$ cat PRIVACY.md
Privacy & cookies
Last updated: August 2026
RepoJournal is a daily briefing on public open-source activity. We try to collect as little personal data as possible, and we never sell it. This page explains what we do collect, the cookies we set, and how you can control them.
It also explains something less obvious: we write journals about developers from their public GitHub activity, and we sometimes do that before the person has an account with us. If that is why you are here, read Journals about developers — it tells you what we hold, why, and how to have it removed.
What we collect, and why
- Your email address — only when you subscribe to a briefing. We use double opt-in (you confirm via a link before anything is sent), and we use the address solely to deliver the wires you asked for. Every email has a one-click unsubscribe.
- Public GitHub activity — commits, pull requests, releases and the public repositories they belong to, together with the public profile attached to them (username, display name, avatar). We read this through GitHub's public API to write journals and briefings. Private repositories are never read for anyone who has not signed in and explicitly enabled it, and private work never appears on a public page.
- Anonymous usage analytics — to understand which pages help readers, we record anonymous events (a page was visited, a signup form was seen or focused) tied to a random session identifier, not to your identity. We also use Google Analytics (IP-anonymized) and Cloudflare Web Analytics (cookieless) to see which pages are useful — see below.
Journals about developers
A RepoJournal journal is a day-by-day write-up of what a developer shipped, generated from their public GitHub activity. Most journals belong to people who signed in and started one. Some we build ourselves, for well-known developers who have not signed up, so that the work is already there if they ever do.
- Only public activity. We read what GitHub already shows to anyone. We do not read private repositories, and we cannot: doing so needs your own sign-in and your own explicit opt-in.
- Our lawful basis is legitimate interest — reporting on public open-source work, in the way a trade publication does. You can object to it, and we will act on that rather than argue.
- We tell you. If we build a journal about you, we contact you — normally at the public email address on your commits — to say it exists and how to claim or remove it. We record when we did that.
-
It is listed nowhere until you say yes. Every journal — including the
ones people start themselves — carries
noindexand stays out of search engines, our directory, /explore, our sitemap and our home page until the person it is about approves it. It does not rank for your name unless you decide it should. The page itself still loads at its own link, so anything you have already shared keeps working. - You approve it, or you tell us. If you have an account, there is a toggle in Settings → Journal and a prompt on your dashboard; you can switch it back off at any time, just as easily. If you do not have an account, replying to us to say yes is enough — we record who recorded it, when, and how we heard from you, and we will not record it for anyone we never contacted.
- Claiming it makes it yours. Sign in with the GitHub account it is about and the journal transfers to you, archive intact. Nothing is re-fetched. If you had already told us yes by email, we ask you once more from inside your own account — we would rather ask twice than list a page about you on the strength of a handle somebody typed.
- Nobody can be signed up to follow you unless your journal is listed, and if you turn listing off, we stop emailing your journal to the people who followed it.
To have a journal removed, email privacy@repojournal.com from any address, or use the "Remove this page" link on the journal itself. We delete it and record your handle so that no one — including us — can rebuild it later. You do not have to give a reason, and you do not have to have an account.
Cookies we set
All of these are first-party cookies. None of them are advertising cookies, and none are shared with third parties.
| Cookie | Purpose | Lifetime |
|---|---|---|
| rj_aid | Anonymous session id used to count a signup funnel (form seen → focused → submitted). Not linked to your identity. | Session (until you close the browser) |
| rj_src | Remembers where you first arrived from (referrer / campaign) so we can attribute a later subscribe to a channel. | 90 days |
| rj_seen | Remembers which project pages you've read, so if you subscribe with a bare email we can start you on those projects. | 30 days |
| rj_consent | Only set where we show a cookie-consent banner (e.g. EU visitors): stores your choice so we don't ask again and only run Google Analytics if you accepted. | 180 days |
Analytics
We use two privacy-minded analytics tools to see which pages are useful — never to build an advertising profile, and never sold or shared for advertising:
- Cloudflare Web Analytics — cookieless and collects no personal data. It sets no cookies and doesn't track you across sites, so it needs no consent banner.
- Google Analytics 4 — with IP anonymization on. You can opt out with Google's browser opt-out add-on or your browser's cookie / tracking-protection settings. Where required (for example, EU visitors), we show a consent banner and Google Analytics stays denied until you accept.
Who we share data with
We do not sell your data or share it for advertising. We rely on a small number of processors to run the service: Amazon SES to deliver email, and Google Analytics and Cloudflare Web Analytics for the analytics above. Each processes data only to provide its service to us.
Your rights
You can unsubscribe at any time from the link in every email, and you can ask us to access, correct, or delete any personal data we hold about you — your email address and subscription records, and any journal we have written about you. Email privacy@repojournal.com and we'll take care of it. You do not need an account with us to ask, and you do not have to give a reason.
Contact
Questions about this policy? Reach us at privacy@repojournal.com.