purpose. GitHub's privacy statement applies to data GitHub processes.
Your control
Clear Token (settings page) removes the token from this device and from Chrome Sync.
Revoke the token on GitHub at github.com/settings/personal-access-tokens (fine-grained) or github.com/settings/tokens (classic) to invalidate it everywhere.
Remove or pause repositories in the popup at any time.
Uninstalling the extension makes Chrome delete its local data.
For safety, use a fine-grained token with Actions: Read-only access, limited to the repositories you monitor, with an expiry. The settings page creates one in a click and checks what a token can see.
Changes
Changes to this policy are published on this page, with the date above updated.
Contact
Questions about this policy: [email protected], or the contact form.