pushbagOpen dashboard

Privacy policy

Effective August 3, 2026

Overview

pushbag is an artifact publishing service. This policy describes what information we collect when you use it, how we use that information, and the choices you have. We collect the minimum we need to run the service: we do not sell personal information and we do not show ads.

Information we collect

  • Google account information. Signing in uses Google OAuth. We receive your name, email address, and profile picture, and we store them to identify your account.
  • Content you publish. The HTML documents, images, and videos you upload, along with their titles, descriptions, visibility settings, and version history.
  • Operational data. Standard request logs such as IP address, user agent, timestamps, and request outcomes, used for security, debugging, and abuse prevention.

How we use information

  • Authenticate you and associate artifacts with your account.
  • Serve private artifacts only to their owner.
  • Enforce storage quotas and file limits.
  • Operate, secure, and troubleshoot the service.

Google user data

pushbag's use and transfer of information received from Google APIs adheres to theGoogle API Services User Data Policy, including the Limited Use requirements. Google account data is used only to authenticate you and display your account in the dashboard. It is never sold, used for advertising, or transferred to third parties except as required to operate the service or comply with the law.

Where data is stored

Account and artifact metadata is stored in Cloudflare's database platform. Artifact files are stored in a private S3-compatible storage bucket and are served only through the service; private files are accessed via short-lived signed grants, never permanent storage links.

Cookies

We use a single session cookie to keep you signed in. We do not use tracking or advertising cookies.

Sharing

We share data only with the infrastructure providers that host the service (such as Cloudflare and our storage provider), and when required by law. Artifacts you mark as public are accessible to anyone who has their URL.

Retention and deletion

Your data is retained while your account is active. Deleted artifacts are purged after a short retention window. You can request deletion of your account and all associated data at any time by contacting us, and you can revoke pushbag's access to your Google account from yourGoogle account settings.

Changes

If this policy changes, we will update this page and its effective date.

Contact

Questions about this policy or your data:support@pushbag.dev.