Legal and privacy
Privacy Policy
A transparent account of the limited public repository, review, community, and operational data used to run WelcomeScore.
Scope and plain-language summary
This Privacy Policy explains how WelcomeScore, an ETHIOR project, processes information when you use the hosted WelcomeScore service, including public repository audits, optional Algofox reviews, the Hall of Fame, and the Dev Lounge. It applies to the canonical hosted service and does not automatically apply to forks, third-party websites, linked services, or modified deployments.
Information the service processes
| Feature | Information processed | Purpose |
|---|---|---|
| Repository audit | The repository path you enter and the public GitHub metadata needed for the six published checks, such as public files, README/setup signals, license metadata, issue-label results, and recent push status. | To calculate and display the requested contributor-readiness score. |
| Optional Algofox review | A normalized audit context: repository path, score, grade, primary language, documented check outcomes, and permitted focus checks. The feature does not send raw README bodies, issue text, source code, browser-submitted metrics, Hall data, or Lounge data to a review provider. | To generate an opt-in, evidence-bound review. |
| Review rate limit | When enabled, a salted hash derived from a network identifier and a short request-count window. The raw IP address is not stored in the review-rate-limit record. | To protect the opt-in review endpoint from excessive use. |
| Hall of Fame | An eligible public repository’s audit information when a visitor explicitly chooses to add it. | To display a public, eligibility-based ranking record. |
| Dev Lounge | The anonymous message, quoted-reply snapshot, optional score card, reaction choice, temporary browser-generated developer handle/avatar, and session-scoped identifiers needed for the chat and one-reaction rule. | To provide a lightweight 24-hour community discussion experience. |
Retention and deletion
Public GitHub scoring data is cached briefly to reduce repeated upstream requests. Private review-cache entries store a normalized context hash and a validated review result. Deterministic review entries are retained for up to 24 hours; validated provider-review entries are retained for up to seven days. Cache retention can be shorter if an entry expires or is cleared through normal operations.
Dev Lounge messages and related temporary chat records are designed to expire after 24 hours. Quoted-reply snapshots may remain only for the same limited retention period. Browser-local identity details are stored in your browser and can generally be removed by clearing the site’s local storage or browser data.
Public Hall of Fame records may remain available while they satisfy the service’s documented freshness and eligibility rules. Because they relate to public repositories, removal and correction requests should be made through the canonical project repository with enough public context to locate the record.
Your choices and responsibilities
You may choose not to submit a repository, request an optional review, add an eligible Hall entry, post in the Lounge, attach a score card, react, or follow an external link. Do not use the Lounge for private conversations, personal information, credentials, transactions, recruiting, legal advice, security reports, or sensitive content.
You are responsible for ensuring that you have permission to submit any repository path, message, score card, or other content. If you believe public content in a project-controlled feature is inaccurate, unlawful, infringing, or harmful, use the conduct and support routes described below. Do not post sensitive reports publicly.
Security and policy updates
No internet service can guarantee absolute security. WelcomeScore uses practical separation of browser-safe and server-only credentials, private review-cache permissions, and limited retention, but you should still avoid sharing sensitive information. For a suspected vulnerability, follow SECURITY.md rather than posting publicly.
ETHIOR may update this policy as the product changes. Material updates will be reflected on this page and in the source repository. Continued use after an effective update is subject to the updated policy to the extent permitted by law.
Questions and reports
For a non-sensitive policy question or correction request, use the canonical WelcomeScore repository. For security reports, use the private route in SECURITY.md. For conduct concerns, use the process in CODE_OF_CONDUCT.md.