privacy.
This notice covers www.slashscore.com and the profiles in the index. It sets out what we collect, the basis we collect it on, how long we keep it, who else handles it, and the rights you have over it.
who we are
slashscore is run by WIN GRAVITY SRL, registered office at Dacia Street No. 1, Iași, Romania. We are the data controller for everything described here. For anything on this page, write to privacy@slashscore.com.
what we store
Handles, datasources, and public numbers. In full:
- handles
- your public handle on each source we read, and which source it came from
- public metrics
- the counts the formula reads: commits, merged pull requests, reviews, stars, followers
- technologies
- top languages across your public repositories, by bytes
- location
- a city or country name, resolved from your public profile field to a coarse gazetteer entry
- scores
- your current score and dated monthly snapshots of it
- streaks & achievements
- derived from the public contribution calendar
- view counts
- how many times your profile page was viewed this week, as a number with no viewer identity attached
what we never store
- your email
- GitHub returns one at sign-in. It is dropped before the row is written, so it never reaches the database
- your OAuth token
- used once to confirm which account you control, then discarded. It is never persisted and never used to read anything private
- your real name
- we index handles, not people
- private activity
- private repositories and private contributions are not read and count toward nothing
- your IP address
- not logged by us, and not stored by our analytics
where it comes from
GitHub's public API, and nothing else today. We read it with our own credential against data GitHub already serves to anyone who asks, never with your token. The schema has been multi-source since day one, so other sources can land later. If one does, it appears on this page before it appears in the index.
why we index people who never signed up
Your profile can be in the index without you having registered. The lawful basis for that is legitimate interest, GDPR Art. 6(1)(f), which holds only if it passes a three-part test. Ours is set out here so you can check it rather than take it on trust.
The interest. Operating an index that scores public professional activity across developers generally. A comparative score is only meaningful against a broad pool, so the interest cannot be served by a pool limited to people who registered.
Necessity. We read only the fields the published formula consumes, only from public sources, and we do not combine them with data GitHub does not already publish. There is no less intrusive way to produce the same result.
Balance. The data is professional activity you have already published, not private life. We hold no email, no name, no contact details, and no special-category data, and the location is a city rather than an address. The impact on you is therefore limited, and it is reduced further by erasure being immediate and unconditional.
Legitimate interest carries a right to object under Art. 21. If you object, we erase rather than assess the objection. That is the removal flow, and it completes in seconds.
When you claim a profile, the basis for the extra things claiming unlocks (the session, the dashboard, connected accounts) is your consent and the service you asked for, Art. 6(1)(a) and 6(1)(b).
removal
Sign in with the matching GitHub account on the removal page and everything about you is erased on the spot: score, metrics, history, technologies, streak, achievements, the profile page, and the badge. It is a hard delete, not a hidden flag.
One thing survives, and it is there to protect you: a one-way fingerprint (a SHA-256 hash) of your handle goes on a suppression list, so that our crawler refuses to index you again. The list holds no readable handles, only hashes. If you later change your mind and claim your profile, that entry is deleted, because your consent overrides your earlier objection.
Lost access to the GitHub account, or deleted it? Email privacy@slashscore.com and we do it by hand.
analytics
We use Vercel Analytics and Vercel Speed Insights to count page views and measure loading performance. Both are cookieless and neither writes anything to your browser. They do not build a profile of you, follow you between sites, or feed any advertising network. Vercel derives a short-lived one-way hash from the request (including the IP address) purely to tell one visit from another for a day, and we never see the IP itself.
There is no Google Analytics, no advertising or social pixel, and no third-party script of any kind. Our fonts are served from our own domain, so loading a page does not tell anyone else that you were here.
who else touches it
As few companies as we can manage, each under a data processing agreement and none of them permitted to use your data for their own purposes:
- Vercel
- hosting, and the analytics described above
- Neon
- the managed Postgres database the index lives in
- GitHub
- the source we read from, and the identity provider for sign-in
These providers are US-based, so data reaches the United States. Those transfers run on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework. We do not sell data, and we do not share it with anyone for their own marketing.
how long we keep it
An unclaimed profile stays while its handle is in the index, refreshed rather than accumulated: metrics are recomputed daily and score snapshots are kept monthly so that a profile can show its own history. A claimed profile stays until you remove it. Erasure is immediate on request. Suppression hashes are kept indefinitely by design, since their whole job is to keep saying no on your behalf.
your rights
Under the GDPR you have the following rights, and none of them require a reason:
- access
- ask what we hold about you. Most of it is already on your public profile page
- rectification
- ask us to correct something wrong. Scores are computed, so the usual fix is a recompute
- erasure
- have everything deleted. Verified and immediate, below
- objection
- object to the indexing itself. We act on this by deleting, not by arguing
- portability
- get what we hold in a machine-readable form
- restriction
- ask us to freeze processing while a dispute is open
Email privacy@slashscore.com. We answer within 30 days, usually much sooner, and there is no charge. If you would rather not go through us, you can complain directly to your local data protection authority. Ours is Romania's ANSPDCP, at dataprotection.ro.
children
slashscore is not aimed at children and we do not knowingly index anyone under 16. If you believe a profile belongs to a child, email us and we will remove it without asking them to prove anything.
security
Sign-in cookies are signed, HTTP-only, and locked to this origin, so a script cannot read them and a neighbouring subdomain cannot plant one. Traffic is HTTPS throughout. The strongest protection is structural: the database holds no passwords, no emails, and no tokens, so a breach would expose material that is already public.
changes to this notice
If we change what we collect or why, this page changes first and the date at the top moves. Material changes to the basis for indexing will also be announced in updates.
Still unsure why you are in the index? The FAQ covers it in less formal terms, and the methodology shows exactly what the score is made of.
/slashscore · public data only · no email, no tracking · privacy