Privacy policy / 개인정보 처리방침
English
RepoRun inspects selected setup files in a GitHub repository to explain declared execution requirements. It does not install dependencies, execute commands, evaluate repository scripts, or write to GitHub. This policy describes the bundled 1.0.1 implementation.
Data processed
On github.com, the extension reads the current repository URL and repository-identifying DOM elements to place its Run setup control. It observes in-page navigation. There is no browser-history permission, general browsing-history database, background polling, or analysis request just because a repository page was visited.
When you open the panel or explicitly inspect a directory, the extension sends repository identifiers, branch or Git object identifiers and normal HTTP metadata to GitHub's REST API at api.github.com. GitHub receives your IP address and, if provided, your token. Requests retrieve repository metadata, directory listings and a bounded set of setup/documentation files. Raw files can contain commands, personal information or secrets supplied by their authors. They are processed in extension memory, not executed.
Storage and retention
chrome.storage.local stores only the interface language preference. chrome.storage.session stores the optional GitHub token, authentication epoch, API rate-limit state and normalized inspection reports. Reports may contain repository names, paths, commit IDs, runtime declarations, script definitions and small README command excerpts. The extension never writes raw configuration files or environment-example values to persistent storage. Environment output retains names and evidence locations, not assignment values.
Reports are considered fresh for five minutes; at most eight reports are retained, bounded to approximately 1.5 MB of serialized report data. Expired reports are rejected when read and pruned on subsequent report writes, not erased by a continuously running timer. Chrome clears session storage on browser restart, extension disable/reload or update. Language remains until extension data is cleared or the extension is removed. Reports are not synchronized by RepoRun.
Token handling
Public repository reads can work without a token within GitHub's anonymous limits. A token is optional; prefer a fine-grained token limited to required repositories with Contents read permission. It is sent only to api.github.com as an Authorization header. GitHub session cookies are omitted. A saved-token message confirms storage, not connection or repository authorization. Diagnostics query the fixed /rate_limit endpoint only on your request.
Session storage is not an encrypted vault. A person controlling the device, browser profile or debugging environment may access it. Redaction of obvious token/password patterns is best-effort and does not guarantee that a command or report contains no sensitive information.
Sharing and controls
RepoRun has no publisher-operated backend, account system, analytics, advertising, AI service or remote executable code. It does not sell data or transfer reports to the publisher. GitHub is the service used for the core feature and processes its network requests under its own policies.
You can remove the token, clear report caches, and change language in Settings. Explicit Copy actions write the visible script text to the clipboard. Export downloads a Markdown report after a warning; reports may disclose private repository names, paths and commands. Downloads are separate local files and are not removed by clearing the extension cache or uninstalling it. Review reports before sharing.
Permissions
storage is used for settings and temporary session data. https://github.com/* is used for repository identification and the injected panel; only the bundled logo SVG is exposed as a web-accessible resource. https://api.github.com/* permits read-only GitHub API requests from the service worker. RepoRun does not request cookie access, all-sites access, browser-history access, native messaging or terminal access.
Policy and source questions can be raised through the publisher profile below. Reference: GitHub privacy statement and Chrome storage documentation.
한국어
RepoRun은 GitHub 저장소의 일부 설정 파일을 읽어 명시된 실행 조건을 정리하는 확장프로그램입니다. 의존성 설치, 명령 실행, 저장소 스크립트 평가, GitHub 쓰기 작업을 수행하지 않습니다. 이 방침은 함께 제공된 1.0.1 구현에 적용됩니다.
처리하는 정보
github.com에서 현재 저장소 URL과 저장소를 식별하는 DOM 요소를 읽어 실행 조건 버튼을 배치하고 페이지 내부 이동을 감지합니다. 방문 기록 권한, 일반 방문 이력 데이터베이스, 주기적 감시가 없습니다. 저장소를 방문했다는 이유만으로 분석 API를 호출하지 않습니다.
패널을 열거나 디렉터리를 직접 분석하면 저장소·브랜치·Git 객체 식별자와 일반 HTTP 정보를 api.github.com에 전송합니다. GitHub는 IP 주소와 입력한 경우 토큰을 받습니다. 저장소 메타데이터, 디렉터리 목록 및 제한된 설정·문서 파일을 조회합니다. 원문에는 작성자의 명령, 개인정보, 비밀값이 있을 수 있습니다. 확장 메모리에서 처리할 뿐 실행하지 않습니다.
저장과 보관 기간
chrome.storage.local에는 화면 언어만 저장합니다. chrome.storage.session에는 선택적 토큰, 인증 세대 식별자, API 한도, 정규화한 분석 보고서를 저장합니다. 보고서에는 저장소 이름·경로·커밋·런타임 선언·스크립트 정의·README 명령 일부가 포함될 수 있습니다. 설정 파일 원문이나 환경변수 예제의 값을 영구 저장하지 않으며, 환경변수 결과에는 이름과 근거 위치만 남깁니다.
보고서는 5분 동안 최신 자료로 취급하며 최대 8개, 직렬화한 보고서 약 1.5 MB 이내로 보관합니다. 만료 여부는 조회 시 검사하고 후속 저장 시 정리하며 상시 타이머로 즉시 삭제하지는 않습니다. Chrome 재시작·확장 비활성화·재로드·업데이트 시 세션 정보가 삭제됩니다. 언어 설정은 확장 데이터 초기화나 제거 때까지 유지됩니다. 자체 동기화 기능은 없습니다.
토큰 처리
공개 저장소는 GitHub의 비인증 API 한도 내에서 토큰 없이 읽을 수 있습니다. 토큰이 필요하면 대상 저장소만 선택하고 Contents 읽기 권한을 지정한 fine-grained PAT를 권장합니다. 토큰은 api.github.com의 인증 헤더로만 보내고 GitHub 웹 로그인 쿠키는 보내지 않습니다. 저장 완료 메시지는 연결이나 저장소 권한 검증을 의미하지 않습니다. 연결 진단은 사용자 요청에 따라 고정된 /rate_limit만 조회합니다.
세션 저장소는 암호화 금고가 아닙니다. 기기·프로필·디버깅 환경을 제어하는 사람은 정보를 볼 수 있습니다. 명백한 토큰·비밀번호 패턴 가림은 보조 조치이며, 모든 민감정보 제거를 보증하지 않습니다.
외부 전송과 사용자 관리
개발자 운영 서버, 계정 시스템, 이용 분석, 광고, AI 서비스, 원격 실행 코드가 없습니다. 정보를 판매하거나 보고서를 개발자에게 전송하지 않습니다. 핵심 기능에 필요한 GitHub 통신에는 GitHub의 정책이 적용됩니다.
설정에서 토큰 삭제, 보고서 캐시 삭제, 언어 변경을 할 수 있습니다. 직접 복사를 누르면 표시된 스크립트를 클립보드에 기록합니다. 보고서 내보내기는 경고 확인 후 Markdown 파일을 내려받으며 비공개 저장소 이름·경로·명령이 포함될 수 있습니다. 내려받은 파일은 별도 자료이므로 캐시 삭제나 확장 제거로 없어지지 않습니다. 공유 전에 내용을 검토하세요.
권한
storage는 설정·세션 자료에, github.com 접근은 저장소 식별·패널 삽입에 사용합니다. 웹 접근 가능 자산은 함께 제공한 로고 SVG 한 개뿐입니다. api.github.com 접근은 서비스 워커의 읽기 전용 API 통신에 사용합니다. 쿠키·전체 사이트·방문 기록·네이티브 메시징·터미널 권한은 요청하지 않습니다. 문의 경로는 하단 개발자 프로필을 참고하세요.