REPOSHELF
Privacy Policy
This policy explains how the RepoShelf operator identified above handles information when you use the website or account features. Third-party repositories, demos, GitHub, Hugging Face, and your API/MCP client may separately process information under their own policies.
With optional analytics enabled, RepoShelf also records listing-to-demo and listing-to-save sequences, sign-in starts and completions, storefront row identifiers, and newly observed public fork verifications. These use pseudonymous browser/session identifiers rather than your GitHub account ID. They do not show what you do on third-party demos. Private listing reports contain your account reference, chosen reason and any explanation you provide; authorised administrators use them to investigate and record moderation decisions. Avoid including sensitive personal information. Moderation audit records include administrator account references, decisions and notes. Contact the operator through the contact details above for privacy or removal requests.
1. Information we handle
Account and authentication: GitHub provider identity and account ID, the Supabase user ID, display details supplied during sign-in, administrator role, and authentication sessions. GitHub and Supabase may process email and other provider profile information necessary for their sign-in services. RepoShelf does not ask for your GitHub password. Authentication and provider tokens are stored in secure HttpOnly cookies on HTTPS and are used server-side.
Your collection: liked project IDs, small saved listing snapshots, saved dates, verified public fork information, and verification times. GitHub forks are checked using your established GitHub identity. Private forks are not included. Manual Hugging Face Space tracking and legacy collection information may remain in local browser storage.
Optional viewing history: if you enable “Remember viewed projects”, we save project IDs, small listing snapshots, view timestamps and your hide-seen preference privately with your account. The recently viewed list shows the last 90 days; older entries are removed when you record another project view. You can stop future recording or clear your history across devices in My collection → Recently viewed. This functional account preference is separate from optional analytics.
Agreement records: your user ID, the Terms and Privacy Policy versions you accepted or acknowledged, and a server-generated timestamp. We do not collect a date of birth through the agreement form.
Public catalog information: public repository and Space metadata, README and supporting document excerpts or snapshots, demo screenshots, licences, and public community posts with provenance. Public does not necessarily mean that information is free of personal data; authors can contact us about corrections or removal requests.
Test promotion requests and payments: verified public repository ownership, your request, administrator review and notes, promotion status and remaining time, checkout/payment references, and refund and availability records. Stripe handles test checkout; do not enter real card details. RepoShelf does not store card numbers. Real payments are disabled in this phase. Promotion records are private to their owner and administrators; active test placements are shown only in administrator previews.
2. Optional usage analytics
First-party usage analytics are off in a browser until you choose to enable them. They use random browser and session identifiers, event IDs, event types, and project IDs to estimate visits, page views, searches, listing views, demo clicks, and fork/duplicate clicks. The server hashes identifiers before storage. Unique visitor estimates can count the same person separately on different devices or after browser storage is cleared.
The application analytics dataset does not store IP addresses, search text, or full browsing URLs. This does not mean that hosting and authentication providers never process IP addresses or request metadata: they may do so for delivery, security, abuse prevention, and operational logs. Browser privacy signals such as Do Not Track and Global Privacy Control disable application analytics; admin activity is also excluded. Withdrawal stops future collection in that browser, rather than automatically identifying or erasing earlier anonymous aggregates.
Analytics preferences for this browser
3. Why we use information
We use account and session information to authenticate you, provide saved collections, verify public forks, apply roles, protect the service, and respond to requests. Acceptance records show which agreement was made. Repository submission requests and scan results are stored privately with your account to process requested imports and show progress. Imported public repository metadata, README material and a generic submission provenance label enter the shared catalogue; the submitter’s account identity does not. Public catalog information supports discovery and relevant search results. Optional analytics help assess usage and catalog performance.
Where a legal basis is required, the basis depends on the activity and applicable law: delivering requested account features under our agreement, consent for optional analytics where required, compliance with legal obligations, and legitimate interests such as proportionate service security and catalog discovery where that basis is available and appropriate. Agreement to the Terms is not treated as blanket consent for every processing activity.
4. Storage, cookies, and providers
Essential cookies support GitHub/Supabase authentication, session renewal, sign-in security, and server-side public GitHub API reads. Local storage holds browser preferences, legacy saved items, and, only when analytics is enabled, analytics identifiers. Disabling essential cookies may prevent sign-in or account features.
RepoShelf uses Stripe for hosted test checkout and payment verification, Vercel for hosting, Supabase for authentication and account storage, and GitHub for sign-in, public repository access, and catalog workflows. GitHub-hosted catalog files include public catalog data and sync reports, not your private liked list, submission account identities, or authentication tokens. Optional AI overview generation may send public project text to Google Gemini if the operator enables it. Third-party demo or repository owners receive requests when you follow their links; external preview images, fonts, and other embedded resources may also result in requests to their hosts.
We do not sell personal information or share it for cross-context behavioural advertising.
5. International processing
These services may process information in countries different from yours. Exact storage locations depend on the configured service regions and provider operations. Applicable international-transfer requirements and safeguards depend on the countries and providers involved. Contact us for information about the configuration and safeguards relevant to your request.
6. Retention
Account collections, repository submission requests and scan results, roles, and acceptance records are generally retained while your account exists, unless you request deletion or another retention period is required for a lawful purpose. Detailed application analytics events and identity-deduplication data are retained for up to 90 days; aggregate daily totals and public catalog growth history may remain longer without the original per-event identifiers. Browser-local items remain until you remove them or clear storage. Authentication cookie lifetimes vary and sessions can be renewed. Provider operational logs and backups follow their own retention arrangements; deletion from backups may take additional time.
7. Your choices and requests
You can unlike projects, sign out, change optional analytics preferences above, and clear browser-local data. Use Account & data to download your account information or delete your account. Deletion does not remove repositories or forks from GitHub or automatically remove public catalogue listings. Reserved or running promotions must be resolved first; completed paid promotion records and moderation decisions may be retained privately with account references removed. Reports retain their outcome but reporter-provided explanation text is cleared. You can also contact the operator to request access, correction, deletion, or a portable copy of account information, and to exercise objection, restriction, withdrawal, or other rights available under the laws that apply to you. We may need proportionate identity verification before acting on an account request. Some information may need to be retained for legal obligations or other legally permitted reasons.
Privacy and deletion requests: . Please identify the account or listing involved, but never send passwords or access tokens. We do not charge for ordinary requests unless applicable law permits it. We respond within the time required by applicable law. Where available, you may complain to the relevant data-protection authority or other regulator.
8. Security and children
We use access controls, database row-level security, server-verified sessions, and encrypted transport on HTTPS to help protect account information. No service can guarantee absolute security. RepoShelf account features are intended for people aged 18 or older who can legally accept our Terms. Contact us if you believe a child’s account information has been collected inappropriately.
9. Policy changes
Updates are published with a new version. Material changes may require renewed acknowledgement, with notice where required. Optional analytics choices remain separate. The operator and contact details above identify who is responsible for this service.