Privacy Policy
GitHub Contributors by Location
Last updated: July 12, 2026
This Privacy Policy explains how the GitHub Contributors by Location Chrome extension (the “Extension”) handles information. The Extension helps users find contributors to public GitHub repositories by profile location and review public contribution and repository technology information.
Information the Extension accesses
The Extension accesses only the information needed to provide its features:
- The URL of the active browser tab when you open the Extension, to determine whether you are viewing a GitHub repository or public GitHub user profile.
- Public information returned by GitHub, including usernames, profile URLs, profile locations, public repository contribution activity, repository names, programming languages, and repository topics.
- A GitHub user access token created when you choose to sign in with GitHub.
- Your search query, cached public profile data, and the most recent search results.
The Extension does not access page contents unrelated to identifying the active GitHub repository or profile. It does not collect passwords, payment information, browsing history, or private repository contents.
How information is used
Information is used solely to:
- Identify the public GitHub repository or user profile you choose to analyze.
- Search, filter, display, and cache public GitHub contributor information.
- Authenticate GitHub API requests and provide a higher per-user API rate limit.
- Restore your latest results and generate contribution and technology summaries.
Information is not sold, rented, used for advertising, used to create advertising profiles, or shared for purposes unrelated to the Extension’s functionality.
GitHub authentication
GitHub sign-in is optional. If you sign in, GitHub presents its own authorization screen and issues a user access token for the Extension. The Extension stores that token in Chrome’s local extension storage and sends it only to GitHub for API requests.
A Vercel-hosted callback service exchanges GitHub’s temporary authorization code for the user access token. The callback service processes the code and token only to complete sign-in and does not intentionally retain either value. The GitHub App client secret is stored securely as a Vercel environment secret and is not included in the Extension.
Local storage and retention
The Extension uses chrome.storage.local to store:
- The GitHub user access token until you sign out, uninstall the Extension, clear the Extension’s storage, or revoke authorization through GitHub.
- Minimal public GitHub profile data for up to seven days to reduce repeated API requests.
- The latest completed search and its displayed results until replaced by another search, the Extension’s storage is cleared, or the Extension is uninstalled.
Signing out removes the locally stored GitHub access token. You can remove all locally stored Extension data by clearing the Extension’s site data in Chrome or uninstalling the Extension.
Third-party services
The Extension communicates with:
- GitHub, for authentication and public API data.
- Vercel, which hosts the OAuth code-exchange endpoint and may process standard service metadata such as IP address, request time, and technical logs under its own privacy policy.
- LinkedIn only if you choose to click the developer attribution link.
Chrome permissions
- activeTab: identifies the GitHub repository or profile in the active tab after you open the Extension.
- identity: opens and completes the optional GitHub authorization flow.
- storage: stores the access token, cache, and latest results locally.
- Host access to api.github.com: retrieves public GitHub data and performs authenticated API requests.
- Host access to the Vercel callback: completes the GitHub OAuth token exchange.
Data security
Reasonable safeguards are used to limit data access and exposure. The GitHub App client secret is kept outside the Extension, OAuth requests use state and PKCE protections, callback requests are restricted to the configured Extension origin, and tokens are not intentionally logged by the application. No method of storage or transmission is completely secure, however.
Your choices
You may use the Extension without signing in, subject to GitHub’s lower anonymous API limits. You can sign out at any time, revoke the GitHub App under your GitHub account settings, clear local Extension data, or uninstall the Extension.
Chrome Web Store Limited Use
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Changes to this policy
This policy may be updated when the Extension’s functionality or data practices change. The “Last updated” date will identify the latest version.
Contact
For privacy questions or requests, contact alshabanov27@gmail.com.