Privacy
Privacy Policy
GitHub Signals is an editorial service that discovers useful open-source projects, creates short explanations about them, and publishes selected content to supported social platforms. This policy explains what data we process through the public project catalog and the publishing tools used by authorized GitHub Signals editors.
Information we process
- Public website activity. Our hosting and security providers may process IP address, browser and device information, requested pages, timestamps, referrer information, and security events.
- Site preferences and analytics. The site stores the selected light or dark theme in browser local storage. When analytics is enabled on the published site, Google Analytics may process cookies or similar identifiers and information about visits and interactions.
- Public repository information. We process public GitHub repository names, URLs, descriptions, topics, star counts, and related public metadata used to create the catalog and editorial content.
- Connected social accounts. When an authorized editor connects TikTok, Facebook, Instagram, or another provider through OAuth, we may receive the account identifier, display name, username, profile image, connected Page or professional-account information, granted permissions, and access or refresh tokens. We do not receive the social-account password.
- TikTok data. Depending on the permissions approved and granted, our publishing tools may access basic profile information, additional profile fields, account statistics, public video metadata, and the ability to upload or publish selected content and check publication status.
- Meta data. Depending on the permissions approved and granted, our tools may access Facebook Page and linked Instagram professional-account details, publishing permissions, content identifiers, comments, and insights used for publication and monitoring.
- Publication records. We retain selected media, captions, destination settings, platform post identifiers and URLs, status and error information, publication timestamps, and available engagement statistics needed to operate and audit the publishing workflow.
How we use information
- operate, secure, troubleshoot, and improve the website and publishing workflow;
- authenticate authorized editors and maintain connected social channels;
- publish only editor-selected content and reconcile its delivery status;
- show accurate platform links and aggregated publication statistics;
- respond to privacy, security, support, and deletion requests; and
- comply with applicable law and platform policies.
Sharing and service providers
We do not sell personal information. We disclose information only as needed to operate the service, follow an authorized publishing request, comply with law, or protect the service. Providers may include Cloudflare and our hosting provider for delivery and security, Google Analytics for website measurement when enabled, and the social platform selected for OAuth and publication. Their handling of information is also governed by their own policies.
Retention
OAuth tokens are retained while a channel remains connected or until they expire, are revoked, or are deleted. Unpublished media and operational logs are retained only as reasonably needed for publishing, troubleshooting, security, and recovery. Public publication records may be retained to keep the catalog accurate. Backups may retain deleted information temporarily until they are overwritten under the normal backup cycle.
Your choices and deletion
A connected-account owner may revoke GitHub Signals in the social platform's authorized-app settings. Revocation prevents new authorized API access but may not delete content already published on that platform. For deletion instructions, see Data Deletion. You may also block optional analytics using browser controls or supported privacy tools.
Security and international processing
We use access controls, encrypted HTTPS connections, restricted service accounts, and limited network exposure. No system is perfectly secure. Service providers and social platforms may process information in countries other than the one where a visitor or account owner lives, subject to their safeguards and applicable law.
Children
GitHub Signals is not directed to children under 13, and the publishing tools are restricted to authorized editors. We do not knowingly collect personal information from children through these tools.
Policy changes
We may update this policy as the service or provider requirements change. The effective date at the top identifies the current version.
Contact
Privacy and data requests: githubsignals@gmail.com.