starscope

Privacy and personal data

What starscope processes

starscope reads public data from the GitHub API: username, display name, bio, company, location, website, avatar, follower count, public repos and the social accounts declared on the profile. This concerns people who starred or forked a repo and never asked for any of this. That is precisely why the named list is visible to the owner of the analysed repo, and to nobody else.

What is shared

A share link exposes aggregates only: number of people, distribution by company and by location, and three avatars. No name, no identifier, no social link. The CSV export is restricted to the owner of the analysis.

Retention

Profiles are refreshed after 30 days and deleted after 12 months without consultation. GitHub tokens are encrypted at rest (AES-256-GCM) and carry no write permission: the sign-in requests no scope.

Deletion and objection

To have your profile removed from starscope, or to object to its processing, send a direct message to @DarkPancakes on X. Deletion is carried out within 30 days and applies to every analysis.

Server logs

There is no analytics script, no advertising tracker and no tracking cookie on this site: the pages set no cookie until you sign in or change language. The web server does keep a technical log of each request — truncated IP address (last octet removed), date, path, referrer and browser — kept 14 days and used only to count page views and spot failures. Avatars are served by GitHub, so GitHub sees the IP address of anyone loading a page that displays them.

Hosting

Dedicated server in France. No data is passed to a third party, no advertising tracker.