Skim privacy policy
Skim is a GitHub App that marks noise files in a pull request as viewed
for the reviewers who authorize it.
What it reads
- The names of the files changed in a pull request, their line counts, and
whether you have already marked them viewed. Never the contents of those files
or of the changes.
- Two configuration files from the pull request's branch:
.github/review-ignore and .gitattributes. The App's
GitHub permissions do not allow it to open any other file.
- Your GitHub login and user id, and which installations of the App you can
see.
What it stores
- Your GitHub access and refresh tokens, encrypted with AES-256-GCM. The key
is kept apart from the database.
- The names of the files it marked viewed for you, so it can undo them.
These are deleted when the pull request is merged or closed.
- For accounts that bought a plan on GitHub Marketplace: the account id,
login and plan name.
What it does not do
- It does not sell, share or analyse your data, and uses no trackers or
cookies beyond what GitHub's sign-in needs.
- It does not read code, comment, approve, merge or push.
Deleting your data
Revoke Skim under GitHub → Settings → Applications → Authorized GitHub
Apps. Your tokens, links and records are deleted as soon as GitHub tells us.
Uninstalling the App from an account removes every reviewer's link to it.
Where it runs
On a server in Frankfurt, Germany, hosted by Fly.io.
Questions: pawelferchmin@gmail.com