Privacy Policy
Last updated: April 2026
What we collect
When you sign in, you install the StackProof GitHub App and choose which repositories to grant access to. The app requests read-only access to repository contents and metadata. We only read commit metadata (authors, dates, file paths) and dependency files. We do not store your source code.
We also store the results of our analysis: skill names, commit counts, confidence scores, and activity timelines derived from your repository history.
How we use it
- To build and display your public developer skill profile at
stackproof.io/username - To analyze commit metadata from your selected repositories and extract skill data
- To cache GitHub API responses and reduce redundant requests
We do not sell your data to third parties. We do not use your data for advertising.
How analysis works
When you select repositories for analysis, our worker service temporarily clones them to extract commit metadata (file types, commit counts, and timestamps). The cloned repository data is deleted immediately after analysis. Only the extracted skill summary is retained.
Public profiles
By default, your developer profile is publicly accessible at stackproof.io/username. If you would like your profile made private or deleted, contact us at hello@stackproof.io.
Data storage and security
Your data is stored in a PostgreSQL database on infrastructure we control. All connections to StackProof are encrypted via HTTPS. OAuth tokens are stored server-side and are never exposed to the browser. We do not store GitHub passwords.
Account deletion
You can delete your account at any time from your dashboard. When you delete your account, your profile is hidden immediately and your data is retained for 30 days in case you change your mind. After 30 days, all your data - including your profile, skills, and repository metadata - is permanently and irreversibly deleted.
To restore a deleted account within the 30-day window, simply sign in again with GitHub. You may also request deletion by emailing us at hello@stackproof.io.
Cookies and sessions
We use a single session cookie (connect.sid) to maintain your login state. This cookie is HTTP-only and is not accessible to JavaScript. We do not use tracking cookies or third-party analytics.
Third-party services
- GitHub: OAuth authentication and repository data
Your use of these services is subject to their respective privacy policies.
Changes to this policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date at the top of this page. Continued use of the Service after changes constitutes acceptance of the updated policy.
Contact
Questions about this policy? Email us at hello@stackproof.io.