Legal
Privacy
Last updated: August 14, 2026
What TookEffect stores
We store your GitHub user identifier, login, display profile, an encrypted GitHub user credential, GitHub App installation metadata, agent-token labels and hashes, Effect Contracts, execution inputs, observations, verdicts, signed evidence receipts, and the billing identifiers and subscription status needed to operate TookEffect.
How credentials are handled
GitHub App private keys, webhook secrets, session secrets, Paddle API credentials, and evidence-signing secrets are runtime secrets. They are not displayed in receipts or committed to the source repository. Agent tokens are shown once and stored only as SHA-256 hashes. GitHub installation tokens are short-lived and are not retained as evidence.
Why data is processed
Data is used to authenticate you, execute only the approved GitHub action, read back authoritative state, prevent duplicate execution, preserve evidence, administer subscriptions, provide support, and protect the service.
Service providers
TookEffect currently relies on GitHub for identity and repository operations, Cloudflare for application hosting and data storage, and Paddle for checkout, payment processing, subscription administration, invoices, returns, and applicable transaction tax handling. Paddle acts as Merchant of Record for purchases processed through Paddle.
Payment information
TookEffect does not store your full payment-card number or card security code. Payment details are collected and processed by Paddle. TookEffect stores only the Paddle customer, subscription, transaction, and status information required to grant or remove product access and support billing requests.
Retention and deletion
Sessions expire automatically. Evidence records are retained so customers can audit prior operations. You may request account or personal-data deletion through the Support page; legal, security, fraud-prevention, evidence-integrity, and accounting obligations may require limited retention.
Your choices
You can sign out, uninstall the GitHub App, manage or cancel your Paddle subscription, and request access to or deletion of personal data. Uninstalling removes future repository access but does not silently erase already-issued evidence receipts.
Contact
Privacy and account-data requests can be submitted through the TookEffect Support page.