bpm

Legal

Privacy Policy

We collect the minimum information needed to operate the registry — and nothing more. No third-party trackers, no advertising, no sale of data.

Last updated May 10, 2026

What we store

Cookies

We set exactly one cookie, bpm_session, for browser logins. It is httpOnly, SameSite=Lax, and contains a signed JWT. We do not set analytics or advertising cookies. The bpm CLI does not set cookies at all.

What we don't do

Email use

We use your email only for account recovery and rare, account-specific service notifications (for example, a security advisory affecting a package you own). We do not send marketing email.

Account deletion

Email us — or open an issue on the project's repository — to delete your account. Packages other users depend on may be retained in a tombstoned, read-only form so consumers can still install pinned versions of bnl.lock.

Data residency & backups

The registry runs on infrastructure in the EU. Database snapshots are taken daily and retained for 30 days for disaster recovery.

Contact

Questions about this policy? Open an issue on github.com/bnlang/bpm.