Privacy Policy
This policy explains the information Socialize handles for developer accounts, public profiles, optional public GitHub activity, service operations, and consented analytics.
Llewellyn Adonteng Paintsil
cape Coast, Ghana
Scope
This policy covers the managed Socialize service, not a developer's independent deployment.
This Privacy Policy explains how Socialize intends to collect, use, disclose, retain, and protect information when you visit the service, create an account, publish a hosted profile, contact support, or report abuse.
A self-hosted Socialize operator controls their own backend project, deployment, domain, and visitor data. Their privacy practices are not controlled by the managed Socialize service. Review the policy published by that operator before using a self-hosted instance.
Information we handle
The service needs account data, public profile content, and a limited operational record.
Account and sign-in information
Account sign-in may provide a user ID, email address, display name, avatar, verified-email status, and the sign-in provider you chose. Google and GitHub authenticate you directly; Socialize does not receive your password for those providers.
Profile content
We store the name, handle, role, bio, location, availability, avatar, accent choice, section headings, project links, social links, and other content you choose to publish. Optional uploaded link icons, thumbnails, and heading images are stored in publicly readable cloud storage because public profiles must be able to render them. A published profile record is publicly readable. When developer activity is enabled, its GitHub username, repository selections, and display settings are part of that public record. When it is disabled, the hosted service omits those settings from the public profile and keeps them only in the owner-private account document.
If you enable developer activity, Socialize sends the public GitHub username and relevant owner/repository names to GitHub from the server. We temporarily process and cache public event dates, commit SHAs and first-line messages, repository names and URLs, commit dates, contribution dates, counts, levels and years, public push-day totals, and repository-language data. Full contribution calendars require the optional public-only server token; otherwise the calendar is a labeled sample. Results may be incomplete or delayed. They come from GitHub and are not verified proof that a Socialize account owns a GitHub account or repository. The configured server token must not have private-repository access.
Service and device information
Hosting and security systems may record request time, IP address, user agent, route, referrer, response status, authentication events, and diagnostic details. The GitHub activity route also uses a source IP for a best-effort limit of 30 requests per 60 seconds. If you allow optional analytics, Google Analytics may also process the page path and title, referrer, browser and device details, and session-level measurements. Socialize's manual page-view events omit URL query strings and do not include account or profile fields.
Messages and reports
If you contact support, sponsorship, privacy, legal, or security channels, we receive the message, contact details, attachments, and related account or profile information you provide.
Optional analytics
Google Analytics stays off until you actively allow it.
If you choose Allow analytics, Socialize loads Google Analytics 4 to understand aggregate page visits and navigation. We deny advertising storage, ad personalization, and Google advertising signals. Declining means the analytics tag is not loaded.
Your choice is stored on this device. You can withdraw it at any time through the Privacy choices control. The Cookie Policy describes related browser storage and controls.
How we use information
- Create and secure accounts, sessions, and profile ownership.
- Store, render, and deliver the hosted profile you configure.
- Request, cache, sample, and display public GitHub activity you enable.
- Prevent impersonation, abuse, fraud, malware, and unauthorized access.
- Debug failures, maintain availability, and improve accessibility.
- Measure aggregate site traffic when you allow optional analytics.
- Answer support, privacy, legal, sponsorship, and security messages.
- Enforce the Terms and Acceptable Use Policy.
- Meet legal obligations and respond to valid legal process.
Legal bases
Where law requires a legal basis, the basis depends on the purpose.
We expect to process account and profile information to perform the service contract you request. We may rely on legitimate interests for service security, fraud prevention, support, and careful product improvement, after considering the effect on users. We may use consent for optional technologies or communications where required, and process information to comply with law or protect vital interests in an emergency.
The legal operator is Llewellyn Adonteng Paintsil, located at cape Coast, Ghana. Additional lawful bases may apply when required by the law governing a specific request or user.
How information is shared
We may disclose information in the following limited situations:
- Public profile delivery. Enabled profile content is available to anyone who opens or discovers the public URL.
- Service providers. Cloud infrastructure providers handle account and profile storage, Vercel hosts and delivers the Next.js application, and Google Analytics provides optional aggregate traffic measurement after consent. Email, domain, and error-monitoring providers may also process information to operate the service under their terms and safeguards.
- Identity providers. Google or GitHub receives the authentication request when you choose that provider.
- Developer activity. GitHub receives server-side API requests for the public username and repositories needed to render an activity section you enable. GitHub is the third-party source of the resulting public commit, event, repository, and language metadata and handles those requests under its own terms and privacy practices.
- Legal and safety needs. We may disclose information when reasonably necessary to comply with valid process, protect rights or safety, investigate abuse, or defend legal claims.
- Business transfer. Information may transfer as part of a merger, financing, acquisition, reorganization, or sale, subject to appropriate notice and applicable law.
Socialize does not intend to sell personal information or share it for cross-context behavioral advertising. Provider and analytics changes are reviewed to keep this statement accurate.
Public profiles and links
A hosted profile is public by design. Search engines, archives, link preview services, and visitors may index, cache, copy, screenshot, or redistribute content after publication. Deleting content from Socialize cannot erase copies controlled by other parties.
Links take visitors to independent services with their own privacy practices. Socialize does not control what those destinations collect. Profile owners should avoid publishing confidential information or data about another person without permission.
GitHub activity cards reproduce public information from GitHub, with a labeled sample when the full calendar is unavailable. They may be delayed, incomplete, attributed incorrectly, or changed at the source, and do not indicate verification, endorsement, employment, authorship of every pushed change, or affiliation with GitHub.
Retention and deletion
Account and profile data is generally kept while the account remains active. When in-product account deletion completes, the authentication account, claimed handle, profile records, click totals, and uploaded profile media are removed from the primary service systems during that request. A failed cleanup leaves the sign-in account available so the deletion can be retried.
Backups and provider logs may age out on separate schedules. Abuse, transaction, or security records may be retained longer when reasonably necessary to prevent repeat harm or meet legal obligations. Exact periods can vary with the production provider configuration and an applicable legal hold; request the current schedule from llewellynpaintsil34@gmail.com.
Public GitHub events are revalidated after five minutes, while repository, commit, contribution, and language fetch results are revalidated after up to one hour. Activity API responses themselves are marked private and no-store. To avoid repeatedly scraping GitHub and to support the calendar year selector, normalized contribution and language summaries are also retained in a shared server cache keyed by the public GitHub username. Contribution records are bounded to 5,500 dates and at most 15 available years; language records are bounded to 15 years. Current-year entries are refreshed as activity requests occur, while historical entries may remain until replaced or removed during maintenance. Because those caches are derived from public GitHub data and can serve more than one profile, they are not automatically erased with one Socialize account. Disabling the panel stops that profile from initiating new activity requests.
Your choices and rights
You can edit public profile content from the dashboard and control your chosen identity provider through that provider. Depending on your location, you may also have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, and to withdraw consent where processing relies on consent.
You can change or clear the GitHub username and repository selections, disable developer activity, or unpublish the profile from the dashboard. Disabling the feature removes its configuration from the public profile record on the next successful save; cached activity responses then expire on the schedule described above.
Use the Privacy choices button available throughout the service to allow, decline, or withdraw optional analytics on this device. Withdrawing consent stops future analytics collection from Socialize.
Send a request to llewellynpaintsil34@gmail.com. We may need to verify account control before acting. You may also complain to the data-protection authority available in your jurisdiction.
Browser storage and cookie choices are described in the Cookie Policy.
International use and children
Socialize and its providers may process information in countries other than yours. Where applicable law requires a transfer safeguard, the operator relies on the provider's approved contractual safeguards or another legally recognized transfer mechanism.
The managed service is not directed to children under 13, or a higher minimum age where local law requires it. If we learn that an ineligible child supplied personal information, we will take reasonable steps to remove it. A parent or guardian can contact the privacy address below.
Changes and contact
Material policy changes will be posted with a new update date and, where required, additional notice or consent. Continued use after an effective change is subject to the notice and applicable law.
Privacy questions and rights requests can be sent to llewellynpaintsil34@gmail.com. The service operator is Llewellyn Adonteng Paintsil, at cape Coast, Ghana.
A question about this policy?
Write to llewellynpaintsil34@gmail.com. Include the account or profile URL involved, but do not email passwords, access tokens, or service-account keys.