Byline
Privacy policy
Draft — under review. This text is not yet ratified.
Effective date: to be set at launch. This policy mirrors the /data transparency page. Where they differ, the stricter reading governs.
What we collect
- Account: your GitHub identity (username, display name, avatar; email only if your GitHub profile provides one).
- GitHub connection: your own PRs, issues, reviews, and commits — titles, bodies, diff statistics, links. Read-only scopes; no organization data.
- Collector uploads: exactly what the repo's tier permits (see /data). Your code never leaves your machine.
- Profile: handle, display name, bio, and — if you provide them — your role and goal.
- Billing: handled by Stripe. We store subscription status, never card numbers.
- Usage: standard server logs. There are no analytics at launch.
How we use it
To build and synthesize your ledger, render your pages and exports, operate billing, and secure the service. Synthesis calls Anthropic's API with your artifact data; Anthropic processes it as a subprocessor.
What we never do
We never sell your data. We never show your ledger to your employer. We never publish anything you did not explicitly publish. Machine actions never widen visibility.
Research (opt-in only)
Byline supports published academic research on how engineering work is recognized. Participation is consent-based and mirrors the dashboard's Research card.
- What is shared: aggregate statistical patterns derived from ledgers — trends across many people — for published academic research.
- What is never shared: your name, your employer, the content of your entries, or anything that identifies you or any individual record.
- Off by default: research sharing is off unless you turn it on in your dashboard. Absence of a choice means you are out.
- Revocable: you can turn it off at any time, in any billing state. Turning it off stops all future inclusion.
Subprocessors
Convex (database and functions), Anthropic (synthesis), Stripe (billing), Vercel (hosting), GitHub (sign-in and data source).
Retention and deletion
Your data persists while your account exists, in any billing state. Deleting an entry removes it from every surface. Removing a repo removes its artifacts.
Closing your account (Dashboard → Danger zone) deletes your data immediately: your ledger, drafts, artifacts, public page and handle, vouches, collector tokens, and the GitHub connection. The stored GitHub token is destroyed and revoked at GitHub. Your Stripe subscription is canceled; Stripe keeps the billing records the law requires. Platform backups may hold deleted rows for a limited period, to be confirmed.
Your rights
Access, export, correction, deletion — the product's own controls provide all four. Email works too: hello@withbyline.com.
Changes
We announce material changes by email and on the site at least 15 days ahead.