Privacy policy
Effective 2 August 2026
The Cadence app has no account, no analytics and no servers. It reads your contribution history from GitHub and keeps a copy on your device. This site is a separate, small system of its own, covered below under This website.
Who we are
Cadence is published under the project name Lokas Solutions, which is not a separate legal entity: the repository, the GitHub organisation and the support address all use that name. The app and this site are the work of Ivan Lokas, trading as Lokas Solutions, of Put Šepurine 1, 22215 Raslina, Croatia. That is who controls the data described below.
What is stored, and where
Everything the app holds is on your device:
- Your contribution history: daily counts and totals, in the app's local store.
- Your GitHub access token: on iOS, in the keychain; on Android, in an encrypted preferences store the operating system restricts to Cadence. Not included in a backup we control.
- Your GitHub login, stored without encryption alongside the token, so Cadence knows who you're connected as.
- Your theme choice: light or dark.
None of it is sent to us, because there is nowhere in the app to send it.
What the app talks to
One thing: GitHub, to sign you in through its own approval screen and to read your contribution counts using the read:user scope. There is no analytics service, no crash reporter and no advertising network built into the app. Apple and Google still give us, as the developer, crash and error reports, install counts and retention figures through App Store Connect and Play Console; that visibility comes from publishing through their stores, not from anything Cadence adds.
What the app can read on GitHub
read:user is the narrowest permission that can count private contributions. It reads your profile data and your contribution counts. It cannot read your code, and it cannot push, edit or delete anything. Private contributions are included as counts only — never repository names, commit messages or file contents.
You can revoke access at any time on GitHub, under Settings › Applications. Revoking stops any further reading. The copy already on your device stays readable until you clear it.
This website
Cadence's website runs on a Cloudflare Worker, so Cloudflare processes visitor IP addresses, request logs and security events on our behalf, under our legitimate interest in keeping the site working and secure. Cloudflare Web Analytics is enabled on this site: it counts visits and page views without cookies or a persistent identifier. We set no cookies of our own, build no advertising profiles and do no cross site tracking.
Deleting your data
Two controls in Settings do this. Disconnect removes the GitHub token only; the cached history stays. Clear everything removes the cached history and the token immediately. Uninstalling the app does the same as Clear everything. Depending on your device settings, app data may be included in a device backup managed by Apple or Google; those are managed through your device or account settings, not through Cadence.
Children
Cadence is not directed at children. Nothing reaches us from the app itself: contribution data and the GitHub token stay on the device. A GitHub account is needed to connect it, and that account has its own age requirement.
Support email
If you email support, that message is held in Gmail, our support inbox provider, for as long as it takes to answer you and for 12 months afterwards, in case anything you raised needs following up. The basis is our legitimate interest in providing support to people who ask for it. Please leave out anything sensitive unless it is needed to solve the problem.
Your rights
You can ask us to access, correct, erase or restrict what we hold about you, object to our use of it, or receive it in a portable form. In practice this mostly concerns support email: anything on your device is unreachable to us, so clearing it is done through the app's own controls, not through a request to us. You also have the right to complain to your supervisory authority; in Croatia, that is AZOP.
International transfers
Gmail and Cloudflare both operate outside the EEA. Where they move data across borders, they represent that they do so under an adequacy decision, the EU/US Data Privacy Framework, or Standard Contractual Clauses, as applicable to that provider.
Service providers
Cloudflare, for this site. Google Gmail, for the support address. Apple and Google, for distribution. GitHub, covered above, under its own privacy policy. If you follow the Sponsor link, you leave this site for GitHub, an independent controller of its own.
Changes
If this policy changes, the date above changes with it and the current version is published here.
Contact
Cadence is published by Ivan Lokas. Questions about this policy: lokassolutions@gmail.com.