Legal

Privacy Policy

Last updated: September 12, 2026

This policy explains how Good First Issue handles account information, GitHub-connected workflows, indexed public GitHub data, logs, and cookies.

Overview

Good First Issue helps users discover beginner-friendly open source issues and repositories. This policy explains the information we process to operate that service.

This policy is informational and should be reviewed by qualified counsel before relying on it as legal advice or as a final legal policy for production use.

Account information

Sign-in is handled by GitHub through a GitHub App. There is no password and no separate account registration. When you sign in we store the identifier GitHub gives us: your GitHub user id, your username, and the email address GitHub reports for your account (or, if your email is private, the verified address from your GitHub email settings).

We use this information to authenticate requests, show account state, support user-specific GitHub workflows, and troubleshoot service behavior.

GitHub access tokens

Signing in gives the service a GitHub user access token and a refresh token, which are stored encrypted. The service uses them to call the GitHub API on your behalf for the workflows that need it, and rotates the token pair on a schedule so the access token stays valid.

Tokens are never displayed in the product interface, are excluded from request logs, and are deleted when GitHub rejects the refresh token or when you revoke the app's access in your GitHub settings.

Public GitHub data

The service stores indexed public GitHub data needed for discovery and synchronization. This may include repository metadata, issue metadata, labels, counts, body text, and links back to GitHub.

This data originates from GitHub and public repositories. It may be stale, incomplete, or removed from GitHub after it has been indexed here.

Analytics

The site runs Google Analytics (GA4) to understand which pages and workflows are used. It sets its own cookies and sends the page you visited, its referrer, an approximate location, and a random client identifier to Google. Account information, GitHub tokens, and repository content are not part of that payload. The site runs no advertising or profiling trackers.

Operational logs

The service writes application logs for operational visibility, debugging, abuse prevention, and reliability work. Logs may include route names, request status, user ids, repository identifiers, repository URLs, error details, and task progress metadata.

Logging is configured to redact tokens, passwords, and similar credentials, but you should not put secrets into repository descriptions, issue content, names, URLs, or other public fields that may be indexed from GitHub.

Cookies and sessions

We use a single signed session cookie to keep you signed in; Google Analytics sets its own analytics cookies (_ga) to count visits. The session cookie is required for authentication and the site sets no advertising cookies. Your browser may let you block or delete cookies, but blocking the session cookie prevents sign-in from working.

Sharing

We share information with service providers only as needed to operate, secure, host, and maintain the service. Those providers are the GitHub API, our hosting and database infrastructure, our logging and monitoring stack, and Google Analytics.

If AI-assisted content enrichment is enabled, the public repository and issue text being enriched may be sent to the configured model provider. Account information and tokens are not part of that payload.

We may also disclose information if required by law, to protect the service, to investigate abuse or security issues, or as part of a project transfer or reorganization.

Retention

We keep information for as long as needed to operate the service, maintain indexed public GitHub data, troubleshoot issues, comply with legal obligations, and protect the service.

Because much of the indexed content comes from public GitHub repositories, deleting or changing content on GitHub may not immediately remove previously indexed copies from this service. You can ask us to remove an indexed repository through the contact page.

Your choices

You can revoke the app's access at any time in your GitHub settings (Settings → Applications → Authorized GitHub Apps), which stops further API access on your behalf. For access, correction, deletion, or other privacy requests, contact the project through the Good First Issue GitHub organization. We may need enough information to verify the request and identify the relevant account or indexed data.

Contact: https://github.com/goodfirstissueorg

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.