Privacy

Last updated: September 20, 2026

What we store

  • Account data: email, optional GitHub link, session tokens.
  • Optional MFA (TOTP) enrollment metadata when you enable two-factor authentication.
  • CLI sign-in tokens (hashed), labels, and expiry. You can revoke them from the dashboard.
  • Project metadata: names, protection mode, environments, machine identity labels and public keys.
  • Secret ciphertext and wrapped project keys. We do not store Vault passwords or plaintext secret values.
  • Activity and security events: actions such as project created, secret updated, CLI command used (command name and counts), login, and access request approve or deny. Metadata only - not secret values.

What we never store

  • Your Vault password.
  • Plaintext secret values.
  • Secret values in emails or webhook payloads (names and metadata only).
  • The command line after getmyenv run -- (your app command).

Runtime

Secrets are injected as environment variables before your process starts. That works for any language that reads the environment (for example Node, Python, Ruby, Rust, Go, PHP, Java, .NET, and shell).

Why we store it

To run the product: authenticate you, deliver ciphertext to authorized clients, show your activity, and understand which CLI commands are used so we can improve the product. Access and security events also support account safety.

Site analytics

On production, we load Google Tag Manager (container GTM-KNRWPCJX), which can run Google Analytics 4 (measurement ID G-566S2Z04B0). We use this to understand marketing and product traffic: pages viewed, referrals, and rough geography. It does not read your Vault password or plaintext secret values.

What may be collected includes:

  • Page URL and path, referrer, and similar navigation data.
  • Device and browser information.
  • Approximate location derived from IP address.
  • Measurement events Google Analytics provides for site usage.

Google processes this data under Google's terms for Tag Manager and Analytics. We do not sell it.

Cookies

We set session and related auth cookies so you can stay signed in and complete login flows (including OAuth and MFA when used).

Google may set its own cookies or similar storage for Tag Manager and Analytics measurement.

Retention and deletion

Data stays while your account exists. Deleting your account removes your projects, secrets ciphertext, and related activity from our systems. Session and CLI tokens expire on their own schedule.

Analytics retention follows the settings in our Google Analytics property.

Your choices

You can limit analytics with browser controls or extensions that block tracking scripts. Questions about this policy: use the contact options on getmyenv.

    Privacy - getmyenv · getmyenv