Privacy policy
Last updated September 25, 2026
This policy explains what data stateofpixel ("we", "us") collects when you use stateofpixel.com, the GitHub App and the stateofpixel CLI, and what we do with it. Questions go to hello@stateofpixel.com.
What we collect
When you sign in with GitHub:
- Your GitHub user ID, login, name, avatar URL and email address, if GitHub shares them.
- A GitHub access token, used to check which repositories you can read, review or administer.
- The time you last used the app.
When you install the GitHub App:
- The login and ID of the GitHub account or organization.
- For each repository you select: its ID, owner, name, visibility and default branch.
When your CI uploads a build:
- The PNG screenshots, their names and SHA-256 hashes, and the diff results your runner computed.
- Git metadata: commit SHA, commit message, branch, base branch, pull request number and recent ancestor commits.
- The CI provider and the URL of the CI run.
We never receive or run your source code. Screenshots show whatever your pages or components render, so do not capture pages that show data you are not allowed to share with us.
When you review a build:
- Each approve, reject and undo, who made it, and any comment you add.
Cookies and browser storage
The site stores your sign-in session and your theme choice in your browser's local storage. We do not use advertising or tracking cookies.
Analytics
We use Umami Cloud to count page views and clicks on some buttons, such as sign in, copy code and approve. Umami does not use cookies. It records the page, the page you came from, your browser, operating system, device type, screen size, language, country and page load times. Before anything is sent, we replace account names, repository names, build numbers and snapshot names in page addresses with placeholders, and we leave out search parameters. If your browser sends Do Not Track, nothing is sent.
How we use it
- To run the service: store baselines, compare builds and show them.
- To set commit statuses on your commits in GitHub.
- To check that you are allowed to see or review a project.
- To reply when you contact us.
We do not sell your data and we do not use it for advertising.
Who processes it
We use these providers to run stateofpixel:
- GitHub, for sign-in, the GitHub App and commit statuses.
- Convex, for the database, file storage and the backend functions.
- Netlify, to host the website.
- Umami, for the analytics described above.
These providers may process data in other countries. Before paid plans start, we will add the payment provider to this list.
How long we keep it
- Builds of pull requests and other branches are deleted after the retention period set in the project settings, 60 days by default, counted from when the pull request closes or the branch gets no new builds.
- Screenshots and diffs that no build uses any more are deleted.
- Deleting a project in its settings deletes its builds and images.
- Uninstalling the GitHub App archives your projects. Their data stays until you ask us to delete it.
- GitHub webhook delivery records are deleted after 7 days.
Your choices
You can ask for a copy of your data, a correction or its deletion by writing to hello@stateofpixel.com. We will delete your user and account data on request. You can also revoke the app's access at any time in your GitHub settings.
Security
Data moves over HTTPS. Project tokens are stored as hashes, so we cannot show them again after you create them. Access to a project follows your permissions on its GitHub repository.
Children
stateofpixel is not meant for anyone under 18, and we do not knowingly collect their data.
Changes
When we change this policy, we update the date at the top of this page. For changes that affect how we use your data, we will also tell you by email or on the site before they apply. See also the terms and the refund policy.