Data collected
GitHub account identity, authorized repository metadata, traffic aggregates, referrers, popular paths, stars, preferences, and operational diagnostics.
This pre-launch policy describes the data boundaries implemented by the service and remains subject to legal review.
GitHub account identity, authorized repository metadata, traffic aggregates, referrers, popular paths, stars, preferences, and operational diagnostics.
User access tokens are used only during sign-in and are never stored. Repository access tokens are short-lived and are never written to storage.
Your plan controls how much history stays visible. Deleted data remains recoverable for 30 days before it is permanently removed. Account controls provide a portable JSON export and permanent deletion of your analytics, reports, badges, sessions, pending background work, communication history, and any administrator records that identify you.
Service messages are kept separate from optional marketing and digest preferences. After account deletion, a minimal irreversible record of bounces, complaints, and unsubscribes is kept so those addresses are never emailed again.