Privacy Policy

Last updated: 7 August 2026

This policy explains what data the Rux project collects, why, and how long it is kept. It covers the website at rux-lang.dev, the package registry and its API at api.rux-lang.dev, and the playground.

Questions about this policy, or a request about your data, go to [email protected].

In short

  • The documentation site has no analytics, no tracking, no advertising, and no third-party scripts.
  • Reading the documentation, browsing packages, and downloading packages need no account.
  • The only personal data we hold is what a registry account requires, and it comes from GitHub.
  • The playground stores nothing.
  • Published packages are public and permanent.

Browsing the website

The site is a set of static files. It sets no cookies, embeds no analytics, and loads no third-party scripts. Fonts are served from our own domain rather than a font CDN.

Two things are stored in your own browser, never sent to us as a profile:

StoredWherePurpose
Light/dark preferencelocalStorageRemembering the theme you chose
rux.auth.returnsessionStorageThe page to return to after signing in; expires in 10 minutes
rux.auth.sessionsessionStorageSession expiry only, so "signed out" and "session expired" can be told apart

You can clear these at any time through your browser; nothing on the site depends on them.

The site is hosted on Cloudflare Pages. Like any web host, Cloudflare processes the network requests needed to serve pages, subject to its own terms.

Signing in to the registry

Signing in is optional and only needed to publish or manage packages. It uses GitHub OAuth: you authorize the Rux registry on GitHub, and GitHub returns your identity to us. We store:

  • your numeric GitHub user ID and login;
  • your display name and avatar URL, if your GitHub profile has them.

We do not receive or store your GitHub password, your email address, or access to your repositories.

While you are signed in, the registry API sets two cookies, __Host-rux_session and __Host-rux_csrf. Both are strictly necessary for authentication and cross-site request protection. Neither is used for analytics, and there are no other cookies.

Your avatar image is loaded directly from avatars.githubusercontent.com. That request goes to GitHub, not to us, so GitHub can see your IP address and browser when it is fetched.

API tokens

An API token lets the rux command line publish on your behalf. We store the token's display name, its scopes, its creation, expiry and last-use times, a short non-secret prefix, and a SHA-256 hash of the credential. The credential itself is shown once and never stored, so we cannot recover or display it again.

Publishing and downloading packages

Everything you publish is public: the package name, namespace, version, manifest metadata, README, license, and the package archive itself. Published versions are immutable — yanking withdraws a version from new resolution but does not delete it. Do not publish anything you are not willing to make permanently public.

The registry records a download event for each package download so it can show download counts. Events are counted; they do not identify who downloaded what.

The playground

Code you run in the playground is sent to our API and executed in a throwaway container. The container is destroyed after the run.

Nothing is stored. There is no database table for playground runs, no retention period, and no permalinks. Do not paste secrets or personal data into the playground.

Logs and abuse prevention

To keep the service available we apply rate limits, which derive a short-lived key from the requesting IP address (IPv6 addresses are reduced to their /64 prefix). That key lives in memory, is pruned regularly, and is not written to logs.

Request logs are deliberately narrow. They record a generated request identifier, the HTTP method, the matched route pattern, the response status, the duration, and tracing identifiers. They do not record IP addresses, user agents, raw paths, query strings, request bodies, headers, cookies, or credentials.

Security-relevant account actions — signing in, creating or revoking a token, changing namespace membership, publishing, yanking — are written to an append-only audit record so an account owner can see what happened. Those records hold only safe identifiers and a fixed set of allowed fields; they never contain credentials, cookies, request bodies, IP addresses, or user agents.

How long data is kept

DataKept
Published packagesIndefinitely — publication is permanent
Account profileUntil you delete your account
SessionsUntil they expire or you sign out
API tokensUntil they expire or you revoke them; revoked tokens remain as history
Audit recordsIndefinitely, as an append-only account history
Playground runsNot stored
Database backupsRoughly four weeks of point-in-time history
Deleted stored objectsRetained for 90 days as protection against accidental deletion

Deleting your account

You can delete your registry account from your dashboard. Deletion revokes every session and API token you hold and clears your GitHub identity and profile from our records.

It anonymizes rather than erases. Your account row remains, without any identity attached, so that the packages you published stay valid and installable. Publication history is part of the public record and is not removed.

If you are the last owner of a namespace, deletion is refused until you add or promote another owner.

Your rights

You can ask us to confirm what data we hold about you, correct it, or delete it, and you can obtain a copy of it. Write to [email protected]. Most of it is visible in your dashboard already, and account deletion is self-service.

The one thing we cannot undo is publication. A published package version is permanent and public.

Children

The registry is not directed at children under 16, and we do not knowingly collect their data.

Changes

We will update this page when what we collect changes, and change the date at the top. Material changes will also be noted on the blog.

Contact

[email protected]