Signing
Fettle's releases aren't signed yet: a signing certificate costs money, and the free ones for open-source projects go to projects that are already widely known. Fettle is new. Until it's signed, Windows may say the publisher is unknown the first time you run it.
Each release lists the SHA-256 checksum of every download, so you can check that the file you have is the one that was built.
How a release is built
A release starts when the maintainer tags a version in the public repository. GitHub Actions then builds the installer and the portable zip from that tag's source, runs every test, and records a build attestation: a signed note of which source and which build made each file.
Nobody builds a release on their own PC, and a release isn't public until the maintainer has looked it over and published it.
Who does what
Author and reviewer: candygoogy, who maintains Fettle. Changes from anyone else are reviewed before they're merged.
Approver: candygoogy approves every release before it's published.
Privacy
Fettle sends nothing on its own, except the update check: it asks this website for the newest version number, sending nothing about your PC, and you can turn it off in Settings. A receipt is uploaded only when you ask for a share link.