Privacy Policy
Last updated: August 25, 2026
What Octoflow is
Octoflow ("we", "the bot", "the service") is a Discord bot that relays GitHub webhook events into Discord channels. This policy describes what data the hosted instance at v2.gitlogs.xyz collects when you use it, and how it's handled. If you run your own self-hosted instance from the open-source repository, this policy doesn't apply to your instance you control that data yourself.
Data we store
When you use commands like /newhook or /newrepo, we store:
- Your Discord server (guild) ID.
- Webhook IDs and their signing secrets (used to verify that incoming requests really came from GitHub).
- A comment/label you set for a webhook.
- The GitHub repository owner/name and Discord channel ID for each linked repository.
- Event modifier configuration (which event types are filtered, redirected, and at what priority).
- The Discord user ID of whoever created or last edited a webhook, repository link, or event modifier.
- Short text logs of how a given GitHub event was processed (repository name, event type, and the routing/permission checks applied) used for the /audit debugging tool.
Data we don't store
- We do not read, log, or store the content of your Discord messages.
- We do not store your GitHub account, GitHub token, or any GitHub login credentials Octoflow never authenticates as you on GitHub. You add the webhook URL to your repository settings yourself.
- We do not collect email addresses, IP addresses, or analytics/tracking data about who uses the bot.
- Full GitHub webhook payloads (commit messages, diffs, author emails, etc.) are used transiently to build the Discord message and are not retained afterward, beyond the short processing summary described above.
How we use this data
Stored data is used exclusively to operate the bot: matching incoming GitHub events to the right server and channel, enforcing your event modifier rules, verifying webhook signatures, and helping you debug delivery issues. We do not sell, rent, or share this data with third parties, and we don't use it for advertising.
How long we keep it
Webhook, repository, and event modifier data is kept for as long as the webhook exists. Deleting a webhook with /delhook immediately and permanently deletes its repositories and event modifiers along with it. Processing logs are retained until the associated webhook is deleted; there is currently no separate automatic expiry for them.
Third-party services
Octoflow necessarily communicates with the Discord API (to operate as a bot) and receives webhook requests from GitHub's servers. Your use of Discord and GitHub is separately governed by Discord's Privacy Policy and GitHub's Privacy Statement. We don't control, and aren't responsible for, how those platforms handle your data.
Your choices
- Delete a webhook (and everything tied to it) at any time with
/delhook. - Remove a single repository link with
/delrepo. - Remove the bot from your server at any time this stops any further data collection for that server.
- Contact us via the support server below to request deletion of any remaining data we hold about your server.
Children's privacy
Octoflow is a Discord bot and inherits Discord's own minimum age requirement. We don't knowingly collect data from anyone who doesn't meet Discord's eligibility requirements.
Changes to this policy
We may update this policy as the bot changes. Material changes will be reflected here with an updated date at the top of this page.
Contact
Questions about this policy or a data deletion request? Reach out on our support server.
See also our Terms of Service.