Privacy
Last updated October 9, 2026.
Many people who use has-a.tech are under 18, so we collect as little as we can and keep it for as short a time as we can. This page explains exactly what we collect.
What we collect and why
When you sign in with GitHub
GitHub tells us your username and when your account was created. We use the creation date once, to check your account is at least 30 days old, and don't store it. We don't get access to your repositories, and we can't post or change anything on your account.
When you verify your school email
- We use your email address once, to send you a code. We don't store your email address.
- We store a keyed fingerprint of it (a scrambled version made with a secret key) so one school email can't verify several GitHub accounts. The fingerprint can't be read back into your address by anyone who doesn't have our secret key.
- We store your school's email domain (for example
utoronto.ca), your GitHub username, and when you verified.
If you verify by contacting us
Whatever you send us is used only to check you're a student, then deleted. We keep a note that your GitHub account was verified by hand, and nothing else.
Your domain file
The file you add to the register is public, like everything on GitHub: your name, GitHub username, description and where your address points. Don't put personal information in it.
Cookies
We use two cookies, only so sign-in works: one that lasts 10 minutes while you sign in with GitHub, and one that keeps you signed in for up to an hour. No ads, no analytics, no tracking.
Abuse prevention
To stop people from flooding inboxes with codes, we count how many codes are requested. These counters use scrambled versions of your IP address and email, never the real ones, and they're deleted after about an hour.
Who else handles your data
- Cloudflare runs our website and stores the verification records.
- Resend delivers the email with your code, so it sees your school email address to send it.
- GitHub handles sign-in and hosts the public register.
We never sell or share your information with anyone else.
How long we keep it
- Codes: deleted after 15 minutes, or as soon as they're used.
- Verification records: until you delete them, or until you stop using has-a.tech and ask us to remove them.
- Rate-limit counters: about an hour.
Your choices
- Delete your verification any time on the verify page (sign in, then "Delete my verification").
- Remove your address by deleting your file from the register with a pull request.
- Ask us anything, or ask us to delete your data, at verify@has-a.tech. A parent or guardian can contact us on your behalf too.
Changes
If we change this policy, we'll update this page and the date at the top.