Last updated July 17, 2026
Privacy policy
Short version: we collect what we need to run the service, we don't sell or share your data, and you can delete it any time.
What we collect
- Email address — when you subscribe to the newsletter, request a free audit, request a 30-min call, or sign in with a magic link.
- GitHub org name — when you submit the audit form. We use the public GitHub API to read the org's public repos, stars, languages, and contributor activity.
- Audit results — bus factor, dormancy, and abandonment analysis for the orgs you submit. Stored for 90 days, then deleted.
- Session cookie — when you sign in. A signed HTTP-only cookie that lasts 30 days.
- Anonymous analytics — page views, referrers, and one-shot events (audit_submit, audit_call_requested) via Google Analytics 4. We do not track you across sites. You can opt out via your browser's Do Not Track header.
What we do not collect
- Your full name (unless you provide it on a form)
- Your physical address, phone number, or government ID
- Your browsing history outside of
breakpoint.network - Payment information (we don't store it — Stripe would handle that if/when paid checkout ships)
How we use your data
- Email — to send the audit report (within 24h), the call-request follow-up, the newsletter (weekly Monday digest, or whatever cadence we publish), and magic-link sign-in.
- GitHub org — to produce the audit report. We do not modify the org or its repos.
- Anonymous analytics — to understand which pages are useful and where the audit funnel leaks.
Third parties
We share your data with three services, and only as needed to run:
- Resend — transactional and newsletter email delivery. Email is sent from
[email protected]to your submitted address. - GitHub — the public REST API for audit data. We use unauthenticated requests (60 req/hr) or authenticated requests (5000 req/hr) with a server token. We only read public data.
- Cloudflare — hosting, CDN, D1 database, KV. Cloudflare's privacy policy applies to the data they process on our behalf: cloudflare.com/privacypolicy.
- Google Analytics 4 — anonymous page-view analytics. Google's privacy policy applies: policies.google.com/privacy.
We do not share your data with advertisers, data brokers, or marketing platforms.
Your rights
- Unsubscribe — every email we send has a one-click unsubscribe link signed with an HMAC token. The link works without a session.
- Access — email [email protected] for a copy of all data we have on you.
- Deletion — email [email protected] with "delete my account" and we'll purge your email, audit submissions, and session data within 7 days.
- Correction — same email, tell us what's wrong and we'll fix it.
Cookies
We use one cookie: __session, an HTTP-only signed session cookie for authenticated users. It expires after 30 days. We do not use third-party tracking cookies.
Data retention
- Audit submissions: 90 days, then deleted
- Newsletter subscribers: until you unsubscribe
- Sessions: 30 days of inactivity, then expired
- Account data: until you request deletion, then within 7 days
Children
BreakPoint is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has submitted data, email [email protected] and we'll delete it.
Changes to this policy
We'll update the "Last updated" date at the top when we make material changes. For significant changes (anything that broadens what we collect or who we share with), we'll email active subscribers at least 14 days before the change takes effect.
Contact
Email [email protected] with any question, request, or complaint. We respond within 24 hours.