Privacy Policy
Last updated: 2026-08-15 (event counting for similar repositories)
This page explains what data GitHub Star History processes when you visit, why, and what rights you have. It is written to satisfy GDPR (EU/France) and CalOPPA/CCPA-style disclosure expectations for a small, non-commercial site.
1. Who is responsible for your data
@Mubelotix operates GitHub Star History and is the data controller for the processing described here. Contact: mubelotix@gmail.com (also acting as data protection contact / "DPO" for this site: mubelotix@gmail.com).
2. What we process
| Data | Source | Detail |
|---|---|---|
| Analytics visit data | Self-hosted analytics (s.dera.page) | Page views, referrer, and browser/device type. IP addresses are anonymized before storage, so no individual visitor is identifiable from stored data. When the "Do Not Track" (DNT) signal is set in your browser, analytics are completely ignored and no data is collected. We also count events (e.g. clicks on recommendations) to measure accuracy of our models and plan future improvements. |
| Server request logs | Web server / reverse proxy | Method, path, and status code only. No query strings containing personal data, no full IP retained beyond transient rate-limiting (see §5). |
| GitHub public data | Public data from our server; avatar images from GitHub's CDN | Public repository, user, and avatar-image data you explicitly search for. This is public data GitHub already serves; we don't store search history tied to you. |
We do not use cookies for tracking, do not sell data, and do not build user profiles.
We cache metadata for almost all public GitHub repositories that have gained some traction. This metadata is public data served by GitHub, stored on our servers so the site works faster and reliably. It may include the repository owner's username, but it is not tied to you as a visitor in any way.
3. Why we process it, and our legal basis
- Analytics & server logs: legitimate interest (GDPR Art. 6(1)(f)): understanding traffic and keeping the site reliable and secure, done in the least intrusive way possible (anonymized/aggregated). Analytics is handled by the privacy-friendly, self-hosted Umami software. When the "Do Not Track" (DNT) signal is set in your browser, analytics are completely ignored and no data is collected. No consent banner is required for this because no tracking cookies or cross-site identifiers are used.
- Repository metadata caching: legitimate interest (Art. 6(1)(f)) — improving site performance and reliability using data GitHub already makes public, with no additional profiling.
- GitHub images: loading avatar images requires contacting GitHub's CDN (Art. 6(1)(b)-adjacent / legitimate interest), triggered only by the data you view.
4. Third parties
| Third party | Purpose | Data shared |
|---|---|---|
| GitHub | Public data search feature | Avatar images loaded directly from GitHub's CDN |
5. Retention
- No persistent logs tied to individual users.
- Rate-limiting IP data is held in memory only, for the duration needed to enforce rate limits, and is never written to disk or a database.
- Analytics data is retained only in anonymized/aggregated form.
6. Your rights
Under GDPR (and equivalent rights under CCPA if applicable to you), you can:
- Access: ask what data we hold about you
- Rectification: correct inaccurate data
- Erasure: ask us to delete data
- Portability: receive your data in a portable format
- Object: object to processing based on legitimate interest
Since we don't maintain individual visitor profiles, most requests will simply confirm we hold no identifiable data about you. To exercise any right, contact mubelotix@gmail.com. You can also lodge a complaint with your national data protection authority (in France: the CNIL, www.cnil.fr).
7. Changes to this policy
We'll update the "Last updated" date above when this policy changes materially.