The short version: we collect as little as possible, we never see your GitHub password, we only act on GitHub when you ask us to, we don't track you or sell anything, and you can export or delete your data yourself at any time.
01Who we are
Stardeck (joinstardeck.site) is operated by [YOUR FULL NAME OR BUSINESS NAME] (“we”, “us”), based in India. We decide how and why your personal data is processed, which makes us the data fiduciary (under India's Digital Personal Data Protection Act, 2023) or data controller (under the EU/UK GDPR).
Contact for anything in this policy, including privacy requests and grievances: hello@joinstardeck.site.
Stardeck is an independent project and is not affiliated with, endorsed by or sponsored by GitHub, Inc.
02What we collect
We collect only what the service needs to work. We never see or store your GitHub password.
- From your GitHub profile when you sign in: your GitHub user ID, username, display name, profile picture URL and the date your GitHub account was created. We do not request or store your email address.
- A GitHub access token that GitHub issues when you authorize Stardeck. It is encrypted (AES-256-GCM) before it is stored, and is used only for the purposes in section 3. We delete it and cancel it with GitHub when you sign out on your last signed-in device, when you stop visiting (see section 7), or when you delete your account. Each new sign-in cancels your previous token.
- What that token allows: GitHub only offers one permission that covers starring, called
public_repo, and it is broader than what we need: GitHub shows it as read and write access to your public repositories. Stardeck only ever uses it to star a repository when you ask and to read public repository details. We never create, change or delete anything in your repositories, issues or settings. We do not get access to your private repositories. - Your project submission: the repository you submit, its public details from GitHub (name, description, language, topics, star count, link) and the pitch you write.
- Your activity: which projects you were shown, liked or skipped, whether a like also starred the repository on GitHub, how long each card was on screen, any optional reason you gave for a skip, and when. Project owners only ever see anonymous totals for their own project (for example “12 views, 3 skipped for an unclear pitch”), never who you are or what you did.
- Security and abuse-prevention records: short-lived request counters used for rate limiting.
- Technical logs: our hosting provider automatically records standard request logs (such as IP address, browser type and the page requested) for security and reliability.
03How and why we use it
- To run the service: sign you in, show you projects, record your likes, rank the leaderboard and display your project to others.
- To star repositories on GitHub, only when you ask: when “Star on GitHub on like” is switched on and you like a project, we use your token to star that one repository for you. We never star, follow, or take any other action on GitHub without that specific action from you.
- To check submissions: we use your token to confirm that you own or administer the repository you submit.
- To keep likes honest: if you starred a project through Stardeck, we regularly check whether you still star it, using your own token. If we no longer hold your token (for example after you sign out), we check that repository's public stargazer list using its owner's token instead. If you have since unstarred it, your like stops counting; if you star it again, it counts again. Likes you gave without starring are not checked.
- To keep the platform fair and your account safe: enforcing limits such as 10 likes and 10 stars per 24 hours, checking the minimum GitHub account age of 30 days, filtering pitches that ask for stars back, and preventing abuse.
Legal basis. Where the GDPR applies, we rely on performance of our contract with you (the Terms of Service) to provide the service, your consent for starring (which you give per like and can switch off at any time), and our legitimate interest in keeping the service secure. Under the DPDP Act, we process your data on the basis of the consent you give when you sign in, for the purposes described here.
We do not sell your data, use it for advertising, build advertising profiles, or use it to train AI models.
04What other people can see
Your submitted project, its pitch, your GitHub username and profile picture, and your project's like and skip counts are shown publicly on Stardeck, including on the public leaderboard.
Who liked or skipped your project is never shown to anyone. Your own likes are visible only to you. Stars you give on GitHub are public on GitHub itself, as with any GitHub star.
07How long we keep it
- Account, project and activity data: for as long as you keep your account.
- GitHub access token: until you sign out, delete your account, or your sign-in expires (7 days without a visit), whichever comes first. An expired token is cancelled with GitHub within a day.
- Rate-limit counters: overwritten within an hour; erased with your account.
- Hosting request logs: kept by our hosting provider for a limited period under its own retention policy.
- After you delete your account: you are signed out, your project leaves the deck, you disappear from the leaderboard and Stardeck's access to your GitHub account is revoked, all at once. Your data is then erased from our live database 30 days later. Signing in again before then cancels the deletion and restores your account. We keep this short window so that deleting and rejoining can't be used to get around the daily like and star limits (our legitimate interest in preventing abuse). Your data may remain in our database provider's automatic backups for a short period after erasure, until those backups expire.
08Your rights
Depending on where you live, you have some or all of these rights:
- Access and portability: use Export my data on your dashboard to download everything we hold about you as a JSON file.
- Correction: your name and picture come from GitHub, so update them there and sign in again. You can remove and resubmit your project at any time.
- Erasure: use Delete account on your dashboard. This revokes Stardeck's access to your GitHub account and hides you at once, and erases your data after 30 days (see section 7).
- Withdraw consent: switch off “Star on GitHub on like”, or revoke Stardeck at any time in your GitHub settings under Applications. Withdrawing consent doesn't affect anything done before.
- Object or restrict certain processing, and nominate someone to exercise your rights if you die or become incapacitated (DPDP Act).
For any request we can't handle through the dashboard, email hello@joinstardeck.site. We respond within 30 days and may need to confirm the request comes from you.
Grievances and complaints. Contact us first at hello@joinstardeck.site. If you're not satisfied, you may complain to the Data Protection Board of India, or, in the EU/UK, to your local data protection authority.
09Security
We protect your data with encryption in transit (HTTPS) and at rest for GitHub tokens, strict browser security policies, server-side rate limits, and access limited to what the service needs. No system is perfectly secure, but we will notify you and the relevant authorities of a personal data breach as the law requires.
Found a security issue? Please report it privately to hello@joinstardeck.site rather than disclosing it publicly.
10Age requirement
Stardeck is intended for people aged 18 or older. We do not knowingly collect data from anyone younger. If you believe a child has used Stardeck, contact us and we will delete their data.
11Changes to this policy
If we change this policy, we will update the effective date above. For significant changes, we will show a notice on Stardeck before they take effect. Continuing to use Stardeck after that means you accept the updated policy.
Questions about this document? Email hello@joinstardeck.site.