Privacy Policy_
Last updated: October 2026
1. Information We Collect
When you sign in with GitHub, we receive your public profile information (username, display name, avatar URL), access credentials and authorized activity data. If you link additional platforms (Bitbucket, Codeberg, or GitLab), we receive similar profile, activity and credential data from those services. If you link a secondary GitHub account (for example an EMU account) with the Chapa CLI, we store an encrypted access token for that account and use it only to read that account's activity; it is deleted when you unlink the account. An optional PostHog Cloud connection authorizes read-only access to one selected project and saved supported insight for one product. We read six completed UTC monthly active analytics identifier aggregates, not raw event or person exports. Analytics identifiers are not verified people.
2. How We Use Your Information
We use authorized development activity to compute your policy-labelled Developer Impact Profile and related badge, history and verification. Optional PostHog or Google Analytics aggregates can supply bounded adoption evidence with recorded repository participation and a GitHub-reported deployment association. Google Analytics data is read only after you connect it, with the read-only analytics.readonly scope, and is used only to compute these monthly aggregates. They do not establish unique people, personal ability, causal contribution, served code or revenue. We cache data to reduce API calls and do not sell your data. We use Vercel for hosting and analytics, Upstash Redis and Supabase for storage, Resend for email delivery, and PostHog for Chapa telemetry and the separate optional owner-authorized outcome connection.
3. Data Storage
Session data is stored in an encrypted HTTP-only cookie in your browser. Upstash Redis stores temporary caches and coordination records whose expiration varies by record type. Supabase stores durable account records, linked-platform credentials (including the encrypted token of a linked secondary GitHub account), supplemental activity, saved badge configuration, accepted scoring evidence, immutable policy-labelled receipts, history, verification issuance and CLI merge telemetry. CLI merge telemetry records are eligible for cleanup after 90 days. Optional PostHog access and refresh credentials are encrypted server-side; grant, project/insight selection and source-association details remain private service records. Public receipts include replay-safe aggregate counts, participation, evidence status and opaque references, without raw events, person records, credentials or the private selection. Immutable receipt aggregates remain until scoring withdrawal or account deletion; verification issuance does not have a blanket 30-day expiry and receipt history does not have a blanket 365-day cleanup promise. Limited raw artifacts have separate expiry rules. Account-scoped records remain while needed to provide Chapa or until you request deletion. Durable records are not deleted merely because a Redis cache entry expires. Content-free revision revocation records may remain after withdrawal/deletion, and independently downloaded public copies cannot be recalled.
4. Analytics
We use PostHog and Vercel Analytics for Chapa page views, errors and product events. Some events can include a public GitHub handle or selected badge configuration. This telemetry helps us operate and improve Chapa and is separate from your optional PostHog outcome connection. That connection requires owner consent, uses only project:read and insight:read for one project, and reuses existing GitHub access without broader scopes. Missing or unsupported outcome evidence leaves activity scoring available and is labelled unmeasured rather than observed zero.
5. Your Rights
You can sign out at any time to clear your session. You can revoke Chapa's GitHub access in GitHub settings under Authorized OAuth Apps and unlink Bitbucket, Codeberg, or GitLab accounts from your profile. You can unlink a linked secondary GitHub account in Settings or with the chapa unlink command, which deletes its stored token. You can disconnect optional PostHog access in Chapa settings: local credentials and selection are removed and a configuration tombstone blocks further use before a bounded provider revocation attempt. Chapa reports provider revocation failure separately from local disconnection; you can also manage the grant at PostHog. Disconnect does not erase already issued historical aggregates. To request scoring withdrawal or deletion of your Chapa account data, contact us below. Withdrawal/deletion removes public receipt access, but cannot recall copies independently downloaded earlier.
6. Contact
For privacy-related inquiries, contact us at support@chapa.thecreativetoken.com