/slashscore

privacy.

This notice covers www.slashscore.com and the profiles in the index. It sets out what we collect, the basis we collect it on, how long we keep it, who else handles it, and the rights you have over it.

last updated 4 August 2026controller: WIN GRAVITY SRL

who we are

slashscore is run by WIN GRAVITY SRL, registered office at Dacia Street No. 1, Iași, Romania. We are the data controller for everything described here. For anything on this page, write to privacy@slashscore.com.

what we store

Handles, datasources, and public numbers. In full:

handles
your public handle on each source we read, and which source it came from
public metrics
the counts the formula reads: commits, merged pull requests, reviews, stars, followers
technologies
top languages across your public repositories, by bytes
location
a city or country name, resolved from your public profile field to a coarse gazetteer entry
scores
your current score and dated monthly snapshots of it
streaks & achievements
derived from the public contribution calendar
view counts
how many times your profile page was viewed this week, as a number with no viewer identity attached

what we never store

your email
GitHub returns one at sign-in. It is dropped before the row is written, so it never reaches the database
your OAuth token
used once to confirm which account you control, then discarded. It is never persisted and never used to read anything private
your real name
we index handles, not people
private activity
private repositories and private contributions are not read and count toward nothing
your IP address
not logged by us, and not stored by our analytics

where it comes from

GitHub's public API, and nothing else today. We read it with our own credential against data GitHub already serves to anyone who asks, never with your token. The schema has been multi-source since day one, so other sources can land later. If one does, it appears on this page before it appears in the index.

why we index people who never signed up

Your profile can be in the index without you having registered. The lawful basis for that is legitimate interest, GDPR Art. 6(1)(f), which holds only if it passes a three-part test. Ours is set out here so you can check it rather than take it on trust.

The interest. Operating an index that scores public professional activity across developers generally. A comparative score is only meaningful against a broad pool, so the interest cannot be served by a pool limited to people who registered.

Necessity. We read only the fields the published formula consumes, only from public sources, and we do not combine them with data GitHub does not already publish. There is no less intrusive way to produce the same result.

Balance. The data is professional activity you have already published, not private life. We hold no email, no name, no contact details, and no special-category data, and the location is a city rather than an address. The impact on you is therefore limited, and it is reduced further by erasure being immediate and unconditional.

Legitimate interest carries a right to object under Art. 21. If you object, we erase rather than assess the objection. That is the removal flow, and it completes in seconds.

When you claim a profile, the basis for the extra things claiming unlocks (the session, the dashboard, connected accounts) is your consent and the service you asked for, Art. 6(1)(a) and 6(1)(b).

removal

Sign in with the matching GitHub account on the removal page and everything about you is erased on the spot: score, metrics, history, technologies, streak, achievements, the profile page, and the badge. It is a hard delete, not a hidden flag.

One thing survives, and it is there to protect you: a one-way fingerprint (a SHA-256 hash) of your handle goes on a suppression list, so that our crawler refuses to index you again. The list holds no readable handles, only hashes. If you later change your mind and claim your profile, that entry is deleted, because your consent overrides your earlier objection.

Lost access to the GitHub account, or deleted it? Email privacy@slashscore.com and we do it by hand.

cookies

Three, all our own, all functional, and none of them set until you click something. If you are just reading the graph, a profile, or this page, we set no cookies at all.

__Host-ss_session
7 days. keeps you signed in after you claim a profile. Holds a signed reference to your account row, nothing else
__Host-ss_oauth_state
10 minutes. a random value that proves the GitHub sign-in you come back from is the one you started. Standard CSRF protection
__Host-ss_oauth_intent
10 minutes. remembers whether the sign-in was to claim a profile or to erase one, since both use the same GitHub round-trip

There is no cookie banner because none of these require consent. Under the ePrivacy rules, storage that is strictly necessary to provide a service you explicitly asked for is exempt, which covers a sign-in cookie and the tokens that protect that sign-in. If we ever set a cookie that falls outside that exemption, we will ask you first.

analytics

We use Vercel Analytics and Vercel Speed Insights to count page views and measure loading performance. Both are cookieless and neither writes anything to your browser. They do not build a profile of you, follow you between sites, or feed any advertising network. Vercel derives a short-lived one-way hash from the request (including the IP address) purely to tell one visit from another for a day, and we never see the IP itself.

There is no Google Analytics, no advertising or social pixel, and no third-party script of any kind. Our fonts are served from our own domain, so loading a page does not tell anyone else that you were here.

who else touches it

As few companies as we can manage, each under a data processing agreement and none of them permitted to use your data for their own purposes:

Vercel
hosting, and the analytics described above
Neon
the managed Postgres database the index lives in
GitHub
the source we read from, and the identity provider for sign-in

These providers are US-based, so data reaches the United States. Those transfers run on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework. We do not sell data, and we do not share it with anyone for their own marketing.

how long we keep it

An unclaimed profile stays while its handle is in the index, refreshed rather than accumulated: metrics are recomputed daily and score snapshots are kept monthly so that a profile can show its own history. A claimed profile stays until you remove it. Erasure is immediate on request. Suppression hashes are kept indefinitely by design, since their whole job is to keep saying no on your behalf.

your rights

Under the GDPR you have the following rights, and none of them require a reason:

access
ask what we hold about you. Most of it is already on your public profile page
rectification
ask us to correct something wrong. Scores are computed, so the usual fix is a recompute
erasure
have everything deleted. Verified and immediate, below
objection
object to the indexing itself. We act on this by deleting, not by arguing
portability
get what we hold in a machine-readable form
restriction
ask us to freeze processing while a dispute is open

Email privacy@slashscore.com. We answer within 30 days, usually much sooner, and there is no charge. If you would rather not go through us, you can complain directly to your local data protection authority. Ours is Romania's ANSPDCP, at dataprotection.ro.

children

slashscore is not aimed at children and we do not knowingly index anyone under 16. If you believe a profile belongs to a child, email us and we will remove it without asking them to prove anything.

security

Sign-in cookies are signed, HTTP-only, and locked to this origin, so a script cannot read them and a neighbouring subdomain cannot plant one. Traffic is HTTPS throughout. The strongest protection is structural: the database holds no passwords, no emails, and no tokens, so a breach would expose material that is already public.

changes to this notice

If we change what we collect or why, this page changes first and the date at the top moves. Material changes to the basis for indexing will also be announced in updates.

Still unsure why you are in the index? The FAQ covers it in less formal terms, and the methodology shows exactly what the score is made of.

/slashscore · public data only · no email, no tracking · privacy