LEGAL
Privacy policy
Last updated: July 26, 2026
Gitwork helps clients discover and contact developers using public GitHub activity. This policy explains what we collect, why we collect it, and the choices you have.
What the scores cover
Cards, rankings, and lineups are built from public GitHub activity only. We do not access private repositories. A score is not a complete measure of a developer's work or ability, especially for people whose primary work is private.
What we collect
Public GitHub data. When you scout a profile or browse country squads, we fetch public GitHub information (for example: username, avatar, repositories, contributions, collaborators on public repos, and location when listed on GitHub). We turn that into player cards, rankings, and related profile surfaces. We do not access private repositories.
Account data. If you sign in with GitHub (and optionally link Google on the same account), we store your provider user id, login or email, name, email (if shared by the provider), and profile image so we can run your session and dashboard. We also store your product plan (for example Developer, Pro, or Recruiter) and any paid-plan waitlist interest you submit.
Claimed profile details. Developers who claim a profile may add availability, a contact email, a contact URL, rates, and a short bio. You choose what to publish.
Linked packages. Claimed developers may link npm or PyPI packages on their profile. We store the package name, registry, repository URL when available, and download counts we fetch from public registry APIs (npm and pypistats for PyPI). Package ownership is checked against the GitHub repository metadata on that package.
Requests and messages. Clients may post hiring requests and send messages to developers. We store request text, message bodies, timestamps, and the accounts involved so threads can be shown in the dashboard.
Saved items and API keys. Signed-in users may save developer accounts and pitch setups for later. Developers may create API keys (we store a hash and metadata, not the full secret after creation). We may also store product feedback you submit, including page URL and user agent.
AI-generated content. Features such as scout briefs and Open Source CV may send public card signals and selected claim fields (for example bio or rates) to an AI provider so we can generate summaries. Generated outputs may be cached and shown on profiles or in the dashboard.
Usage and technical data.We may log IP-derived country (for default squad selection and profile visit analytics), page views, scout counts, search queries (including language and country filters used in talent search), and basic error logs. When you are signed in, we may record a login session (provider, start and last-seen times, approximate time on the platform) and an activity trail of in-product actions such as page views, profile views, searches, claim saves, messages, and saved pitches, so we can improve the product. When you view a developer profile, we may record which profile you opened, approximate time spent, visitor country, and your account id if you are signed in, for product insights and profile analytics for developers. If you click through from a Gitwork profile to that developer's GitHub page or portfolio / website link, we may record that outbound click the same way (including the destination URL for portfolio links). When you open the Insights tab on your dashboard, we may record that session and how long you stay, so we can improve the product. Your browser may store squad and card cache locally (IndexedDB and localStorage) to speed up repeat visits.
How we use data
We use collected data to:
- Score and display developer cards from public GitHub activity
- Run national lineups, search, and client shortlists
- Authenticate users and operate the claim and messaging features
- Show linked npm and PyPI download stats on claimed profiles
- Generate AI scout briefs and Open Source CV content when you use those features
- Send email notifications related to requests and replies (when enabled)
- Operate plans, waitlists, API access, and saved accounts or pitches
- Improve reliability, prevent abuse, and understand aggregate usage
- Analyze signed-in login sessions and in-product activity trails, profile visits, Insights tab usage (including time spent), search demand signals, and outbound GitHub and portfolio clicks (including visitor country and portfolio destination URL) to improve the product, and show aggregate insights to developers on their claimed profiles (view counts, countries, clicks; not visitor identities on the free tier)
We do not sell your personal data.
Third-party services
Gitwork relies on external providers, including:
- GitHub for OAuth sign-in and public profile data
- Google for optional account linking (when configured)
- npm for public package metadata and download counts
- PyPI for public package metadata
- pypistats.org for PyPI download counts
- AI providers for scout briefs and Open Source CV generation
- Vercel for hosting and analytics
- PostHog for product analytics (when configured)
- Neon for application database storage
- Redis for caching and rate limiting
- Resend for outbound and inbound email (when configured)
- Cloudflare R2 for optional archived card or lineup data (when configured)
Each provider processes data under its own terms. We only share what is needed to run the service.
Cookies and local storage
Sign-in uses session cookies managed by our auth system. We also use browser storage for theme preference (device, light, or dark), your selected country squad, and cached scout results. You can clear site data in your browser settings at any time.
Retention
Account, claim, request, message, linked package, plan, waitlist, and related records are kept while your account or the relevant content exists, unless we must delete them sooner for legal or operational reasons. Cached GitHub card data, collaborator lists, package metadata, and AI outputs may be refreshed or expired over time. Aggregate analytics may be kept longer in anonymized form.
Your choices
- Browse without signing in (limited features only)
- Update or remove claim details, linked packages, and related profile data
- Revoke API keys and manage linked sign-in providers from your dashboard
- Clear local browser cache for this site
- Contact us to ask about access, correction, or deletion where applicable
Because much of Gitwork is built from public GitHub profiles and public package registries, removing data from Gitwork does not remove information already published on those services.
Contact
Questions about this policy or your data: hello@gitwork.dev