What we collect, why we collect it, how long we keep it, and how to get it changed or deleted. Last updated 4 August 2026.
Elyan Labs LLC, Louisiana, USA, operates RepoAppraisal and is responsible for the personal data described here. Contact for any privacy request: scottbphone12@gmail.com.
Email and account identifier: to sign you in, to attach reports to your account, and to send you the report you ordered plus transactional notices about it. Public GitHub data: to produce the appraisal you requested. Order records: to fulfil the order and to meet accounting obligations. Server logs: security, abuse prevention, and debugging.
We use a session cookie to keep you signed in, and nothing else. It is required for the site to function, it expires when your session ends or shortly after, and it is not used to profile you or track you across other websites. There are no advertising or analytics cookies.
Only the service providers needed to run the service: Google (sign-in), our payment processor (checkout and billing), and our hosting provider (servers and delivery). Each processes data on our behalf under its own terms. We may also disclose data if legally compelled to do so.
Account records and order records are kept while your account is active, and afterwards only as long as needed for accounting and legal obligations. Server logs are kept for a short operational period. Generated reports are kept so you can retrieve them; you can ask us to delete them at any time. If you ask us to delete your account, we delete it.
Wherever you live, and regardless of whether a specific statute applies to you, we will honour these requests:
These mirror rights described in the EU/UK GDPR and the California Consumer Privacy Act. We honour them as a matter of policy. We do not claim any specific compliance certification, accreditation, or third-party audit under those or any other regime.
To make a request, email scottbphone12@gmail.com from the address on the account, or with enough detail for us to identify the record. We aim to respond within 30 days.
Case studies and comparable sets may reference public GitHub accounts belonging to people who never used this service. We cite only public, factual metrics, and we attach no valuation or authenticity judgment to a named third party. Any such person may have their account removed from any published page on request — see the Removal & Correction Policy. No reason is required and we do not argue about it.
Traffic is served over HTTPS and access to stored records is restricted. No system is perfectly secure, and we do not claim otherwise. The service is not directed at children under 13 and we do not knowingly collect their data.
If this policy changes materially, the “last updated” date above will change and the revised policy will be posted here.