GitDash
DocsAPI playgroundGitHub
Open GitDash
GitDash Docsv4.7.1
GitHub API playground
  • Introduction
  • Quick start
  • Deployment
  • Configuration
  • Auth modes
  • Access control
  • Caching & rate limits
  • Security model
  • Data sources
  • Feature overview
  • Repositories
  • Repository · Overview
  • Repository · Workflows
  • Repository · Pull requests
  • Repository · Team
  • Repository · Issues
  • Repository · Security
  • Repository · Audit trail
  • Workflow detail
  • Alerts
  • Team insights
  • Contributor & 1:1 prep
  • Cost
  • Reports
  • Org overview & health
  • Settings
  • AI insights
  • Metrics Reference
  • DORA 4 Keys
  • PR Cycle Time
  • PR Lifecycle Health
  • Workflow Overview
  • Performance Tab
  • Reliability Tab
  • Team & People
  • CI & Alert Metrics
  • API Reference
  • FAQ & Troubleshooting
  • Contributing
  • Release Notes
  • Data & privacy
GitHub RepositoryReport an Issue
GitDash Docs

Data & privacy

GitDash is self-hosted: whoever runs an instance holds its data, and nothing is sent to the GitDash project. This page lists what an instance keeps, where, and for how long. The public site, gitdash.info, runs the same code.

What is stored

DataWhereKept
Your GitHub token (PAT or OAuth)Encrypted, HTTP-only session cookie gitdash_session. Never sent to the browser's JavaScript or stored in the database.7 days, or until you sign out
GitHub API responsesIn memory, and in the api_cache table when organization mode has a database. Keyed per token, so nobody reads another person's cache.Minutes to hours, per endpoint
Your GitHub id, login and avatar URLThe users table (organization mode), so an admin can place you in a group.Until an admin removes you
Groups, grants and their changesuser_groups, group_flags and the permission_audit log.Until deleted by an admin
Workflow-run and pull-request historyworkflow_runs, pr_facts and related tables, filled by the nightly sync (which uses the operator's own service token) for Reports and alerts. Admin-made links between GitHub logins live in identity_links.Until deleted by the operator
Alert rules, deliveries and settingsAlert, email, AI and team settings tables. Webhook URLs and keys are visible to admins only.Until changed or deleted

What leaves the instance

  • Requests to the GitHub API, made by the server with your own token.
  • AI insights, only when an admin has configured a provider: the metrics already on screen go to that provider. Run logs and code are never sent.
  • Email and Slack or webhook alerts, only to destinations an admin set up.

GitDash ships no analytics, tracking pixels or third-party scripts. The hosting platform may keep its own request logs; check your host's policy.

Removing your data

Sign out to delete the session cookie, and revoke the token or OAuth App on GitHub to cut access entirely. On an organization-mode instance, ask its admin to remove your user record. For gitdash.info, open an issue at github.com/dinhdobathi1992/gitdash.

PreviousRelease Notes

GitDash v4.7.1 — GitHub Actions Dashboard

Open source on GitHubData & privacyReport an issue