Last updated 2026-07-01.
What we collect
- When you sign in with GitHub: your GitHub username, display name, and avatar URL, and — if your GitHub account provides one — an email address, used only for authentication (session management). We request read-only identity access only; we never request write or admin access to your GitHub account.
- When you vote or submit a listing: that action is linked to your account so we can prevent duplicate votes and attribute submissions.
- If you sign up for update notifications(the "Notify me" form): the email address you provide, separately from your GitHub account email, used only to send you updates about new verified listings. This is a distinct, explicit opt-in — signing in with GitHub does not add you to this list.
What we don't do
We don't sell or share your data with third parties. We don't run third-party advertising or tracking scripts. We collect only what's needed to operate the directory — no more.
Where your data lives
Account and listing data is stored with Supabase (our database and authentication provider). Authentication itself is handled via GitHub OAuth. These are our only data processors.
Your choices
You can revoke GravityHub Directory's access at any time from your GitHub account's Applications settings. To request deletion of your account data or removal from the notification list, contact the site owner directly — this project is new and doesn't yet have a self-service deletion flow.