Doodlebug

Privacy, in plain handwriting

What we store. Your name, email, a bcrypt hash of your password, your GitHub username, your default theme, and — only if you add one — your GitHub token encrypted with AES-256-GCM. We also keep a short-lived cache of the public GitHub data used to draw your cards, and an anonymous log of which card types were rendered (kept 30 days) to see what people use.

What we do with your token. It is decrypted in memory only when Doodlebug fetches your GitHub data, then discarded. It is never logged, never sent anywhere except api.github.com, and you can remove it in Settings at any time.

Email. We send email only to verify your address and for password resets. No newsletters, no marketing.

Cookies. A single httpOnly session cookie keeps you logged in. No analytics or third-party trackers.

Card images. Card URLs are public by design so they can render in READMEs. They only contain data GitHub already shows publicly (or, with your token, counts you chose to expose).

Deleting your account removes your profile and token immediately. Questions? Open an issue on the GitHub repo.

Privacy · Doodlebug