Privacy
Opt-in, push only the card fields, delete on request, one privacy notice.
The ledger is built on your machine and sent by you, to whom you choose. Nothing is published unless you run the effortrank push, and the push asks every time.
What leaves the machine, and when
| When | What | Where |
|---|---|---|
| every build (the seal) | one 32-byte hash of the build — no content, no file names | OpenTimestamps calendar servers |
| every build (gathering) | your GitHub login and your name, as lookups | api.github.com, api.openalex.org (read-only, anonymous) |
| effortrank push (opt-in) | the receipt ids from your ledger (public repository, pull-request and paper ids only), your GitHub login(s), a timestamp, optionally a link to a copy of the ledger you host, and one signature per login made with an SSH key GitHub already lists for it | the EffortRank gallery |
Nothing is ever written to your GitHub account or any other account. The gallery computes the score from the receipts; no score is sent by you. The gallery reads github.com/<login>.keys to check the signatures.
What never leaves
Transcripts, session logs, the ledger text, the résumé, the cover letter, the PDF, private repository names, paths or contents, memory files, emails. The local sweep and the work log stay in ledger/raw/ on your disk.
What the gallery keeps
Per login: each pushed receipt list, the computed card, the time it was received, which logins were signed, and a hash of the signatures (to refuse replays). Versions accumulate; the card shows the latest.
Your rights
Unpublish: effortrank.sh delete <login>, signed with the same key, hides every version of your card. Erasure of the stored versions: ask the operator named on the gallery's notice page. No accounts, no cookies, no analytics.