Legal
Privacy Policy
Last updated 2026-09-01
Operative policy — pending final owner/legal review.
The short version
Commit Archive displays information that is already public on GitHub, collects the minimum personal data needed to run a paid service, and gives contributors real control — including instant opt-out from all public display.
Public repository data
Archive pages are built from the public GitHub API: repository metadata, public commit activity, releases, and public profile information (username, display name, avatar) of contributors. We never display commit email addresses; internally, emails observed in public commit metadata are stored only as one-way hashes used to group a contributor’s own commits.
Data we collect directly
- Purchases: Stripe processes payment; we store the Stripe session/payment identifiers, amount, and the purchaser email Stripe provides so we can deliver receipts and status emails. We never see card numbers.
- GitHub sign-in: when you sign in (opt-out, claims, voting) we store your GitHub numeric ID, username, display name, and avatar. We request no repository permissions and never store your GitHub access token.
- Email: transactional email delivery state is stored so we don’t double-send.
- Anti-abuse: rate limiting uses short-lived, keyed one-way hashes of network identifiers. Raw IP addresses are not stored in our database.
- Requests you send us: report/removal forms store what you submit, including a contact email if you provide one.
Cookies
One HttpOnly session cookie after GitHub sign-in, plus a short-lived cookie during the sign-in redirect. No advertising or cross-site tracking cookies. Cloudflare Turnstile (bot protection) sets its own functional cookie during checkout.
Contributor control
- Linked contributors (commits tied to your GitHub account): sign in and opt out instantly — removal from all public display, across all entries and future editions.
- Unlinked contributors: use the privacy removal request. We verify with the minimum private evidence necessary and never expose it.
Retention
Archive content persists as a permanent public record (that is the product), subject to removal and opt-out rights above. Payment records are kept as legally required. Anti-abuse buckets expire within days; sessions within weeks. Details per table are documented in the project’s data-model documentation.
Sharing
Service providers only: Cloudflare (hosting), Stripe (payments), GitHub (public API), Resend (email). We do not sell personal data.
Contact
Privacy questions and data requests: Contact.