Effective date: not yet in effect
the Repoify entity ("Repoify", "we", "us") operates a candidate sourcing and outreach platform at https://repoify.com. This policy explains what personal information we handle, why, and what you can do about it.
1. Scope: Repoify is a United States service
We source only US-based developers. A profile we cannot positively place in the United States is not stored at all. This is enforced when data is collected, not merely filtered out of search results.
We offer the Service only to US-based customers.
If you believe you are outside the United States and appear in our systems anyway, Section 8 explains how to be removed. Location on GitHub is free text people write themselves, so our classification is careful but not perfect, and we would rather hear from you than assume.
2. This policy covers two different groups of people
Read the part that applies to you. The distinction matters, because most of the people described here have never used our product.
Customers. Recruiters, hiring managers and their organizations who create an account and use the Service.
Developers. Software engineers whose publicly available professional information we analyse so Customers can find people whose public work relates to a role. If you are a developer, you did not sign up for Repoify and may not have heard of us. Section 8 explains how to have your information removed.
3. Information we collect
3.1 From Customers
- Account information: name, work email, company, job title, authentication identifiers via our identity provider.
- Billing information: handled by our payment processor. We do not store full card numbers.
- Content you create: searches, projects, notes, message templates, and the content of outreach you send.
- Connected email accounts: where you connect Gmail or Outlook, the authorization tokens and the message metadata and content needed to send outreach and thread replies. See Section 5.
- Usage data: log data, device and browser information, pages viewed, features used.
3.2 About Developers
Publicly available professional information, principally from GitHub's public API:
- Public profile fields: username, display name, avatar, biography, stated location, company, personal website, linked social handles, public email address where the developer has published one, account creation date, follower count, and the "available for hire" flag;
- Public repository metadata: names, descriptions, topics, languages, star counts, last-activity dates;
- Public contribution activity, such as the public contribution calendar;
- Public repository documentation, used to generate a description of the project.
We also derive a relevance ranking, measuring how closely a developer's public repositories match a Customer's search, and a plain-language description of a repository.
These describe repositories, not people. We do not generate assessments of any individual's ability, character, seniority or fitness for a role, and our terms prohibit Customers from using our output as a factor in employment eligibility decisions.
We do not access private repositories, private contribution data, anything behind a login, or any information a developer has not made public.
3.3 Named sources
| Source | What |
|---|---|
| GitHub public API | Developer profile, repository and activity data described in 3.2 |
| Our Customers | Notes, pipeline stage and other information a Customer adds about a candidate |
| Our identity, payment and email providers | Account, billing and mailbox data needed to run the Service |
| You directly | Anything you send us |
4. Why we handle it
| Purpose | Whose data |
|---|---|
| Providing and operating the Service | Customers |
| Billing, collections, tax records | Customers |
| Matching public repository signals against a Customer's search criteria | Developers |
| Enabling Customers to contact developers about employment opportunities | Developers |
| Security, fraud prevention, service integrity | All |
| Product analytics and improvement | All |
| Marketing email to Customers, with opt-out in every message | Customers |
| Responding to legal process | All |
We have documented our reasoning for sourcing public developer information and weighed it against developers' interests. You may request a summary at our legal contact address.
5. Google and Microsoft account data
When you connect a Gmail or Outlook account, we access only what is needed to send your outreach and show replies in your inbox.
Repoify's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not use Google user data for advertising, do not sell it, do not allow humans to read it except with your explicit consent, for security purposes, to comply with law, or where it is aggregated and de-identified, and do not use it to train generalized AI models. You can disconnect a mailbox at any time in Settings, which revokes our access.
6. Who we share it with
We do not sell personal information, and we do not disclose it to third parties for their own marketing.
We share with subprocessors who process on our behalf under contract. They fall into a small number of categories: cloud hosting and compute; database and file storage; authentication and identity; payment processing; AI model providers, used to analyse public repositories and draft messages; and, where a Customer connects one, the mail platform that Customer already uses to send their own outreach. A current list naming each subprocessor is available on request at dev@repoify.com.
We also disclose to comply with law or valid legal process, to enforce our terms, to protect rights and safety, and in connection with a merger or sale of assets where the recipient remains bound by this policy.
7. How long we keep it
| Data | Retention |
|---|---|
| Customer account records | Duration of the account, then a defined number of years for legal and tax purposes |
| Billing and transaction records | Seven (7) years |
| Developer profile information | Up to ninety (90) days from last refresh, then deleted, or until removal is requested |
| Cached developer contact information | Up to thirty (30) days |
| Candidate lists saved with a past search | Up to ninety (90) days. The search itself is kept; the list of people is not |
| Outreach message content | Three (3) years from the last message in a thread |
| Do-not-contact records | Retained indefinitely, so a removal request keeps working. This is the minimum necessary to honour your request |
| Security, access and usage logs | Twelve (12) months |
| Aggregated or de-identified analytics | Indefinitely, in a form that cannot identify you |
8. Removal and do-not-contact
Any developer can be removed from Repoify, and we will keep them out. We offer this to everyone, regardless of where they live and regardless of whether any law requires it of us.
How: visit https://repoify.com/do-not-contact, or email our legal contact address from an address associated with your GitHub account. We ask you to verify control of the account so nobody can remove or impersonate someone else.
What happens: we delete your profile, any cached contact information, your analysis history and your outreach history, and we add your identifier to a permanent do-not-contact list so no future search re-adds you. That record is the one thing we keep, because deleting it would defeat the request.
How long: within ten (10) business days of a verified request.
You may also ask for a copy of what we hold about you, or ask us to correct it, at the same address.
Customers: to access, correct, export or delete your account data, contact dev@repoify.com.
Information a Customer holds about a candidate in their own workspace, such as notes and pipeline stage, belongs to that Customer. Contact them directly. If you contact us we will refer your request to them and assist.
9. Marketing email
Every marketing email we send includes an unsubscribe link, honoured within ten (10) business days as CAN-SPAM requires. Service and transactional messages about your account are not marketing and continue regardless.
10. Security
We use encryption in transit, access controls and least-privilege credentials, and restrict access to personal information to personnel who need it. All database access goes through our backend; no database credential is exposed to browsers. No system is perfectly secure and we cannot guarantee absolute security.
11. Automated processing
We generate relevance rankings and AI-assisted descriptions of public repositories. These are not assessments of any individual. Every hiring decision is made by the Customer, and our terms prohibit using our output as a factor in establishing employment eligibility. If you believe an automated process has affected you, contact our legal contact address.
12. Children
The Service is not directed to anyone under 18 and we do not knowingly collect information from children. If you believe we have, contact our legal contact address and we will delete it.
13. Changes
We post changes here and update the effective date. Material changes are notified to Customers by email or in-product at least thirty (30) days in advance. Superseded versions are archived and available on request.
14. Contact
the Repoify entity our registered postal address our legal contact address