Privacy Policy

Last updated: July 25, 2026

1. What we collect

Account data — name, email address, username, and password hash; if you sign in with a social provider (GitHub, Google, GitLab, Bitbucket, Gitea) we receive your name, email, and avatar from that provider.

Your content — the organizations, projects, and secrets you store. Secret values are envelope-encrypted (AES-256-GCM) at rest; they are decrypted only transiently, in memory, to serve requests your session or API tokens authorize. Secrets marked sensitive are additionally hidden from the dashboard.

Usage and security data — an audit log of security-relevant actions (who revealed, pulled, or changed a secret and when) kept per organization, plus standard server logs (IP address, request path, timestamps) for abuse prevention and debugging.

Payments— handled entirely by Polar as merchant of record. We never receive your card details; we store only your organization's plan and Polar subscription reference.

2. What we don't do

We do not sell your data, use it for advertising, train models on it, or use third-party analytics or tracking cookies. The only cookie we set is the session cookie that keeps you signed in.

3. Where your data lives

bulgur runs on servers in the European Union (Hetzner, Germany). Encrypted database backups are stored with Cloudflare R2. Transactional email (verification, password reset), when enabled, is delivered via Resend.

4. Subprocessors

Hetzner Online GmbH (hosting, DE) · Polar Software Inc. (payments, merchant of record) · Cloudflare, Inc. (backup storage) · Resend, Inc. (transactional email) · the social login provider you choose to authenticate with. Each receives only what its function requires.

5. Retention and deletion

Your data is kept while your account is active. Deleting a secret, project, organization, or your account removes the data immediately from the live database; encrypted backups age out on a rolling window of at most 30 days. Payment records are retained by Polar as required by tax law.

6. Your rights

Under the GDPR (and KVKK where applicable) you can access, export, correct, or delete your personal data, object to processing, and lodge a complaint with a supervisory authority. Export is built in — your secrets can be downloaded from the dashboard or CLI at any time. For anything else, email hello@bulgur.dev and we will respond within 30 days.

7. Security

All traffic is TLS-encrypted. Secret values are protected with envelope encryption: a per-project data key wrapped by a master key that is never stored in the database. API tokens are stored only as SHA-256 hashes and can be scoped so AI tooling can never read secret values. If a breach affects your data we will notify you without undue delay.

8. Changes and contact

We may update this policy; material changes will be announced by email or in the dashboard. The data controller for bulgur is reachable at hello@bulgur.dev.