Privacy Policy
Last updated: 15 July 2026
Who we are
Issue Atlas is operated by Midz Labs (James Middleton), at atlas.midz.dev. This policy explains what data we handle, why, and what control you have. Using the service is also covered by our Terms of Service.
What we handle, and why
Your GitHub identity (when you sign in). When you sign in with GitHub we receive your GitHub user id, username and avatar. To keep you signed in, we store your username and a GitHub access token in one encrypted, essential cookie (AES-256-GCM) — no advertising or tracking cookies. Your id and avatar are held in the account record described below. This is how we know who you are and which repositories you're allowed to see.
Repository content. For repositories the app is installed on, we read their issues, pull requests, labels and native dependency links (GitHub's "blocked by" relationships and sub-issues) to build and cache your dependency graph. We re-check with GitHub whether you can read a repository before we show it, so you never see anything you couldn't already see on GitHub.
Billing (paid plans). Payments are handled entirely by GitHub Marketplace. GitHub processes the payment — we never see or store your card or bank details. We store only the billing metadata GitHub sends us: your account id, plan, seat count, and a record of billing events. For organisation plans we also record which member holds a seat, with timestamps, so seats can be managed.
Account cache. We keep a small record of accounts we've seen: GitHub user id, username, avatar, and first- and last-seen timestamps.
What we don't do
- We don't sell or share your data.
- We don't run ad networks or third-party trackers.
- We don't feed your issue text into analytics.
- We never receive your payment details.
Cookies
One essential cookie: the encrypted session cookie described above, which keeps you signed in. That's it — no analytics, advertising, or cross-site tracking cookies.
Storage, retention & deletion
Your dependency graph is cached in our database and can always be rebuilt from GitHub. When you uninstall the app we stop collecting data and delete the cached repository data and access tokens for those repositories. Billing records are kept for a short retention window after cancellation (so the account can be reconciled), then purged. The service runs on a private server, with secrets kept server-side.
Who else is involved
GitHub is our only essential processor — it provides your identity, the repository data we read, and all billing. GitHub's handling of your data is covered by the GitHub Privacy Statement, and GitHub's terms also apply to any purchase. We also use a hosting provider to run the service. We don't share your data with anyone else.
Your controls
- Stop collection and trigger deletion: uninstall the Issue Atlas GitHub App from the account or repositories.
- Manage or cancel a paid plan: through GitHub Marketplace.
- Access or deletion requests: email atlas@midz.dev and we'll help.
Changes to this policy
We may update this policy as the service evolves. If we make a material change we'll flag it here or in the app. The "last updated" date at the top always shows the current version.
Contact
Questions, or a data request? Email atlas@midz.dev.