Privacy
gitmyhub renders showcase pages from public GitHub data. This page covers both sides of that: the public data we display about GitHub users (including people who have never visited us), and the data we store about you if you claim your page or subscribe.
Plain-English summary: a gitmyhub page can be viewed for any GitHub username. Everything on it comes from GitHub's public API, is cached for at most 24 hours, and links back to the source. If you don't want a page for your username served at all, email us and we'll stop serving it.
For a given username we fetch, via GitHub's documented API: the public profile (login, numeric ID, name, bio, avatar, website, location, company, follower and repo counts, join date), public repositories (up to 200: names, descriptions, languages, stars, forks, topics, timestamps), the public profile README, pinned repository names, public organization members, and the public contribution calendar. We display this with attribution and links to GitHub.
Signing in uses GitHub OAuth with the read-only read:user scope — profile identity only, no access to your repositories' contents.
We do not store passwords. We do not run third-party trackers, analytics, or advertising scripts anywhere on the site.
gmh_sess — your session (random token; HttpOnly; 30-day sliding expiry). Set when you sign in.gmh_oauth_state — a 10-minute anti-forgery token used only during the GitHub sign-in redirect.That's the complete list. After a Polar checkout, your browser's sessionStorage may briefly hold the checkout reference used to link the purchase to your account; it's cleared once the link completes.
The primary sign-in is GitHub OAuth, which involves no email. The service also supports signing in via an emailed single-use link: if you use it, we process your email address to send that link (through our email provider, Migadu) and keep it in your session. We send no other email — no newsletters, no marketing. Purchase receipts come from the payment provider, not from us.
Visitor IP addresses are used only inside short-lived abuse counters (rate limits on page renders, billing endpoints, and domain management). These counters expire within seconds to hours and IPs are never stored durably or attached to accounts or pages.
The social-preview image for a page is rendered by us, on our infrastructure, from the same public profile data — no third-party image service. Avatars for it are fetched only from GitHub's own image hosts. Rendered cards are cached for up to 24 hours.
Plain-English repo explanations and tile teasers are fetched from explaingit, a BitVibe Labs sibling service. The only data sent to it is the public repository identifier (owner and repo name) — never your identity, cookies, or IP address.
On the Pro checkout pages only, your browser loads the payment form from Polar (and its script from the jsDelivr CDN). No third-party code loads on profile pages.
Full erasure is two actions on the Account page, in this order: "Remove my page customization" deletes your page content; "Delete account" then removes your subscription record, license-key binding, and session. Deleting the account alone deliberately leaves your page content in place, so run the removal first if you want everything gone.
For users in the EU/UK: displaying public GitHub data rests on legitimate interest (Art. 6(1)(f)) with the objection route above; processing your claimed account, page content, and billing data rests on performance of a contract (Art. 6(1)(b)). You have the rights of access, rectification, erasure, restriction, portability, and objection — email us to exercise any of them. The controller is BitVibe Labs, the trading name of an individual operator established in Greece; the lead supervisory authority is the Hellenic Data Protection Authority, and you may also complain to your local authority.
The service is not directed at children under 16. If you believe a child has claimed a page, email [email protected] and we'll delete the account.
Material changes will be reflected here with the "Updated" date above. Non-material changes (typos, clarifications) are made in place.
BitVibe Labs · [email protected]