RATATOSKRATATOSK
Sign in

Effective July 31, 2026

Privacy policy

RATATOSK (ratatosk.io) is a CNCF release analysis service. This page describes what the service stores and how it is used.

What is stored

  • Account: your email address, name, and profile picture link, as provided by GitHub or Google when you sign in.
  • Settings: language, theme, your stack (watched projects), notification preferences, and a personal RSS feed token.
  • Automatically: a sign-in session cookie and language/theme cookies. Visit statistics are collected in-house, without third-party analytics services, and are not linked to your account.

How it is used

  • Signing you in and showing your profile.
  • Sending the email notifications you have turned on. All notifications are off by default.
  • Serving content in the language you chose.

Retention and deletion

  • Account data is deleted immediately when you delete your account (Settings → Delete account), together with your stack and settings.
  • Email delivery logs are kept for operational review and purged automatically on a regular schedule.
  • Server access logs never record query parameters (such as version numbers sent to the API), and IP addresses are masked before writing (IPv4 /24, IPv6 /48). Logs rotate within days. Traffic passes through a CDN upstream, which processes connection data under its own policy.
  • Requests to the hosted MCP endpoint (ratatosk.io/mcp) are processed statelessly: the request contents (such as the stack configuration and versions you send) pass through server memory during processing only and are never written to any log. The access log records that a call to /mcp was made, along with connection metadata (masked IP, country code, client User-Agent string, request size, status code, and the like) — never what was queried. That metadata is covered by the same access-log policy above (masking, rotation within days).

Third parties

  • Personal data is never sold or shared for advertising.
  • Email delivery and hosting rely on external infrastructure; only the minimum needed to operate, such as your email address for delivery, passes through it. Sign-in uses your GitHub or Google account.

Contact