Privacy Policy
How GitHobby handles information when you use the site and its widgets.
Last updated: August 2026
1. Introduction
GitHobby ("we", "us") provides a platform for developers to generate URL-parameterized web widgets and embeddable SVG images for their GitHub profiles. This Privacy Policy explains how we process information when you use GitHobby.
2. Data Controller
The data controller for GitHobby is Nisal Herath. If you have any privacy-related questions, please contact us at: hello@githobby.com.
3. What Information We Handle
Account and Profile Data
When you create an account, we collect your email address and a password. If you sign in using GitHub OAuth, we receive your public GitHub profile information (such as your username and avatar) and email address. We use this information to secure your account and identify your saved widgets.
Widget Data and Designs
When you use the Design Studio, your custom widget configurations, designs, and AI prompts are saved to our database associated with your account.
Important Notice: Do not place sensitive personal information, API keys, or private identifiers in widget configuration fields, as generated widgets become accessible via a public URL.
Technical Request Data
When you browse the GitHobby website or when a widget image is loaded from our endpoints, our hosting and CDN providers automatically receive standard technical information, such as IP addresses, browser types, and request timestamps, necessary to serve the content and prevent abuse.
Security and Bot Protection
We use Cloudflare Turnstile to protect authentication endpoints from bots and abuse. Turnstile evaluates browser and network characteristics to verify human interaction without using tracking cookies.
Transactional Emails
We use SMTP2GO to send necessary account emails (such as password resets). We share your email address with them strictly for delivery purposes.
Cookies and Browser Storage
We use browser storage to maintain your authentication session (via Supabase), remember your cookie consent preferences, and store UI state. If you grant permission, we also use Google Analytics to understand how our website is used. Please read our Cookie Policy for details.
4. Purposes and Legal Bases
We process information for the following purposes and on the following lawful bases (under the GDPR):
- Delivering the requested service: We process your account data and widget configurations to provide the GitHobby platform and generate your widgets. (Legal basis: Contract/Service Necessity)
- Security and stability: We process technical request data and utilize Turnstile to ensure the platform remains secure and available. (Legal basis: Legitimate Interests)
- Website analytics: If you opt in, we process aggregated analytics to improve our website. (Legal basis: Consent)
5. Recipients of Data
We use the following categories of service providers to operate GitHobby:
- Hosting & Database: Vercel and Supabase to host the application and store user data.
- Security: Cloudflare (Turnstile) for bot protection.
- Email: SMTP2GO for transactional emails.
- Authentication: GitHub (if you choose to sign in via GitHub OAuth).
- Analytics: Google Analytics (only if you consent).
6. International Transfers
GitHobby is accessible globally. Your data may be processed on servers located outside the European Economic Area (EEA), including in the United States, by our infrastructure providers subject to their respective safeguards.
7. Data Retention
We retain your account data and saved widgets as long as your account is active. You may delete your account and associated data at any time. Technical logs retained by our hosting infrastructure are kept for short periods necessary for security.
8. Your Rights
Depending on your location, you may have the right to access, correct, or request deletion of personal data we hold about you. You can manage your account and data directly within the application. If you need assistance or wish to exercise your rights, please contact us.
9. Security
We use reasonable organizational and technical measures to protect the information we handle. Passwords are securely hashed by Supabase, and we employ Row Level Security (RLS) to ensure users can only access their own private data.
10. Changes to this Policy
We may update this Privacy Policy as GitHobby evolves. We encourage you to review it periodically.