Data collected
GitHub account identity, authorized repository metadata, traffic aggregates, referrers, popular paths, stars, preferences, and operational diagnostics.
This pre-launch policy describes the data boundaries implemented by the service and remains subject to legal review.
GitHub account identity, authorized repository metadata, traffic aggregates, referrers, popular paths, stars, preferences, and operational diagnostics.
User access tokens are used transiently during sign-in and are not stored. Installation tokens are short-lived and cached only in process memory.
Plan retention controls visibility. Data remains recoverable during a 30-day grace period before batch purge. Account controls provide a portable JSON export and permanent deletion of analytics, reports, badges, sessions, queued work, communication history, and attributable administrator identity.
Operational messages are separated from optional marketing and digest preferences. Minimal hashed bounce, complaint, and unsubscribe suppression is retained to prevent prohibited redelivery after account deletion.