Last updated 2 October 2026

Privacy

No ads, no tracking across sites, no selling. Here is everything we keep and why.

1. Who is responsible

Ewen Le Quéré, who publishes Sidetown as a private individual, is responsible for your data. Contact: ewen@favikon.com.

2. What we keep

  • From GitHub when you sign in: your GitHub account ID, username, display name and avatar address, and the public no-reply address GitHub gives every account, never your real email. We ask GitHub for your public profile only, and we do not keep the access token it sends back.
  • What you add: your page's address, name and bio, who can see it, and your projects (name, pitch, status, hours, dates, links, stack, epitaph, hidden or not).
  • A session to keep you signed in, without your IP address or your browser.
  • GitHub previews: when someone types a GitHub username, we read that account's public repositories (names, descriptions, homepages, dates, commit counts) to draw a preview city. Previews are never indexed and never become a city until their owner signs in.
  • Server logs: like any web server, ours records each request (IP address, date, page, browser) to keep the site secure and working.
  • Anonymous counts: when a project is saved, a link is shared or a card is drawn, our server tells PostHog that it happened, with a random id and a few fixed values (a status, a format, a channel). No cookie, no script in your browser, nothing that identifies you or links one event to another.

3. Why

To run the service you signed up for: your account, your city, your page and its images (the contract between us). Server logs keep the site secure and working, and anonymous counts show which features people use (our legitimate interest). No ads, no selling, no tracking across sites.

4. What is public

On a public page: your address, name, bio, visible projects and your city. Its card and story images have public addresses so apps can preview your link. An unlisted page is reachable by its link only and skipped by search engines. Hidden projects never appear.

5. Who else handles it

OVHcloud
Hosting · France
Neon
Database · Frankfurt, Germany
GitHub
Sign-in · United States
PostHog
Anonymous counts · European Union

Your data stays in the European Union, except at sign-in, when GitHub (United States) tells us who you are. That transfer relies on the EU–US Data Privacy Framework, under which GitHub is certified.

6. How long

  • Your account, city and projects: until you delete your account. Deletion is immediate; our database provider keeps a six-hour history to recover from mistakes, after which deleted data is gone for good.
  • Sessions: they expire after seven days; deleting your account removes them all.
  • GitHub previews: read again after 24 hours, deleted after 7 days at most, and at once when the account they show is deleted here.
  • Server logs: not kept for a set number of days; they rotate, and the oldest are overwritten once they reach 30 MB in total. They are never copied elsewhere.

7. Cookies

One session cookie keeps you signed in, plus a short-lived one during GitHub sign-in to check the request came from you. Nothing else, so no banner. Visitors who don't sign in get no cookie at all.

8. Your rights

From Settings, you can export everything we keep about you as one JSON file, correct your name, address and bio, and delete your account. For anything else (objecting, restricting, a question), write to ewen@favikon.com.

You can also complain to the CNIL (cnil.fr).