Privacy Policy
Last updated 31 August 2026 · Version priv-2026-08-31
GitFinder indexes personal information about software developers — including email addresses found in public git commit history, public GitHub profiles and public GPG keys — and shows it to recruiters who pay us.
If you are a developer and you want out, email info@workonward.com with your GitHub handle. We will remove you, and add you to a permanent suppression list so later searches do not put you back. No justification needed, no account needed.
If you are a customer, we hold your account, your searches, and billing identifiers (never your card number). We use Stripe for payments, Anthropic for AI ranking, GitHub as our data source, Amazon SES for email, and DigitalOcean for hosting. We do not sell your account data — but giving customers candidate data for money may count as a “sale” under California law, so there is an opt-out below.
This summary is for convenience only and is not part of the agreement.
1. Who we are, and who this policy is about
GitFinder is operated by WorkOnward, Inc., WorkOnward, Inc., 124 East 14th Street, New York, NY 10003, USA. For the information described here we are the controller (or “business”). Contact: info@workonward.com.
This policy covers two different groups of people, and it is worth knowing which one you are:
- Customers — recruiters and hiring teams with a GitFinder account. Sections 2, 7, 8 and 11 to 14 are the relevant ones.
- Developers — people whose public GitHub activity we have indexed, who never signed up for anything. Sections 3 to 6, 11, and especially 15 and 16 are for you.
2. Information we collect from customers
- Account: email address, optional name, a bcrypt hash of your password (never the password itself), and the date you signed up.
- Consent records: the exact terms you were shown when you agreed to the trial and automatic renewal, the version identifier, and the date, time, IP address and browser user-agent at the moment you agreed. We are required to be able to prove this.
- Billing: a Stripe customer and subscription identifier, subscription status, and the brand and last four digits of your card. We never receive or store your full card number.
- Usage: the job descriptions you submit, the search plans derived from them, the results of your searches, your saved lists, notes and statuses, and per-day search counts.
- Technical: a session cookie, plus server logs and rate-limit counters that include your IP address.
3. Information we hold about developers
If we have indexed your public GitHub activity, we may hold:
- your GitHub username, display name, profile and avatar URL, and the self-reported bio, company, location, blog and social links on your profile;
- public activity signals: repositories you own or contribute to, programming languages, star and follower counts, how long you have been active, and when you were last active;
- one or more email addresses, together with where each came from and how confident we are in it;
- an AI-generated relevance score and a one-line explanation of why you might fit a particular role, generated when a customer’s search matched you.
We do not seek, and do not knowingly index, special-category or sensitive information — health, race or ethnicity, religion, political opinions, trade-union membership, sex life or sexual orientation, biometric or genetic data, or government identifiers. If such information reaches us because you published it on your GitHub profile, tell us and we will remove it.
We never access anything that requires a login, and we never ask you for anything. If you have turned on GitHub’s “Keep my email address private”, the @users.noreply.github.com address GitHub substitutes is rejected outright by our system and is never unwrapped or worked around.
4. Where developer information comes from
All of it comes from sources GitHub makes publicly available through its API, consulted in this order:
- Your public GitHub profile — including the email field, if you filled it in and left it public.
- Public git commit metadata — the author email recorded in commits you pushed to public repositories. Git stores this in every commit by design, and GitHub serves it publicly.
- Public commits in your own public repositories — the same, in repositories you own.
- Public GPG key user IDs — the email address embedded in a GPG key you uploaded to GitHub and made public.
We stop at the first usable address, so in most cases only one or two of these are ever consulted. We discard machine-local addresses, obvious placeholders, shared role addresses, automated-bot addresses, and GitHub’s privacy pseudo-address.
We do not buy candidate data from data brokers, we do not scrape LinkedIn or any other site that requires a login, and we do not use resumé databases.
5. Why we process it, and our lawful basis
Purpose. To operate a recruiting search tool: to let an employer describe a role and find developers whose public work suggests they might be a good fit, and to give the employer a way to contact them about it.
Lawful basis (GDPR / UK GDPR). We rely on our legitimate interests and those of our customers under Article 6(1)(f) — the interest in matching open engineering roles with people who might want them. We have carried out and documented a legitimate interests assessment weighing that interest against your rights and freedoms, and you can request a copy at info@workonward.com. In carrying it out we took particular account of the fact that you did not give us this information yourself, that being contacted about a job is a use you may not have expected when you pushed a commit, and that an unwanted approach is an intrusion even when the underlying data is public.
Our mitigations are:
- we index only what is already public, and never anything behind a login;
- we do not index special-category data;
- we reject addresses you have chosen to hide;
- we cache profiles for a short period rather than building a permanent dossier;
- we bind our customers contractually to recruiting-only use and to honouring your objections (Terms, section 8);
- we give you an unconditional, no-questions-asked removal route that also suppresses you from future searches.
Why we could not tell you individually. Because we collect your information from a public source rather than from you, Article 14 requires us to give you notice. Notifying every indexed developer individually would involve disproportionate effort and would itself mean emailing people who have not asked to hear from us, so we rely on Article 14(5)(b) and give that notice publicly, here, in a policy that is linked from every page of the site, listed in our sitemap, and open to search engines and AI crawlers.
You can object. Because we rely on legitimate interests you have a right to object under Article 21. We do not weigh it up: if you object, we remove you. See section 16.
6. How we use AI
We send two kinds of text to Anthropic PBC (Claude) through its commercial API:
- the job description a customer pastes in, so the model can derive a search plan from it — customers are told not to paste anything confidential, or anything about a named individual, into a job description;
- a summary of each candidate’s public profile and activity, so the model can score relevance to that role and write a one-line explanation.
Anthropic processes this on our instructions under its commercial terms, which provide that API inputs and outputs are not used to train its models; it retains data for a limited period for trust-and-safety purposes. We do not send Anthropic any candidate email address, any account credential, or any payment data.
The score and explanation are relevance suggestions, not judgements about a person, and no decision about anyone is made automatically — see section 18.
8. Email, and the tracking in it
We send transactional email — email confirmation, password resets, trial and billing notices — through WorkOnward Reach, which delivers via Amazon SES.
Open and click tracking are enabled on our sending domain. In practice that means our provider records when an email is opened and rewrites the links in it so a click is recorded before you are redirected to the intended page. We use this to tell whether important notices (such as a trial-ending reminder) were delivered and read. Delivery, bounce, open and click events are retained for 90 days.
The only email with a preference toggle is the optional “your search is ready” notification, which you can turn off in Settings and which carries a one-click unsubscribe header. Security and billing notices are not optional while you have an account, because you need them.
9. Who we share information with
We do not sell customer account data. We share what is necessary with the following providers, each processing on our instructions under a written agreement:
| Provider | What they receive | Why | Where |
|---|---|---|---|
| Stripe, Inc. | Name, email, billing address, card details (collected directly by Stripe — we never see the full number), subscription and invoice records | Payments, subscriptions, trials, the customer portal, fraud prevention | US, with global processing |
| Anthropic PBC | Job description text; a summary of each candidate’s public GitHub profile and activity. No email addresses, credentials or payment data | Parsing job descriptions and ranking candidates | US |
| GitHub, Inc. (Microsoft) | Our search queries. GitHub is our source, not a recipient of your data | Public repository, contributor, commit and GPG-key data | US |
| Amazon Web Services (SES), used through WorkOnward Reach | Your email address and the content of emails we send you; delivery, bounce, open and click events | Transactional email | US |
| DigitalOcean, LLC | Everything the application stores, as operator of the server it runs on. Our database is self-hosted on that server, not a managed third-party database | Hosting and infrastructure | US |
We may also disclose information where legally required, to protect our rights or someone’s safety, or to a buyer as part of a merger or acquisition — in which case we will update this page before the information is transferred.
Candidate information goes to our customers. That is what the product does. Our customers are independent controllers of what they do with it, under the contractual restrictions in section 8 of our Terms. Under some US state laws, providing personal information to a customer for money can count as a “sale” or “sharing” — see section 15.
10. International transfers
We are based in the United States and our infrastructure and providers are located there. If you are in the EEA, the UK or Switzerland, your information is transferred to the US. Where required we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum) with our providers, together with the supplementary measures described in section 12. You can request details of the relevant transfer mechanism at info@workonward.com.
11. How long we keep things
We keep information only as long as we need it for the purpose we collected it for, or as long as the law requires.
| What | How long |
|---|---|
| Customer account record | For the life of the account, then deleted within 30 days of a deletion request |
| Session cookie | 7 days, then it expires and you are signed out |
| Email confirmation and password-reset tokens | Valid for 24 hours and 60 minutes respectively; the records are deleted after 7 days |
| Candidate enrichment cache | 7 days from the last fetch, then deleted automatically |
| Job descriptions, search plans and saved search results | Until you delete the search or your account |
| Saved lists, notes and candidate statuses | Until you delete the list or your account |
| Per-day search counters | 35 days |
| Email delivery, bounce, open and click logs | 90 days |
| Automatic-renewal consent records | 4 years — the law requires at least 3, or 1 year after the subscription ends, whichever is longer |
| Billing records (identifiers, invoices) | 7 years, for tax and accounting; Stripe applies its own retention |
| Suppression list (developers who asked to be removed) | Indefinitely — this record is the only thing that stops us re-adding you, so keeping it is how we honour your request |
A note on candidate snapshots.The 7-day cache above is our short-term store for re-fetching. When a customer runs a search or saves someone to a list, a snapshot of that candidate is copied into the customer’s own search or list record, and that copy lives as long as the search or list does. Removing yourself from GitFinder removes both.
12. How we protect information
The site is served over HTTPS only. Passwords are stored as bcrypt hashes, never in plain text. Email confirmation and reset tokens are stored only as SHA-256 hashes, so a copy of our database cannot be used to take over an account. The session cookie is httpOnly and same-site. Card data never touches our servers. The database is not reachable from the public internet, and access to production is limited to people who need it. No system is perfectly secure; if we become aware of a breach affecting your personal information we will notify you and the relevant regulator as required by law.
13. Your rights under the GDPR and UK GDPR
Whether you are a customer or an indexed developer, you have the right to:
- know and access what we hold about you, and get a copy;
- rectify anything inaccurate or incomplete;
- eraseit (“right to be forgotten”);
- restrict processing while a dispute is resolved;
- object to processing based on legitimate interests — including, always and without needing a reason, to your inclusion in our index;
- portability — receive the information you gave us in a machine-readable form;
- withdraw consent where we relied on consent;
- not be subject to a decision based solely on automated processing with legal effects — see section 18;
- complainto a supervisory authority — in the EU the authority where you live or work, in the UK the Information Commissioner’s Office (ico.org.uk). You do not have to come to us first, but we would like the chance to fix it.
How to exercise them. Email info@workonward.com. Say which right you are exercising and, if you are a developer, give your GitHub handle — that is the only identifier we need, and it is how our records are keyed. We respond within 30 days and do not charge. We will only ask for identifying information if we genuinely cannot tell whose data you mean, and we will never ask for a government ID to process a removal request. If we refuse a request we will tell you why and how to complain.
14. Your rights under US state privacy laws
If you live in California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia or another state with a comprehensive privacy law, you have rights similar in substance to those above: to know, access, correct, delete, obtain a portable copy, and opt out of targeted advertising, of the sale of your personal information, and of profiling in furtherance of decisions with significant effects.
We do not use your information for targeted advertising and we do not profile for advertising purposes. We do not knowingly sell the personal information of anyone under 16.
Under the CCPA/CPRA the categories of personal information we handle are: identifiers (name, email, GitHub handle, IP address); professional or employment-related information; internet or network activity; commercial information (subscription and payment records); and inferences (the AI relevance score). Our sources, purposes and categories of recipient are set out in sections 2 to 9.
How to exercise them. Email info@workonward.com, or use the mechanism in section 15. We verify a request only to the extent necessary, respond within 45 days (extendable once by a further 45 with notice), and will not discriminate against youfor exercising a right. You may use an authorised agent; we will ask for proof of their authority. If we deny a request you may appeal by replying with the word “appeal”; we will respond within 45 days and, if we still deny it, tell you how to complain to your state Attorney General.
15. Do Not Sell or Share My Personal Information
GitFinder’s business is providing recruiters with information about developers, and recruiters pay us for access. We do not think of that as selling your data, and we do not run advertising or trade data with brokers. But we would rather be straight with you than argue about definitions: disclosing personal information to a customer for monetary consideration can fall within the definition of a “sale” or of “sharing” under the California Consumer Privacy Act and similar state laws. So we treat it as one, and we give you an opt-out.
To opt out, do either of these:
- Email info@workonward.com with the subject line “Do Not Sell or Share” and, if you are a developer, your GitHub handle. We will suppress you within 15 days and confirm.
- Send a Global Privacy Control signal from your browser. We honour GPC as a valid opt-out request for the browser that sends it.
For an indexed developer, opting out of “sale”/“sharing” and asking to be removed amount to the same thing in practice, and we process either as a full removal and permanent suppression. You do not need an account, and we will not ask you to create one.
16. Developers: how to be removed from GitFinder
You do not have to justify this and we will not push back.
Email info@workonward.comwith the subject “Remove me from GitFinder” and your GitHub handle. That is all we need.
What we do when we receive it, within 30 days and usually within a few business days:
- delete your cached profile;
- remove you from every customer list and every stored search result, so you disappear from shortlists that have already been built;
- add your handle to a permanent suppression list, so future searches skip you and you are not silently re-added the next time someone searches for your skills;
- email the confirmation back to you.
What we cannot do. We cannot recall a CSV or JSON export a customer has already downloaded, or an email they have already sent you. Our Terms require customers to delete exported information when you ask them to, and to stop contacting you. If a customer contacted you and will not stop, tell us who they are — we will require them to comply and will terminate their account if they refuse.
We cannot remove you from GitHub. The commit metadata, profile fields and GPG keys we read stay on GitHub whether or not you are in our index. If you want to stop this class of tool finding you generally, the effective step is at the source: turn on “Keep my email address private” in your GitHub email settings and set a noreply commit email — our system rejects that address unconditionally.
17. Children
GitFinder is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe we hold information about a child, tell us and we will delete it.
18. Automated decision-making and profiling
We generate an AI relevance score and a short written explanation for each candidate a search matches. That is profiling in the GDPR sense. It is decision support only: it produces a suggested ordering of publicly visible technical signals, and it is presented to a human recruiter who decides what to do. We make no automated decision that produces legal effects or similarly significantly affects anyone, and our Terms require customers to have a human review every candidate and forbid using the score as the sole basis for any decision. If you would like to know how a score about you was reached, ask us and we will explain the factors involved.
19. Changes to this policy
We may update this policy. When we do we change the “Last updated” date and the version identifier at the top of this page. For changes that materially affect how we use personal information we will give notice — to customers by email, and publicly here for developers — before the change takes effect. Superseded versions are available on request.
20. Contact us, and how to complain
Email info@workonward.com, or write to WorkOnward, Inc., 124 East 14th Street, New York, NY 10003, USA. If you are not satisfied with our response you can complain to your data protection authority (in the UK, ico.org.uk) or your state Attorney General. We would rather hear from you first, and we read every message.