Privacy Policy

Privacy Policy

What we collect, why we collect it, how long we keep it, and how to get it changed or deleted. Last updated 4 August 2026.

1. Who is responsible

Elyan Labs LLC, Louisiana, USA, operates RepoAppraisal and is responsible for the personal data described here. Contact for any privacy request: scottbphone12@gmail.com.

2. What we collect

  • Your email address, via Google sign-in. If you sign in, Google returns your email address and a Google account identifier to us. We do not receive your Google password. We do not request access to your Gmail, Drive, contacts, or calendar.
  • Public GitHub data. Repository names, star and fork counts, contribution counts, pull request records, and public profile fields for the accounts being appraised. This is data that GitHub already publishes to anyone.
  • Order records. If you buy a report: what you bought, when, and the processor's transaction reference. We never see or store your card number. Payment card handling is performed entirely by our third-party payment processor.
  • Ordinary server logs. IP address, timestamp, requested URL, user agent — recorded by the web server for security and troubleshooting.

3. Why we collect it

Email and account identifier: to sign you in, to attach reports to your account, and to send you the report you ordered plus transactional notices about it. Public GitHub data: to produce the appraisal you requested. Order records: to fulfil the order and to meet accounting obligations. Server logs: security, abuse prevention, and debugging.

4. What we do not do

  • We do not sell personal data, and we never have.
  • We do not share personal data with advertisers or data brokers.
  • We do not run third-party advertising or cross-site tracking pixels.
  • We do not send marketing email to addresses collected at sign-in unless you separately ask us to.

5. Cookies

We use a session cookie to keep you signed in, and nothing else. It is required for the site to function, it expires when your session ends or shortly after, and it is not used to profile you or track you across other websites. There are no advertising or analytics cookies.

6. Who else touches the data

Only the service providers needed to run the service: Google (sign-in), our payment processor (checkout and billing), and our hosting provider (servers and delivery). Each processes data on our behalf under its own terms. We may also disclose data if legally compelled to do so.

7. How long we keep it

Account records and order records are kept while your account is active, and afterwards only as long as needed for accounting and legal obligations. Server logs are kept for a short operational period. Generated reports are kept so you can retrieve them; you can ask us to delete them at any time. If you ask us to delete your account, we delete it.

8. Your rights

Wherever you live, and regardless of whether a specific statute applies to you, we will honour these requests:

  • Access — tell you what we hold about you.
  • Correction — fix anything inaccurate.
  • Erasure — delete your account and associated records.
  • Portability — give you your data in a machine-readable file.
  • Objection — stop a particular use, including removal from any published page under our Removal & Correction Policy.

These mirror rights described in the EU/UK GDPR and the California Consumer Privacy Act. We honour them as a matter of policy. We do not claim any specific compliance certification, accreditation, or third-party audit under those or any other regime.

To make a request, email scottbphone12@gmail.com from the address on the account, or with enough detail for us to identify the record. We aim to respond within 30 days.

9. Public data about developers who are not users

Case studies and comparable sets may reference public GitHub accounts belonging to people who never used this service. We cite only public, factual metrics, and we attach no valuation or authenticity judgment to a named third party. Any such person may have their account removed from any published page on request — see the Removal & Correction Policy. No reason is required and we do not argue about it.

10. Security and children

Traffic is served over HTTPS and access to stored records is restricted. No system is perfectly secure, and we do not claim otherwise. The service is not directed at children under 13 and we do not knowingly collect their data.

11. Changes

If this policy changes materially, the “last updated” date above will change and the revised policy will be posted here.

Written in plain English for readability. This is a description of our practices, not legal advice.