Privacy

What Repobeats accesses and stores

Repobeats is built around a narrow, read-only GitHub App integration. GitHub sign-in is required to manage repositories, while every connected card remains accessible to anyone who has its SVG URL.

GitHub access

Stored data

Repobeats stores your GitHub user ID, login, avatar URL, a hash of each opaque session token, verified repository-manager relationships, the GitHub App installation ID, and a collected activity snapshot. The browser cookie contains only the opaque session token. Snapshots let the service render cards without calling GitHub on every request.

Public and Unlisted are both link-accessible

A Public card is available at its owner/repository URL. An Unlisted card disables that predictable URL and uses only its random embed URL, but it is not private or authenticated: anyone with the link can view it. This also applies to aggregate activity from private repositories.