Legal

Privacy

What this site knows about you, what Conductor Cloud stores, and what neither of them can see.

This site sets no cookies.

No analytics vendor, no tag manager, no embedded video, no font CDN — the typefaces are served from this origin. There is no consent banner because there is nothing to consent to, and that is the version of this we would want to read.

What we can see

Our reverse proxy writes an access log: the path requested, the status code, the referring page, and a truncated user agent. It is aggregated for counts — which pages get read — and it is not joined to anything that identifies a person.

Links from this site to the console carry a ?ref= parameter naming the page you left from. That is the whole of our attribution. The cost is stated honestly: we have no per-visitor funnel and cannot tell you how many people read the pricing page before signing up. We accept that in exchange for the paragraph above.

Conductor Cloud

If you use the hosted control plane, it stores what a release platform needs to do its job: your organisation, the people in it, your projects, your runs and their logs, and your credentials — encrypted at rest with a key we hold separately from the database.

Credentials
Encrypted at rest. No API returns credential material, to anybody, including you and including us — there is no route that can. What we can see is that a credential exists, what purpose it serves and when it was last used.
Your source code
Never stored. Conductor reads release.yaml from your repository at a commit and hands a clone token to your own runner. The code is checked out on your machine and stays there.
Build artifacts
Stored in your object store on a self-hosted deployment. On Cloud, in ours, for the retention period of your tier.
The audit log
Append-only and hash-chained per organisation. It records who did what and when. It is never truncated, including when run and log retention expires — a chain with a hole in it is not a chain.
Self-hosted deployments
We see nothing. There is no phone-home, no licence check and no telemetry. We do not know your deployment exists unless you tell us.

Your rights, and the practical version

You can ask us what we hold about you, ask for it to be corrected, and ask for it to be deleted — write to privacy@mangozestlabs.com and we will answer within thirty days.

Deleting an organisation deletes its projects, runs, logs, artifacts and credentials. The audit log is the exception and the reason is the one above: an append-only chain that supports selective deletion is not append-only. If that is a problem for your jurisdiction, self-host — then it is your log, in your database, under your policy.