RepoKit ("the extension," "we," "us") is a browser extension that enhances the GitHub.com repository browsing experience. This policy explains what data RepoKit handles, why, and how it is protected.
WHAT DATA WE HANDLE
1. GitHub Personal Access Token (optional)
If you choose to unlock RepoKit's features on private repositories, you may provide a GitHub personal access token. This token is stored locally in your browser using Chrome's built-in storage (chrome.storage.local). It is used solely to add an Authorization header to requests RepoKit makes, on your behalf, directly to GitHub's own API (api.github.com and raw.githubusercontent.com). RepoKit does not require a token to use its core features on public repositories.
2. Local usage flags
RepoKit stores one small local flag to remember whether you've already seen its one-time token-setup walkthrough, so it doesn't show it to you again. This flag contains no personal information.
3. Repository content
To power features like file sizes, line counts, search, duplicate-file detection, and content copying, RepoKit reads file and folder data from the GitHub repositories you browse. This data is fetched directly from GitHub's public API in response to your actions, is processed entirely within your browser, and is displayed back to you on the page. It is never stored by RepoKit beyond your current browsing session, and it is never sent to any server we operate.
WHAT WE DO NOT DO
- We do not operate our own backend server. RepoKit talks only to GitHub's own domains (github.com, api.github.com, raw.githubusercontent.com).
- We do not collect, transmit, or have access to your personal access token, your repository contents, or your browsing activity. Everything stays on your device.
- We do not sell, rent, or share any data with third parties.
- We do not use your data for advertising, analytics, profiling, or any purpose unrelated to RepoKit's single purpose of enhancing GitHub's file browser.
- We do not use any data to make credit or lending decisions.
- We do not track your activity across other websites.
DATA RETENTION AND DELETION
Your personal access token and local flags remain in your browser's local storage until you remove them. You can delete them at any time by clearing the extension's data in your browser settings, or by uninstalling RepoKit, which removes all locally stored data associated with it.
THIRD-PARTY SERVICES
RepoKit communicates only with GitHub's official API and content-delivery domains to perform the actions you request (such as reading file sizes or downloading a file). Your use of GitHub itself remains subject to GitHub's own Privacy Statement and Terms of Service.
CONTACT
Questions about this policy or how RepoKit handles data can be sent to: a.mhamimi@outlook.com