Theforeman
- The documents do not say whether your data trains AI.
- The policy rules out using your data for targeted ads.
- Data is shared only with the providers who run the service.
- The documents do not say who can read your content.
A project site that logs IPs briefly, shares hosting with GitHub/YouTube, and lets you ask to erase most personal data.
Agent Trust Hub uses AI and may make mistakes. Review reports and confirm their contents before relying on them.
Collected
Name, email, IP addresses, browser strings, survey answers, and optional debug logs.
Read the exact line
Privacy policy
“Data that identifies you IP addresses Browser UserAgent strings Debug archives Answers to survey questions”
Training
They use logs and posts for community stats, support, spam checks, and contacting you about bugs.
Read the exact line
Privacy policy
“The webserver logs are used to produce statistics about the community, such as popularity of different browsers, operating system packages, plugins, etc.”
Sharing
They say they do not share with third parties except hosts like GitHub and YouTube, or the law.
Read the exact line
Privacy policy
“The Foreman project does not share data with 3rd parties, except for hosting requirements (e.g. GitHub, YouTube) as detailed below, or when required to by law.”
Kept
Website logs are deleted after 4 weeks; other data needs a contact request and git history stays.
Read the exact line
Privacy policy
“The webserver (Apache) logs will contain IP addresses, timestamps, and UserAgent strings - these are log-rotated and deleted after 4 weeks.”
Controls
You can skip giving data, use a fake name, control emails, and email them to access or erase data.
Read the exact line
Privacy policy
“If you would like to exercise any of these rights, you may do so by contacting the Foreman Project at contact us or on Matrix.”
Fine print
They will post material policy changes on the announcements list and the front page.
Read the exact line
Privacy policy
“Material changes will be posted to the Announcements list and posted to the front page of the website.”
Expand “Read the exact line” to see the source alongside the explanation.
What you can turn off
The controls and opt-outs their own documents describe, and where they say to find them.
Ask to access, fix, or erase your data
Contact the Foreman Project via the contact us page or on Matrix
Turn down Redmine and Discourse emails
Account preferences in Redmine and Discourse
Use a and skip real email in commits
Redmine, Discourse, and git commit messages
If a switch is not where they say, the deletion request above still applies.
Line by line
The lines that matter most, worst first.
If your name or email is in git history, they will not remove it even if you ask to be forgotten.
Read the exact line
Privacy policy
“Git commits will not be rewritten contributing to the codebase is opt-in, providing personally identifying information in commit messages is a further opt-in”
For example, an old commit with your real email stays public forever.
Forum and bug comments stay up; they only scramble your name and email.
Read the exact line
Privacy policy
“Posts are not removed, as we have a in retaining the history of discussions about our project”
For example, a rant you posted years ago remains readable after your account is .
Linking your email to GitHub can show your bug activity to everyone.
Read the exact line
Privacy policy
“This populates your Redmine “activity” page, which is public.”
For example, people can see which issues you closed without extra permission.
They keep forum IPs to catch fake or spam accounts.
Read the exact line
Privacy policy
“We also use the IP addresses to help identify sock puppeting and spam accounts.”
For example, two accounts from the same IP can be flagged as sockpuppets.
They do not sell your data, but GitHub, YouTube, Fastly, and similar hosts still see it.
Read the exact line
Privacy policy
“The Foreman project does not share data with 3rd parties, except for hosting requirements (e.g. GitHub, YouTube) as detailed below, or when required to by law.”
For example, watching an embedded video sends data under YouTube’s policy.
The main site itself is not running ad or analytics cookies.
Read the exact line
Privacy policy
“The Foreman website is a static site which does not track, collect, store information or set cookies.”
For example, just reading docs does not create a Foreman account cookie.
Debug uploads only happen if you choose to send them.
Read the exact line
Privacy policy
“Use of this tool is entirely voluntary (it is never run automatically), and the data is used by our developers to assist users in debugging complex problems.”
For example, they will not auto-upload your server logs.
Optional survey emails are dropped after they finish the yearly analysis.
Read the exact line
Privacy policy
“Such addresses are stored until the survey analysis is complete, and then deleted from the raw survey data before publication.”
For example, your survey email should not stay in the published dataset.
Big privacy changes are announced, not hidden.
Read the exact line
Privacy policy
“Material changes will be posted to the Announcements list and posted to the front page of the website.”
For example, a new log type should show up on the homepage and mailing list.
You can use a fake name on Redmine and Discourse.
Read the exact line
Privacy policy
“we do not mandate use of real names, and using will not affect the services.”
For example, you can sign up as “NightOwl” instead of your legal name.
Words to know
Legal words from the lines above, in plain English.
- de-identified
- Data with your name and obvious identifiers removed, though it can sometimes still be traced back to you. For example, your chats with names stripped out may still be kept and studied after you delete your account.
- third parties
- Any company or person other than you and the app, such as advertisers, partners or analytics firms. For example, an analytics company that receives a record of every screen you tap is a third party.
- opt in
- Something is off until you actively say yes to it. For example, marketing emails that only start after you tick a box are opt in.
- legitimate interest
- A legal reason that lets a company use your data without asking, when it decides its own need outweighs your privacy. For example, an app may analyse how you use it to improve the product, without ever asking you.
- cookies
- Small files a website saves on your device so it can recognise you and remember what you did. For example, a cookie keeps you logged in and can also tell an ad company which sites you visited.
- pseudonymous
- Your name is swapped for a code, but the company keeps the key and can still link the data back to you. For example, your chats are filed under user 48213 instead of your name, but staff can still look up who that is.
How we got here · grade A · score 57/100 · 15 of 15 policy answers backed by a verified quote · 7 not stated
What does the app collect beyond what it needs to work?
Besides name and email for accounts, they collect IPs, UserAgent strings, debug archives, and survey answers.
Does it record your voice, face or body, and what happens to that?
The policy does not describe collecting voice, face, or body data.
Are your chats and uploads used to train AI models, and is that off by default?
Not stated in the documents.
Can employees or contractors read your conversations, and when?
Not stated in the documents.
Are you profiled or tracked for advertising?
They say the website does not track or set cookies; they do not describe ads or ad profiles.
Do they sell or share your data, and can you opt out?
They say they do not share with third parties except hosting (GitHub, YouTube, Fastly) or the law.
What rights do they take over what you type and what the AI makes?
Not stated in the documents.
How long do they keep your data after you delete it, and can you delete it in the app?
Website logs go after four weeks; other deletion is by contacting them, and git and public posts are kept.
Does it build a lasting memory or profile of you, and can you see, edit or turn it off?
Not stated in the documents.
Do they commit to basic security, and have they leaked data?
Debug data is stored in a secure location, limited to a few developers, and deleted regularly.
Is there a real age gate, and are teens protected?
Not stated in the documents.
Will they tell you when the rules change, and is the policy specific?
The policy is dated 10 May 2024 and says material changes go to the announcements list and front page.
Can they close your account without warning, and can you get your data out first?
Not stated in the documents.
If something goes wrong, who pays?
Not stated in the documents.
Do subscriptions renew on their own, and can you get a refund?
No paid subscriptions or refunds are described.
The privacy policy is 1,352 words at a fairly hard level (Flesch reading ease 53).