Legal
Terms of service
What we agree to provide, what you agree not to do with it, and how the money works.
1. Who you are contracting with
The service at runners.io is operated by Lineman. The registered company name, number and office are not stated on this page yet. Until they are, treat this document as a statement of intent rather than a contract — see the draft notice above.
“You” means the person or organisation with an account. “The service” means the runners, the Terraform-compatible runs, the dashboard and the APIs.
2. Your account
You need an account to use the service, and you are responsible for what happens under it. Keep your credentials to yourself, and tell us promptly if you believe someone else has them.
Connecting the GitHub App gives us the access GitHub shows you at the moment you install it, and no more. You can remove it at any time from your GitHub settings, which stops us being able to run anything for you.
3. What we provide
We run your CI jobs on machines we operate and hand the results back to GitHub. Each job gets a fresh virtual machine that is destroyed when the job ends, and no virtual machine is reused between jobs — not between customers and not between two of your own jobs.
We do not commit to an uptime figure. We would rather say that than publish a number we have not measured over a meaningful period. If you need a service level in writing, ask us and we will talk about it rather than point at a page.
Caches and sticky disks are an optimisation, not storage. We reclaim an Actions cache entry unread for seven days and a sticky disk unattached for seven days, and a build must be able to reconstruct anything it keeps there. The documentation says which is which.
The Docker layer cache is different: nothing deletes its layers by age. They are kept until your organisation’s layer cache reaches 10 GiB, and then we delete the layers that no cache tag of yours still points to and that no push has written for seven days. A layer a tag still points to is kept however old it is. Its documentation says when a push writes a layer, and the privacy policy how to have layers deleted sooner.
4. Your code and your data
Your code is yours. We claim no rights over it, we do not use it to train anything, and we run it only to do what you asked — execute the job.
We store the output of your CI jobs. While a job runs we collect its log from inside the machine, so that you can watch the build in the dashboard as it happens rather than wait for GitHub to publish the log at the end. We also keep the names of its tests and the failure messages of any that failed, read from JUnit XML the build writes. Both are deleted 90 days after the job finished, by a sweep that runs on its own. The Actions runner uploads the log to GitHub as well, and GitHub keeps that copy on its own terms.
The output of your Terraform plans and applies is kept until you delete the run or the workspace it ran in, through the API; nothing deletes it by age. Caches, sticky disks and the Docker layer cache are reclaimed as clause 3 says.
A deleted log or test result can survive in an encrypted backup for up to eight more days. The same is true of anything else deleted from our databases, a Terraform run or workspace included.
The privacy policy says the same in more detail, and what else we keep and for how long — including the record of each job, which an invoice is built from and which outlives the job’s output.
5. What you may not run
Do not use the service to:
- mine cryptocurrency, or run any workload whose purpose is to consume compute for its own sake. We detect this and stop the job;
- attack, scan or disrupt anyone else’s systems, including ours;
- break the law, or infringe someone else’s rights;
- resell the service, or provide it to third parties as though it were your own, without agreeing that with us first;
- deliberately try to escape the virtual machine or reach another customer’s data. Telling us about a way to do it is welcome; doing it for any other reason is not.
These are the rules that let one machine serve several customers safely. We enforce them, and a job that trips a detector is stopped rather than silently throttled.
6. Fees, and how billing works
Compute is billed by the minute at the rate published on the pricing page, which is read from the same rate card that produces your invoice — the figure you are shown is the figure that bills. Add-ons, where you use them, are billed on what you actually consume.
We invoice monthly in arrears and take payment through Stripe. Card details are entered on Stripe’s pages; we never hold them.
If a payment fails we tell you before anything changes. The sequence is: we notify you and retry; if it stays unpaid your account is degraded, which limits how many jobs run at once; and only after that is it restricted. Each step is announced in the dashboard with the date the next one happens. We do not cut a customer off without warning.
7. Suspension and ending the agreement
You can stop at any time by removing the GitHub App and closing your account. You pay for what you used up to that point and nothing after it.
We may suspend an account that is breaking clause 5, that is not paying, or that is putting the service at risk for others. Except where the risk is immediate, we will tell you first and give you a chance to fix it.
8. Liability
This clause is not drafted. A liability cap and the exclusions around it are the part of an agreement that most deserves a lawyer, and putting a confident-sounding paragraph here would be pretending we had one. It will be written before these terms come into force.
What we can say plainly in the meantime: CI is infrastructure, and you should not build a process around us that has no way of surviving us being down.
9. Changes to these terms
We will tell existing customers by email before a change that affects them takes effect, and this page will say the date it came into force. A change we make silently is not one you agreed to.
10. Governing law
Not yet decided. The jurisdiction whose law applies and whose courts hear a dispute will be stated here before these terms come into force. It is not something to guess at, and a wrong guess would be the most expensive line on the page.
Questions about this page go to legal@runners.io. See also the terms of service and the privacy policy.