Doodlebug is open source5

Privacy, in plain handwriting

What we store. Your name, email, a bcrypt hash of your password, your GitHub username, your default theme, and — only if you add one — your GitHub token encrypted with AES-256-GCM. We also keep a short-lived cache of the public GitHub data used to draw your cards, and an anonymous log of which card types were rendered (kept 30 days) to see what people use.

What we do with your token. It is decrypted in memory only when Doodlebug fetches your GitHub data, then discarded. It is never logged, never sent anywhere except api.github.com, and you can remove it in Settings at any time.

Email. We send email only to verify your address and for password resets. No newsletters, no marketing.

Cookies and analytics. A single httpOnly session cookie keeps you logged in — that is the only cookie Doodlebug sets. Page views are counted with Vercel Web Analytics, which is cookieless: it records aggregate counts per page and sets nothing on your device. There are no advertising trackers and nothing follows you to other sites.

Card images. Card URLs are public by design so they can render in READMEs. They only contain data GitHub already shows publicly (or, with your token, counts you chose to expose).

Deleting your account removes your profile and token immediately. Questions? Open an issue on the GitHub repo.