Privacy Policy

GitHub Contributors by Location
Last updated: July 12, 2026

This Privacy Policy explains how the GitHub Contributors by Location Chrome extension (the “Extension”) handles information. The Extension helps users find contributors to public GitHub repositories by profile location and review public contribution and repository technology information.

Information the Extension accesses

The Extension accesses only the information needed to provide its features:

The Extension does not access page contents unrelated to identifying the active GitHub repository or profile. It does not collect passwords, payment information, browsing history, or private repository contents.

How information is used

Information is used solely to:

Information is not sold, rented, used for advertising, used to create advertising profiles, or shared for purposes unrelated to the Extension’s functionality.

GitHub authentication

GitHub sign-in is optional. If you sign in, GitHub presents its own authorization screen and issues a user access token for the Extension. The Extension stores that token in Chrome’s local extension storage and sends it only to GitHub for API requests.

A Vercel-hosted callback service exchanges GitHub’s temporary authorization code for the user access token. The callback service processes the code and token only to complete sign-in and does not intentionally retain either value. The GitHub App client secret is stored securely as a Vercel environment secret and is not included in the Extension.

Local storage and retention

The Extension uses chrome.storage.local to store:

Signing out removes the locally stored GitHub access token. You can remove all locally stored Extension data by clearing the Extension’s site data in Chrome or uninstalling the Extension.

Third-party services

The Extension communicates with:

Chrome permissions

Data security

Reasonable safeguards are used to limit data access and exposure. The GitHub App client secret is kept outside the Extension, OAuth requests use state and PKCE protections, callback requests are restricted to the configured Extension origin, and tokens are not intentionally logged by the application. No method of storage or transmission is completely secure, however.

Your choices

You may use the Extension without signing in, subject to GitHub’s lower anonymous API limits. You can sign out at any time, revoke the GitHub App under your GitHub account settings, clear local Extension data, or uninstall the Extension.

Chrome Web Store Limited Use

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Changes to this policy

This policy may be updated when the Extension’s functionality or data practices change. The “Last updated” date will identify the latest version.

Contact

For privacy questions or requests, contact alshabanov27@gmail.com.