Privacy Policy

Last updated: 2026-09-28.

Who we are

We are Locally Build Limited, a company registered in England and Wales.

What information we collect

Anonymous browsing data

When you visit our website or the Locally Account, Simple Analytics collects the following on our behalf, anonymously:

  • Your country
  • Which pages you visit
  • Your browser type (like Chrome or Firefox)
  • Your device type (desktop, mobile, or tablet)
  • Referring website (where you came from)

Simple Analytics (a company based in the EU) is privacy-focused and does not use tracking cookies. We cannot identify who you are from this data.

We also use Cloudflare as a security and performance service. Cloudflare may collect technical information like your IP address and set strictly necessary cookies for security purposes.

When you fill in a form on our website

If you get in touch using our contact form, we keep your name, email address, company (if you give one) and your message. If you ask to talk to sales, we keep your name, email address, company, its size, your role (if you give one) and what you'd like to use Locally for. We use these only to reply to you, and they're stored in our own database.

When you sign in to your Locally Account

In addition to the anonymous browsing data above, when you sign in to your Locally Account we collect:

  • Your GitHub User ID, Display Name, Username, Email Address and profile picture, which GitHub shares with us when you sign in, along with when you last signed in.
  • The configuration of any CI Trusts (OIDC) you set up in your Locally Account - the display name you give each trust, the issuer URL, the subject filter and (where you set one) the audience.
  • The display name (which defaults to your computer's name), platform (e.g. macOS) and architecture (e.g. arm64) of any Installation that you link to your Locally Account.
  • Your newsletter subscription preference (if you opt in to our newsletter).
  • An email address you leave on our waitlist. We may let people into the Locally Account in batches; if we do and you sign in before we've let you in, you can leave one so we can tell you when you're in, and remove it from the waitlist page at any time.
  • Anything you post in the issue tracker: the title, description, comments and votes, and the display name you choose. Public issues and comments can be seen by anyone signed in to a Locally Account; private ones only by you, your team (for a team issue) and us. If you close your account, your comments and votes, and the issues you raised for yourself, are deleted; issues you raised for a team stay with the team, under the display name you gave.
  • An activity log of what happens in your Locally Account and your teams: who did what, and when - for example signing in or out (including failed attempts), changing your settings, adding an Installation or changing a team. It doesn't record your IP address or browser.

We collect this information to provide the core functionality of the Locally service and, with your consent, to send you relevant updates via our newsletter. You can unsubscribe from our newsletter at any time either by updating your preferences in your Locally Account, or by clicking the unsubscribe link in our emails, and you'll be unsubscribed immediately (note that any newsletters which are sent at the same time as you unsubscribe may still arrive, but you won't receive any more).

We also email you about your account when we need to - for example to let you in from the waitlist, about your team, about security, or about changes to our terms - and, once paid plans launch, about payments. These aren't marketing, so they're sent whether or not you've opted in to the newsletter. We send all of our emails, including the newsletter, through Resend.

Our newsletter mailing list is held by Resend rather than in our own database. When you opt in, from your Locally Account or by signing up on our website without an account, we add your email address to it. If you unsubscribe using the link in one of our emails, we turn the setting off in your Locally Account too, and if you close your account, we remove your email address from the list.

When you're part of a team

  • Which teams you're in, and your role in each.
  • Anything you or your teammates upload to the team, such as Locally Runbooks and Locally Policies. We store this on your team's behalf and sync it to the Installations of everyone in the team. If it contains information about other people, your team is responsible for it.
  • Your team's Locally Directory, which shows your teammates how many of each type of resource you've created recently. It's built from usage analytics (below), so it only includes you if you've turned those on.

When you use the Locally application

Most of what you do with Locally stays on your machine and never reaches us. The Locally application does send the following to the Locally API:

  • To keep your Installation running: when you set up an Installation, its display name, platform, architecture and the version of Locally you're using. Each time Locally starts, it checks for updates to Locally and to the plugins you have installed (sending which plugins and versions you have). While it's running, it checks your installation certificate every hour, renews it when needed, and syncs your team's content. Each of these requests includes your Installation ID, the version of Locally, and your platform and architecture.
  • When you run Locally in CI: the identity token your CI provider issues (for example GitHub Actions), which identifies the repository, workflow and branch it came from and who triggered it. We use it to check it matches a CI Trust you've set up.
  • Usage analytics, if you turn them on: your Installation ID, the date, the version of Locally, how long it ran, and for each type of resource you created, how many, and which API versions and SKUs you used. Never the names, settings or contents of your resources. We use this to decide which services to work on next, and to build your team's Locally Directory.
  • Crash reports, if you turn them on: when Locally or one of its plugins crashes, what failed, the command you were running, the version of Locally, your platform and architecture, the error message and a stack trace. For a plugin, this includes its most recent log output. Before sending, we remove your home folder path and common credential formats (such as storage account keys, passwords in connection strings, shared access signatures and bearer tokens), but a report may still include other secrets that appear in log output, as well as things like resource IDs, hostnames, IP addresses or file paths. Reports are saved on your machine first, so you can see what would be sent.

You choose whether to share usage analytics and crash reports when you run locally setup, and you can change your mind at any time by running it again.

When you create some types of resources, Locally may download container images from public registries such as Docker Hub or the Microsoft Container Registry. On macOS and Windows it also downloads one when it first starts. These downloads go directly from your machine to that registry, which will see your IP address and handle it under its own privacy policy.

Our server logs

Like most websites, our servers log the requests they receive, including your IP address, so we can keep the service secure and fix problems.

Legal basis for processing

We process your information based on:

  • Legitimate interests: To understand how our website is used and improve our services (Simple Analytics)
  • Legitimate interests: To reply when you get in touch using our contact or talk-to-sales forms
  • Legitimate interests: To protect our website from security threats and ensure proper performance (Cloudflare, our server logs and the activity log)
  • Legitimate interests: To keep your Installations running and up to date
  • Contract performance: To provide the Locally Account service functionality (user data, CI Trusts, Installations, teams, the issue tracker and the waitlist), including the emails we send you about your account
  • Consent: To send you newsletter updates (only if you opt in). You can withdraw your consent at any time in your Locally Account settings, using the unsubscribe link in any of our emails, or by contacting us.
  • Consent: To collect usage analytics and crash reports from the Locally application (only if you turn them on). You can turn them off at any time by running locally setup again.

Where your information is processed

Your information is processed in:

  • Our servers: European Union, hosted on Railway (a US-based provider)
  • Resend: European Union (a US-based provider)
  • Simple Analytics: European Union
  • Cloudflare: may process data globally, including outside the EU
  • GitHub: United States (when you sign in with GitHub)
  • Discord: United States (if you join our Discord server)

Where a provider may process data outside the UK or EU, we rely on appropriate safeguards (currently Standard Contractual Clauses).

How long we keep your information

We hold on to different types of information for different lengths of time:

  • Your Locally Account record and the data associated with it (your linked Installations, CI Trusts, team memberships and newsletter preference): for as long as your account is open.
  • The activity log: 30 days from the date of each entry.
  • Waitlist email addresses (if you left one): until you remove yours, or you get access.
  • Contact-form and talk-to-sales messages: 12 months after you message us.
  • Newsletter sign-ups: until you unsubscribe. After that we keep a record that you've unsubscribed so we don't email you again. If you close your Locally Account, we remove your email address from the list entirely.
  • Usage analytics: 90 days.
  • Crash reports: 30 days from when we receive them.
  • Our server logs: up to 30 days, as per our hosting provider's retention policy.
  • Website analytics data: as per Simple Analytics' retention policy (see their privacy policy for details).
  • Cloudflare security data: as per Cloudflare's retention policy (typically 30 days for logs).
  • Records of the emails we've sent you: as per Resend's retention policy.

These periods are for our live systems. Once something is deleted, a copy may stay in our automated backups for up to two weeks, until that backup expires.

You can close your account (and remove any data associated with it) at any time by signing in to your Locally Account and using the "Close Account" feature within Settings. If you own a team, have added Locally Runbooks that a team still uses, or are the contact for an open team issue, you'll need to hand those over to another member or remove them first; if you're the only member of a team, that means deleting the team. Closing your account removes your data immediately from our live systems, though it may remain in automated backups for up to two weeks before being purged. Two things are the exception: entries about you in the activity log, which stay until they reach their normal 30-day limit and are then deleted, and issues you raised for a team, which stay with the team under the display name you gave. Alternatively you can do this by contacting us using our contact form and we'll close your account, remove all your data, and confirm when that's done.

Who we share your information with

  • Simple Analytics (our EU-based analytics provider)
  • Cloudflare (our US-based security and performance provider)
  • Railway (our hosting provider - EU region)
  • Resend (our email provider - EU region), to send our newsletter and the emails about your account
  • GitHub (to sign you in - GitHub's privacy policy applies)
  • Discord (if you join our Discord server for community support - Discord's privacy policy applies)
  • We do not sell or share your information with anyone else

Keeping your information safe

Everything sent to and from Locally is encrypted in transit. We also encrypt the email addresses in your Locally Account and the details in the activity log in our database, and our internal tools aren't reachable from the internet.

Your rights

Under the UK GDPR, you have the right to:

  • Ask what information we have about you (right of access)
  • Ask us to correct wrong information (right of rectification)
  • Ask us to delete your information (right of erasure)
  • Object to how we use your information (right to object)
  • Ask us to limit how we use your information (right to restrict processing)
  • Get a copy of your information in a usable format (right to data portability)

Where we process your information on the basis of legitimate interests (for example our use of Simple Analytics for website analytics, or Cloudflare for security and performance), you have a specific right under Article 21 of the UK GDPR to object to that processing. If you object, we'll stop unless we have compelling legitimate grounds that override your interests, rights and freedoms.

We do not use your information for any automated decision-making or profiling that produces legal or similarly significant effects for you.

To use any of these rights, please get in touch using our contact form. We will respond within two weeks.

If you're not happy with how we handle your request, you can complain to the Information Commissioner's Office (ICO) at ico.org.uk.

Cookies

We don't set cookies on our website. When you sign in to your Locally Account, we set:

  • A cookie that keeps you signed in, for up to 30 days.
  • A few short-lived cookies that protect the sign-in process, which last up to 15 minutes.
  • A cookie that remembers if you've dismissed the setup card on your dashboard, for up to a year.

None of these are used for tracking or advertising. Strictly necessary cookies may also be set automatically by Cloudflare for website security and performance - these are essential for the website to function properly.

Simple Analytics does not use cookies - it uses a privacy-friendly method to collect website statistics without tracking you.

Changes to this policy

We may update this privacy policy from time to time. Changes will be posted on this page, and the "Last updated" date at the top shows when we last changed it. If you have a Locally Account, you'll be asked to accept the new version the next time you sign in.


Got a question about this privacy policy, or about something that isn't covered here? Feel free to reach out and we'll get back to you.

A local cloud for you and your agents.

Your Azure infrastructure, running on your machine. Deploy in seconds, break things freely, and ship to Azure when you're ready.