Skip to content
Privacy Policy · v1.0 · Effective 2026-04-30

Privacy Policy

We collect the minimum data needed to verify reviewers and run the platform. We do not sell data. We do not run advertising. We do not embed third-party trackers. The full details are below.

1. What we collect

Reviewer accounts (GitHub OAuth)

When you sign in with GitHub, the OAuth flow grants us read-only access to a narrow public-profile scope. Specifically, we collect and store:

We do not request access to: private repositories, private email addresses, gists, packages, billing, or any other private GitHub data. The OAuth scope is read:user.

Visitor analytics

For everyone (signed-in or not), we log first-party page-view events to our own database. Each event records:

No cookies. No fingerprinting. No third-party scripts. Logs are retained for 90 days for editorial decisions about what to cover next, then aggregated and discarded.

2. How we use it

3. What we do not do

4. Cookies

We use the following cookies and only the following cookies:

Cookie Purpose Duration
__Host-gs_sessionReviewer session after GitHub OAuth30 days · HttpOnly · Secure · SameSite=Lax
__Host-gs_oauth_stateCSRF protection during OAuth handshake10 minutes · HttpOnly · Secure

No advertising cookies. No analytics cookies. No third-party cookies of any kind. Both cookies above are first-party only.

5. Your rights (GDPR, CCPA, and beyond)

You have the following rights regardless of where you live, on the strictest reading of GDPR and CCPA:

All requests honored within 30 days. Send to privacy@gitshowcase.com from the email address tied to your GitHub account, or via the contact page.

6. Data location and processors

All site data is stored on Cloudflare infrastructure (Workers, KV, D1, R2) in regions selected automatically for low-latency reads. Cloudflare is the only sub-processor. We do not use any other third-party service to store, process, or transmit user data.

7. Children

GitShowcase is not directed to children under 16, and we do not knowingly collect data from anyone under 16. If you believe we have, email privacy@gitshowcase.com and we'll delete the account immediately.

8. Changes to this policy

This policy is versioned. Material changes are announced 30 days in advance via the homepage and via email to active reviewers. The current version is v1.0 effective 2026-04-30. Previous versions are archived and linkable.

Questions?

Email privacy@gitshowcase.com or visit the contact page. We respond within 5 business days; data-rights requests within 30.