Privacy Policy
Last updated: August 7, 2026
DotPM is a package registry for the DotC package manager. This page explains what information we handle and why. We keep things simple: there are no ads and no third-party trackers.
What we collect
- Account information. Sign-in is via GitHub OAuth only. We receive your GitHub username, display avatar, and email address, and use them to identify you on the site.
- Publishing data. When you publish a package we store its contents, metadata, and a content hash so versions stay immutable and verifiable.
- API keys. Keys used to publish are stored only as cryptographic hashes, never in plain text, and can be revoked at any time from your account page.
- Usage data. We may log basic request information (such as IP addresses) for rate limiting, abuse prevention, and troubleshooting. These logs are not used for profiling.
Cookies and local storage
We use an authentication cookie so you stay signed in, and local storage to remember your chosen theme. We do not use tracking cookies.
Sharing
We do not sell or share your personal information. GitHub processes your credentials during sign-in under GitHub's own privacy policy; we never see your GitHub password.
Your choices
You can sign out at any time, revoke or rotate your API keys from your account page, and remove any packages you own. To request deletion of your account data, contact the site operator.
Contact
Questions about this policy can be directed to the site operator.