Privacy
Last updated 12 September 2026.
DevImprint measures AI-assisted commits in public repositories and ranks developers by them. That means it holds information about people who never signed up for it, and most of you are reading this because you found yourself on a list you did not ask to be on. This page is written on that assumption.
The short version: everything measured is already public, the ranking is built from commit history, and a small amount of extra information — roughly what country you are in, and the social links you published on your own profile — is held privately so that hiring conversations can be aimed sensibly. That extra information isnever published on this site. Nothing is ever sold. You can be removed at any time, without giving a reason, by writing to [email protected].
Who is responsible
The controller is <CONTROLLER>, contactable at[email protected]. Our representatives in the EU and the UK are named at the foot of this page.
This page is not live yet. The controller name, the postal address and the representatives are placeholders until the entity is settled. Do not treat this as a published notice until they are filled in.
Where the information comes from
Not from you. That is the most important thing on this page, and it is why this notice exists at all: data protection law requires that when information about someone is collected from somewhere other than the person themselves, they are told about it. There are two sources, and both are public.
- Public repository history. Commits, the tool signatures they carry, when they were made, the repositories they landed in, and the timezone offset git records alongside every commit date.
- Your public profile on the hosting provider. Your account name and avatar, and — where you filled them in — your location, company, bio, website, and the social accounts you added to your profile.
We do not read private repositories. We do not use your commit email address as a way to contact you. We do not request the profile scope that would give us your email address, so we do not have it. We do not scrape LinkedIn or any other site: a LinkedIn link is only held when you published it yourself in your hosting profile's own social accounts feature.
What is published, and what is not
This distinction is the centre of how DevImprint is built.
| Information | On the public site? |
|---|---|
| Account name, avatar, profile link | Yes |
| Commit counts, rank, tools detected, activity dates, repository names | Yes |
| Commit email address | No — replaced with an opaque handle before publication |
| Country, world region, US state | No |
| Commit timezone offset | No |
| LinkedIn and other social links | No |
| Company, bio, website | No |
Location is only ever held at the level of a country. We do not hold your city, your address, or coordinates, and we do not send anything to a geocoding service. We do not infer your nationality, your residency, or your right to work anywhere, from your timezone or from anything else.
Why it is held
The lawful basis is legitimate interests. The interest is straightforward: hiring for AI-assisted engineering is currently done with take-home tests and interviews, and we think what someone has actually shipped in public is better evidence. The ranking cannot be built on consent, because a ranking that only contains people who agreed to be in it is not a ranking.
The location and social links exist for one purpose: to build a shortlist a company can act on, and to have a way to ask you whether you want to be introduced. Nobody is ever introduced to a company without agreeing to it first.
We assessed that balance in writing before collecting any of it, and we were candid with ourselves that it is a close call rather than an obvious one. The assembly of ninety thousand people into one ranked, filterable table is a bigger thing than any single fact in it, and no developer anticipated it when they pushed a commit. It holds because the extra information is never published, never sold, stops at country level, and because objecting ends it immediately. If you think we got that balance wrong in your case, you do not have to argue the point — see below.
Who else sees it
Nobody buys it. The data is not sold, licensed, rented or brokered, and there is no paid API serving it.
A company hiring for a role may be shown a shortlist that names you — but only after you have been asked and have said yes. If that has happened, you can ask us which company and when, and we will tell you.
Infrastructure providers process data on our behalf in the ordinary way: the cluster host, the object store holding pipeline artifacts, the CDN serving this site, and the mail provider handling[email protected]. They act on our instructions and for no other purpose. Processing takes place outside the EU and the UK.
How long
Ranking data is kept while the repositories it came from remain public and in scope. Profile information — location, company, social links — is refreshed or deleted every twelve months; if we have not re-confirmed a field against your public profile within a year, we should not still be holding it.
If you ask to be removed, we keep a single record of your account name and the date, indefinitely, and nothing else. That record exists so that a later scan cannot quietly put you back.
Your rights
You can ask for a copy of everything held about you, have it corrected, have it erased, restrict how it is used, or object to it entirely. There is no charge, and we answer within one month.
You do not have to give a reason for an objection, and we will not ask for one or try to change your mind. An objection is treated exactly like an erasure request.
We will not ask you for identity documents. Proving you control the account is enough — a message from the account, an email from an address shown on your public profile, or a verification string you put in a public gist.
Removal takes effect on the next build and covers the leaderboard, your profile page, the downloadable document and the social card; the profile URL then returns a permanent “gone” response. The private information is deleted at the same time. Aggregate totals keep the commits with no identity attached to them.
If you are unhappy with how we handle a request, you can complain to a data protection supervisory authority — in the EU, the authority where you live or work.
Decisions made about you automatically
The ranking is computed automatically, but no decision with a legal or similarly significant effect is made about you by a machine. A shortlist is assembled by a person, and an introduction only happens if you agree to it.
Rank is a count of detectable AI-assisted commits and nothing more. It cannot see private work, or work where tool attribution was turned off, and it says nothing about your ability. The methodology pageis explicit about what the number cannot see.
Cookies and analytics
This site sets no tracking cookies, runs no advertising, and does not fingerprint visitors. Analytics, where used, are cookieless and aggregate.
Changes
If what we hold or why changes materially, this page is updated and the date at the top changes with it. The interesting changes are the ones that add a category of information, and those will be described rather than folded silently into the text.