Privacy Policy

Effective October 1, 2026. This is how we handle personal data — for visitors and customers in the EU/EEA, the UK, the United States and elsewhere.

1. Who is responsible

[COMPANY LEGAL NAME], [REGISTERED POSTAL ADDRESS] (“Blamewell”, “we”) is the controller of the personal data described here, except where a customer uploads other people’s data to analyse (see section 12, where we act as a processor).

Privacy contact: [PRIVACY EMAIL].

2. What we collect, why, and on what legal basis

Where the GDPR / UK GDPR applies we must have a legal basis for each use. This table is our record of it.

DataWhy (purpose)Legal basis (GDPR Art. 6)
Account: name, email, password (stored only as a one-way hash), the date and document version you accepted, and your age confirmationCreate and run your account; prove consentContract (6(1)(b)); legal obligation / defence of claims for the consent record
Security: sign-in time, IP address, browser/device string, active sessions, two-factor secret (encrypted) and recovery-code hashesKeep accounts safe, detect abuse and fraudLegitimate interests (6(1)(f)) — protecting our service and you
Payments and wallet: what you bought, amounts, payment-provider reference IDs, wallet top-ups, spending and refunds. We never see or store card numbers.Take payment, run your wallet and plan, issue receipts, prevent fraudContract (6(1)(b)); legal obligation for accounting and tax (6(1)(c))
Record of your agreement to immediate delivery when you buy a report, analysis or plan: time, version of the Terms, IP address and browserProve that you expressly agreed to immediate performance (consumer law)Legal obligation and defence of legal claims (6(1)(c), 6(1)(f))
Reports and analyses you order: the repository / GitHub username / organization you analysed, the report produced, settings you choseDeliver the service you asked forContract (6(1)(b))
Public GitHub data about developers (commits, contributions, public profile) read through GitHub’s public API to build analysesProvide the analysis serviceLegitimate interests (6(1)(f)) — see “people we analyse” in section 12
Files and text you upload (for example resumes for bulk analysis)Process them for youContract (6(1)(b)); we act as your processor — section 12
Your GitHub connection (if you choose to connect): an encrypted access tokenHigher rate limits and access you asked forConsent (6(1)(a)) — disconnect any time in Settings → Integrations
Support and refund messages, attachmentsAnswer you and resolve problemsContract (6(1)(b)); legitimate interests
Notification and email preferences; service emails (verification codes, receipts, security notices, alerts you switched on)Deliver what you asked for and keep you informed of your accountContract; legitimate interests. We send no third-party marketing.
Cookie choicesRemember your consent recordLegal obligation (ePrivacy) — the record itself is a strictly necessary cookie
Privacy requests you make and how we answered themProve we met our legal dutiesLegal obligation (6(1)(c))
Error and diagnostic data (if monitoring is enabled)Fix faultsLegitimate interests (6(1)(f))

We do not knowingly collect “special category” data (health, beliefs, biometrics…) and ask you not to upload it. We do not use your data to train AI models, and we do not sell it.

3. Who we share data with

Only with service providers (“processors” / “service providers”) that help us run Blamewell, under contracts that restrict them to our instructions — see the list of sub-processors — and where the law requires (for example a lawful request from authorities). We do not sell personal data and do not share it for cross-context behavioural advertising.

4. International transfers

Our providers may process data in the United States, the European Union, India and other countries (our hosting: [HOSTING PROVIDER AND REGION]). When personal data from the EEA, UK or Switzerland is transferred to a country without an adequacy decision we rely on Standard Contractual Clauses (and the UK Addendum), the EU–US Data Privacy Framework where the recipient is certified, and supplementary measures such as encryption in transit and at rest. You can ask us for a copy of the safeguards at the privacy address above.

5. How long we keep data

These are the periods our system applies automatically (a daily clean-up job deletes what has passed its period). Where a period is a default, it can only be changed within legal limits.

DataKept for
Account and settingsWhile your account is active. When you delete it: see section 6.
Verification / one-time codesDeleted within 24 hours of use or expiry
Sign-in sessionsUntil they expire or you sign out; deleted 30 days after they expired or were revoked
In-app notifications1 year
Paid-report, payment and wallet recordsAs tax and accounting law requires (generally up to 10 years), with your identity removed when you erase your account
Reports you orderedWhile your account exists. After erasure the report record is kept only as a financial record, without your identity
Uploaded resumes that were never paid for; wallet top-ups that were started but never completedDeleted automatically after 7 days (resumes) / 30 days (top-ups)
Record of your agreement to immediate delivery6 years (the period in which a consumer claim can still be brought)
Privacy requests and our answers3 years after the request is closed (open requests are never deleted)
Security and administrator audit logs3 years

6. Deleting your account — recoverable, then permanent

When you delete your account it is not erased at once. It is deactivated: you are signed out everywhere, paid plans stop, and we stop using your account (no alerts, digests, emails or scheduled analyses). For at least 60 days (never fewer than 60) it stays fully recoverable: sign in again and press “Restore my account” and everything comes back. You can also ask support to restore it.

When that period ends, your account and personal data are permanently erased and cannot be recovered: profile, sessions, notifications, settings, watches, wallet (any balance is forfeited), uploaded files and chat attachments. Records we must keep by law (payments, invoices) are kept without your identity. We tell you the exact date when you delete, in the confirmation email, and in a banner every time you sign in during the period.

Why we wait: so an accidental, coerced or hijacked deletion can be undone. During the period the data is only stored — not used. If you want faster erasure, tell us at the privacy address and we will assess your request under GDPR Art. 17.

7. Your rights if you are in the EEA, UK or Switzerland

  • Access and a copy — Settings → Privacy → Download my data.
  • Rectification — edit your profile in Settings, or send a request.
  • Erasure — Settings → Privacy → Delete account (section 6).
  • Restriction and objection (including to processing based on legitimate interests) — send a request.
  • Portability — the download is machine-readable JSON.
  • Withdraw consent at any time (cookie preferences; disconnect GitHub) without affecting earlier lawful processing.
  • Not to be subject to a decision based solely on automated processing with legal or similarly significant effects — we make none (section 11).
  • Complain to your data-protection authority (for example your national authority in the EU — list — or the ICO in the UK). We would appreciate the chance to help first.

Use Settings → Privacy → Privacy requests, or write to [PRIVACY EMAIL]. We answer within one month (extendable by two months for complex requests, and we will tell you why). We may need to verify it is you. Requests are free unless manifestly unfounded or excessive.

8. Notice for California residents (CCPA / CPRA) and other US states

We do not sell your personal information and we do not “share” it for cross-context behavioural advertising (as those terms are defined in California law), and we have no actual knowledge of selling or sharing the personal information of anyone under 16. We do not use or disclose sensitive personal information except to provide the service you asked for (your account log-in credentials are “sensitive” under California law; they are used only to sign you in). See Your privacy choices.

Categories collected in the last 12 months

CCPA categoryExamples from section 2Disclosed to (service providers)
IdentifiersName, email, IP address, account IDHosting, email delivery, payment processors
Customer records / commercial informationPurchases, plan, wallet activityPayment processors
Internet / network activitySign-in and usage logs, cookie choicesHosting, error monitoring
Professional information (only if you upload it)Resume contents you process with usStorage provider; AI provider if you enable AI insights
Sensitive personal informationAccount log-in credentials (hashed), authenticator secret (encrypted)None
InferencesScores and summaries in reports about repositories / developers you ask us to analyseAI provider if enabled

Sources: you; your device; GitHub’s public data; our payment processors. Purposes: section 2. We keep each category only as long as section 5 says.

Your California rights

To know what we collect and to receive a copy, to delete, to correct, to opt out of sale/sharing (nothing to opt out of — but you can ask us to confirm in writing), to limit use of sensitive information (we already limit it) and to not be discriminated against for using these rights. Make a request in Settings → Privacy, or by email to [PRIVACY EMAIL]. We verify requests by matching them to the signed-in account or a confirmation email, and answer within 45 days (we aim for 30). An authorized agent may act for you with your written permission and proof of their identity. If we refuse a request you may appeal by replying to our decision; if still unsatisfied you may contact your state attorney general.

Global Privacy Control. We honour the GPC browser signal as an opt-out of non-essential cookies. “Shine the Light”: we do not disclose personal information to third parties for their direct marketing.

Other states. Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and other states with privacy laws have similar rights of access, correction, deletion, portability and to opt out of targeted advertising, sale and profiling — we apply the rights in this section to everyone in the United States. To appeal a decision, reply to it with “appeal”.

9. Cookies

We set the cookies needed to keep you signed in and protect forms without asking. Everything else (functional, analytics, marketing) is off until you opt in, and refusing is as easy as accepting. See the Cookie Policy; change your choice any time with Cookie preferences in the footer.

10. Children

Blamewell is for people aged 16 or over and is not directed at children; we ask you to confirm your age when you sign up. If we learn we hold data of someone under 16 (or under 13 in the US) without valid parental consent we delete it. Tell us at the privacy address if you think this has happened.

11. Automated processing and profiling

Blamewell computes scores and summaries (for example repository health, bus factor, candidate screening reports). They are analytics to support a human’s decision, never a decision by themselves. We make no decision about you that produces legal or similarly significant effects by solely automated means. Some summaries are written with the help of an AI model (only when AI insights are enabled for your plan); the data sent is limited to what the summary needs.

12. Candidates and other people we analyse

Customers may analyse public GitHub profiles or upload resumes. For that content the customer is the controller and we are the processor: we process it only on their instructions, keep it only as long as needed for the analysis, and delete uploads that were never paid for after 7 days. Customers must have a lawful basis, must inform the people concerned (GDPR Art. 13/14), must not rely on a report as the sole basis of a hiring decision, and are responsible for laws on automated employment decisions (for example the EU AI Act’s rules on recruitment systems, and New York City Local Law 144 and similar). If you are a person named in an analysis and want to exercise a right, write to the privacy address and we will pass it to the customer or act on it. A data-processing agreement is available on request.

13. Security

See Security. If a breach is likely to put your rights at risk we notify the authority within 72 hours and tell you without undue delay.

14. Changes

We will announce material changes in the app or by email before they take effect and update the effective date and version. Earlier versions are available on request.

15. Contact

[COMPANY LEGAL NAME], [REGISTERED POSTAL ADDRESS] · [PRIVACY EMAIL]

Analyze a repoAnalyze an accountAnalyze an organizationGet help
Privacy Policy — Blamewell · Blamewell