The short version.
- Holt reads public GitHub data. It never posts anything and never gets access to your repositories.
- If you sign in, we keep your name, email and profile picture from GitHub or Google, and your report history. Nothing else from either account. See signing in with Google.
- We don’t store API keys, and we don’t keep the access tokens GitHub or Google hand back at sign-in.
- Payments are handled by Razorpay (INR) and Dodo Payments (USD). Card details never reach us.
- One cookie to keep you signed in, one setting for your theme. Visits are counted by our own analytics, which sets no cookie and runs on our server. No ads, no third-party trackers, no selling data.
- Connecting your GitHub account is optional and for adults only. If you do, we note which repos you view here and may count your public contributions, anonymously, in repo statistics unless you opt out.
- Email us and we’ll delete your account and everything tied to it.
1. Who is responsible
Holt at githolt.com is run by a small team based in Patiala, Punjab, India. For any question about your data, email hello@githolt.com.
2. What we collect and why
If you only visit
- Your IP address is used to rate-limit anonymous requests so one person can’t overload the service. The limiter keeps it in memory for up to an hour. IP addresses also appear in ordinary server and proxy logs for a short time, which we use only to keep the site running.
- The repositories you look up are recorded as analysis jobs. For visitors who aren’t signed in, a job isn’t tied to a person.
- A daily count of requests. Each time someone asks for a report or runs a search, we note the day, the repository and a scrambled code made from your IP address (or your account, if you’re signed in). The code changes every day, so it tells us how many different people used Holt on a given day, but not who they are, and it can’t link your visits across days. The IP address itself isn’t stored.
- Visit counts from our own analytics. See section 5.
If you sign in
- Your name, email address and profile-picture link from GitHub or Google, and nothing else from either account. Sections 3 and 4 say exactly what each provider gives us and how to take it back.
- The sign-in library’s records: the provider’s ID for your account, so it can recognise you next time. The access tokens GitHub or Google return at sign-in are thrown away, not stored.
- Your analyses and history: which repositories you checked, when, in which mode, and the resulting reports, so your history page works.
- Your profile, if you fill one in: the languages, topics, time, kinds of contribution and experience you choose, and when you confirmed you’re 18 or older, used only to pre-fill your searches; delete it any time in settings.
- Repos you save: which repositories you saved and when, so your saved list works. Unsave one any time; deleting your account deletes the list.
- Your free AI reports: how many you have left, when you last claimed one, a record of each one given, used or given back, and your plan.
If you pay for something
- The processor (Razorpay for INR, Dodo Payments for USD) collects your payment details. We never see or store card, UPI or bank details.
- We receive and keep what we need to run your plan: your name and email, what you bought, the amount and currency, the payment or subscription ID, and its status. Receipts show the name Githolt.
- For USD purchases, Dodo Payments is the merchant of record and handles the transaction under its own privacy policy.
If you email us
We keep the email and our reply for as long as we need them to deal with your request.
3. Signing in with Google
You can sign in to Holt with a Google account. This section says exactly what that involves. It applies on top of everything else on this page.
What Holt receives from Google
When you choose “Sign in with Google”, Holt asks Google for the three basic sign-in scopes, openid, email and profile, and nothing more. Through them Google gives Holt:
- your name,
- your email address (and whether Google has verified it),
- the link to your profile picture,
- and Google’s ID for your account, so Holt can recognise you next time.
That is all. Holt has no access to your Gmail, Google Drive, Calendar, Contacts, Photos, YouTube or any other Google data, and it never asks for it. Holt can’t read, send, change or delete anything in your Google account.
What it’s used for
Only to create and identify your Holt account and to show your name and picture in the header when you’re signed in. Your email address is also how we recognise you if you write to us about your account. We don’t send marketing email.
What it’s never used for
- It is never sold.
- It is never shared with anyone except the services listed in section 8, and only as far as running Holt needs (for example, your name and email go to the payment processor if you buy a plan).
- It is never used for advertising, and Holt shows no ads.
- It is never used to train AI models, ours or anyone else’s. AI reports never include anything about you (see section 7).
- No human at Holt reads it except to answer a request you’ve made, or to keep the service running.
Where it’s stored and for how long
Your name, email and picture link are kept in Holt’s own database, on the server described in section 8, alongside the sign-in library’s record of your Google account ID. They are kept until you delete your account (see below) and are not copied anywhere else. The access token Google returns at sign-in is not stored, so Holt can’t fetch anything further from Google.
How we protect it
These are the actual measures in place today, not aspirations. We don’t hold any security certification and don’t claim one.
- Encrypted in transit. githolt.com is served only over HTTPS through Cloudflare, and the connection from Cloudflare to our server is an encrypted Cloudflare tunnel. Your details are encrypted the whole way from your browser to our server.
- The database isn’t reachable from the internet. It runs in a container on a private network on the server, with no public port. Only the app can talk to it, and the app itself is reachable only through the tunnel.
- Access is limited to the Holt team. Only the team can reach the server, the database and the backups. No third party has an account on the server.
- Secrets are kept out of the code. Sign-in credentials, database passwords and encryption keys live in files on the server that are outside the source code and readable only by the Holt team. Holt’s code is open source, and no secret is in it.
- No keys or tokens to leak. Holt doesn’t store API keys, or the GitHub and Google access tokens from sign-in.
- Backups are nightly and restricted. A copy of the database is taken every night, stored on the server with permissions that allow only the Holt team to read it, and deleted after 14 days. So after you delete your account, your details can remain in a backup for up to 14 days and are then gone.
- What we don’t claim: the database files themselves are not separately encrypted at rest beyond the protections above, and we don’t promise that no system can ever fail. If you find a weakness, section 11 says how to tell us.
How to take it back
- Revoke Holt’s access at any time from your Google account’s permissions page: myaccount.google.com/permissions. Holt then can’t sign you in with Google until you allow it again.
- Have your data deleted by emailing hello@githolt.com from the address on your account. We remove your account, the Google details above and your history. Revoking access at Google doesn’t delete your Holt account by itself, so do both if you want everything gone.
Holt’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. Signing in with GitHub
Signing in with GitHub works the same way. Holt asks GitHub only for your public profile and your email address (the read:user and user:email scopes) and receives your name, email, profile-picture link and GitHub account ID. It gets no access to your repositories, public or private, and can’t star, comment, open pull requests or do anything else on your behalf. The data is used, stored and deleted exactly as described for Google above. You can revoke Holt’s access at any time under GitHub settings → Applications, and email us to delete your account.
Connecting your GitHub account
Connecting GitHub is optional, free, and only for people 18 or older. You do it on the Connect GitHub screen, which says in one line: “Connecting lets Holt track your public contributions and include them anonymously in repo statistics (shown only when 5+ people contribute).” Connecting is how you agree to that; the switch below is how you say no to the statistics part.
- Why: to show you your own public pull requests with Holt’s verdict on each repo, to tell whether you opened a pull request soon after checking a repo on Holt, and to count your public contributions, without your name, in statistics about a repo. A repo’s statistics are shown only when 5 or more people’s contributions are in them.
- What we store: your GitHub account ID and username, when you connected, when you confirmed you’re 18 or older, whether you chose “Don’t include me in statistics”, and, while you’re connected, which repos’ report pages you opened on Holt (the repo, the first and last time, and how many times) and your public pull requests to other people’s repos from the last 12 months (repo, number, title, link, whether it was merged or closed, and the dates), refreshed daily.
- How we read GitHub: only public data, with Holt’s own access, never yours. Confirming your GitHub account asks GitHub for the same as signing in with it (your public profile and email address), no new permissions, and Holt can’t post, comment or open anything as you.
- Leaving statistics out: turn on “Don’t include me in statistics” on the Connect screen or in your settings, at any time. Your contributions are left out of every repo’s numbers from then on.
- Disconnecting: the disconnect button in settings deletes the connection, the list of repos you viewed and your saved pull requests, straight away. If you also sign in with Google, the link between your GitHub account and your Holt account is removed too.
- Deleting everything: email hello@githolt.com and we’ll delete your account and everything above with it.
5. Cookies and browser storage
- One session cookie, set only when you sign in, so you stay signed in. It contains a random token, not your details. If you skip the profile card, a second cookie remembers that for a year.
- Small settings in your browser’s local storage: your light or dark theme choice, and whether you closed the Hacktoberfest banner. These never leave your browser.
That’s all. There are no advertising cookies, no third-party analytics scripts, and no tracking pixels.
How we count visits
We count visits with Umami, an open-source analytics tool that we run ourselves, on the same server as Holt. Its script is loaded from githolt.com and sends its counts only to githolt.com. No analytics company receives anything.
- No cookies and nothing stored in your browser. That is why there is no cookie banner.
- What it records: the page you opened and the page you came from, your browser, operating system, device type, screen size and language, your country and approximate city (worked out from your IP address), and a few actions: pasting a repository, opening a report (with its verdict), opening a suggested starter issue, running a search and choosing a sign-in button.
- Not you. To tell one visitor from another, Umami combines your IP address and browser details into a scrambled code that changes every month. It doesn’t store your IP address, and nothing it records is tied to your account, name or email.
- If your browser blocks the script, Holt works exactly the same.
6. Public GitHub data and reports
Holt fetches public repositories, pull requests and comments through GitHub’s API. Reports are cached and shown publicly at githolt.com so the next person gets an answer instantly. A report is about how a project treats outside contributors. It may quote and link to public pull requests, including the public GitHub usernames on them, because every finding must be checkable at its source. Holt adds nothing that wasn’t already public on GitHub.
If you are a maintainer or contributor and believe a report quotes something it shouldn’t, email us and we’ll look at it.
7. AI providers
AI reports are optional. The verdict is computed by rules without a model. When you ask for an AI explanation, Holt sends the model the evidence it collected: excerpts of public pull-request titles, comments and metadata from the repository being analysed, plus Holt’s own findings. Nothing about you (no name, email or account information) is included.
- Requests go through OpenRouter, on Holt’s own account, which routes them to the vendor of the model Holt uses (currently an OpenAI, Google or Anthropic model). OpenRouter’s and that vendor’s policies apply to those requests.
8. Who else sees data
We don’t sell data, and we don’t share it with anyone for advertising. The services that touch data in order to run Holt are:
- GitHub: we read public data through its API. GitHub and Google also handle sign-in.
- Razorpay and Dodo Payments: payments, as described above.
- OpenRouter and the AI model vendors: only for AI reports, as described above.
- Cloudflare: DNS and the connection to our server, so it sees the same request data any web proxy does.
- Our hosting provider: the server and database run there.
We’ll also disclose data if the law requires it, and we’ll tell you when we’re allowed to.
9. How long we keep things
- Account details and your history: until you delete them or ask us to.
- Rate-limit records: up to an hour, in memory.
- The daily request counts and the visit counts: kept to see how Holt is used over time. Neither contains your IP address or anything that identifies you.
- Cached reports: kept so public report pages load fast and so we can see how a project changes over time. They contain public GitHub data, not account data.
- Payment records: as long as Indian tax and accounting rules require.
10. Your rights and how to delete your data
You can ask us to show you what we hold about you, correct it, or delete it. To delete your account, email hello@githolt.com from the address on your account, and we’ll remove your account and history. Cached public reports stay, because they contain no account data.
We follow India’s Digital Personal Data Protection Act, 2023. If you’re somewhere with other privacy laws, such as the EU or the UK, the same rights apply in practice: ask, and we’ll act on it.
11. Security
Everything travels over HTTPS. The database has no public port and is reached only through the app. We store no API keys or sign-in access tokens. Access to the server, database and backups is limited to the Holt team. The full list of measures is under how we protect it in section 3; it applies to everything we store, not only Google data. No system is perfect, so if you find a weakness, please email us before posting it publicly and we’ll fix it fast.
12. Children
Holt is not for children under 13, and we don’t knowingly keep data about them. If you think a child has an account, email us and we’ll remove it.
13. Changes
If this policy changes, the date at the top will change with it, and we’ll flag significant changes on the site. See also the terms of service and the refund policy.
14. Contact
Email hello@githolt.com. Details are on the contact page.