Privacy Policy

Last updated: 7/23/2026

Welcome to CraftScore. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our SaaS platform (the "Service"). We respect your privacy and are committed to protecting the personal data we process in compliance with GDPR, LGPD, and other applicable laws.

1. Our Role in Data Processing

For the purposes of this policy, it is important to distinguish the categories of data we process:

  • Data Controller: When we collect data from our direct users (recruiters, administrators), CraftScore acts as the Data Controller.
  • Data Processor: When we process data from job candidates (third parties) at the request of our users, CraftScore acts solely as a Data Processor. The user (the hiring company) is the Controller and is responsible for ensuring they have the appropriate legal basis to analyze the candidate's code and data.

2. Data We Collect

2.1. User Data (You)

When you create an account and use CraftScore, we collect:

  • Profile Information: Name, email address, and profile picture/avatar (extracted from GitHub).
  • Authentication Data: GitHub ID, OAuth Access Tokens, and Refresh Tokens strictly necessary to keep your session active and connect repositories.
  • Organizational Data: Names of Workspaces created, GitHub App installation IDs, and email addresses of team members invited by you.

2.2. Financial Data

We do not store credit card numbers or sensitive payment data on our servers. All payments are processed by secure, PCI-compliant third parties (Polar.sh / Stripe). We only store billing identifiers (e.g., polar_customer_id, polar_subscription_id) and your current plan status.

2.3. Third-Party Data (Evaluated Candidates)

To generate metrics and scores, the platform processes information from repositories linked by the User, which includes candidate and contributor data, such as:

  • Name and GitHub Username.
  • Email address (extracted publicly or privately from Git commit metadata).
  • Intellectual Property (source code, branches, pull requests, comments, and version history).

3. How We Use Information

We use the collected data to:

  • Provide, operate, and maintain the Platform.
  • Calculate code metrics, Code Churn, and collaboration/AI analysis scores.
  • Process transactions and manage subscriptions.
  • Send support communications, updates, and security alerts.

4. Data Sharing

We do not sell your data. We share information only with essential infrastructure providers (e.g., cloud hosting services, transactional email providers, and payment processors like Polar.sh) under strict confidentiality agreements.

5. Your Rights

You have the right to access, correct, or delete your personal data. If you wish to close your account and remove your authentication data and history, please contact our support. For candidate data (where we are Processors), deletion requests must be directed to the recruiter/company that originated the analysis.

6. Contact Us

For questions about this policy or your data, please contact us at: [email protected]