Privacy Policy
Last updated: 24 July 2026
This policy explains what data Anesis collects when you use the website, the API, or the CLI, why we collect it, and what control you have over it.
1. What we collect
Account data. When you sign in with GitHub we receive and store your GitHub user ID, your login (username), and your avatar URL. We do not receive your GitHub password, and we do not request access to your private repositories.
API tokens. Personal access tokens you create are stored only as a SHA-256 hash, together with the name you gave them, when they were created, when they were last used, and when they expire. The token itself is shown once and never stored.
Published content. The repository URL, manifest, and version metadata for every template, addon, or stack you publish, plus which account published it.
Usage events.When a template, addon, or stack is installed, we record that it was installed, by which account (when authenticated), and when. This drives the download counts and the “trending” ordering in the registry. The CLI reports this on anesis new and on addon commands.
Operational logs. Requests to the API produce a log line containing the method, path, status, latency, and a request identifier. Errors may be sent to Sentry for diagnosis.
2. Why we use it
- To authenticate you and authorise access to your own resources.
- To operate the public registry — showing who published what, and at which version.
- To show download and popularity counts.
- To detect abuse, apply rate limits, and diagnose failures.
We do not sell your data, and we do not use it for advertising or behavioural profiling.
3. What is public
Your GitHub login and avatar, and everything you publish to the public registry (including its metadata and aggregate download counts), are visible to anyone. Resources you mark as private are not listed publicly. Your API tokens, and the list of what you have installed, are never public.
4. Third parties
- GitHub — identity provider for sign-in, and the source of every published repository.
- Vercel — hosts the website.
- Render — hosts the API and its PostgreSQL database.
- Sentry — receives error reports, which may include a request path and stack trace.
5. Cookies
We use cookies strictly to keep you signed in: a session cookie holding your authentication token, per-account session cookies when you add more than one GitHub account, and a short-lived CSRF nonce during the OAuth flow. All are HttpOnly. There are no advertising or analytics cookies.
6. Retention
Account data is kept while your account exists. Revoked API tokens are deleted immediately. Usage events are currently retained indefinitely in aggregate form to keep historical download counts accurate.
7. Your rights
You can view and revoke your API tokens at /account/tokens, and unpublish resources you own from your account pages. To request access to, correction of, or deletion of your data, open an issue or contact us at the link below. Depending on where you live you may have additional rights under the GDPR or similar laws; we will honour them.
8. Changes
We may update this policy. Material changes will be reflected in the “last updated” date above.
9. Contact
Privacy questions or requests: open an issue at github.com/anesis-dev/anesis-cli.
