12. Content Removal Policies - GitHub Private Information Removal Policy

DdanUpdated 17 Oct 2025

This document outlines GitHub's policy and process for requesting the removal of private information from repositories. It defines what constitutes "private information" for removal purposes, such as access credentials or sensitive organizational data, and details the steps a complainant must follow to submit a valid removal request. The policy also clarifies what types of content are not appropriate for this specific removal process.

GitHub Private Information Removal Policy

In this article

What is Private Information?

Things to Know

How Does This Actually Work?

Sending A Private Information Removal Request

How to Submit Your Request

Disputes

We offer this private information removal process as an exceptional service only for high-risk content that violates GitHub's Terms of Service, such as when your security is at risk from exposed access credentials. This guide describes the information GitHub needs from you in order to process a request to remove private information from a repository.

What is Private Information?

For the purposes of this document, “private information” refers to content that (i) should have been kept confidential, and (ii) whose public availability poses a specific or targeted security risk to you or your organization.

"Security risk" refers to a situation involving exposure to physical danger, identity theft, or increased likelihood of unauthorized access to physical or network facilities.

Private information removal requests are appropriate for:

Access credentials, such as user names combined with passwords, access tokens, or other sensitive secrets that can grant access to your organization's server, network, or domain.

AWS tokens and other similar access credentials that grant access to a third party on your behalf. You must be able to show that the token does belong to you.

Documentation (such as network diagrams or architecture) that poses a specific security risk for an organization.

Information related to, and posing a security risk to, you as an individual (such as social security numbers or other government identification numbers).

Private information removal requests are not appropriate for:

Internal server names, IP addresses, and URLs, on their own. You must be able to show that their use in a particular file or piece of code poses a security threat.

Mere mentions of your company's identity, name, brand, domain name, or other references to your company in files on GitHub. You must be able to articulate why a use of your company's identity is a threat to your company's security posture.

Entire files or repositories that do not pose a specific security risk, but you believe are otherwise objectionable.

Requests to remove content that may infringe your or your organization's copyright rights. If you have questions about how GitHub handles copyright-related matters or would like to report potentially infringing content, please review our DMCA Takedown Policy. The private information removal process is generally not intended for the removal of full files or repositories — only for the specific pieces of private information in those files. While there may be cases where files are filled entirely with private information, you must justify the security risk for the removal of such files, and this may increase the time required to process your request.

Trademark disputes. If you have questions about how GitHub handles trademark-related matters or would like to report content containing your organization's trade or service marks, please review our Trademark Policy.

This is a preview. The full template is free on GitLaw.

5.0 out of 5 on Google

Read reviews

As seen in

Law360
Artificial Lawyer
Insider
Axios Pro
San Francisco Business Times
Built In
Startups Magazine
Business Reporter
Tech.eu
Jurisdiction
Jurisdictions aren't set for this document
Document info
HTML document. Document created on Tue Jul 15th, 2025. Last updated on Fri Oct 17th, 2025.
This document is public
Licensed under CC BY 4.0 (Attribution).
Come to agreements faster
Write, review, negotiate, and manage legal contracts
Related documents
US
VPN Privacy Notice by Mozilla
This privacy notice explains how a VPN service handles user data, encryption, and third-party sharing. It details the collection of account info, approximate location via IP address, and limited billing details from providers like Stripe or Apple.
Updated 13 Aug 2026
US
Security Policies Github Sirt Description Rfc 2350 (GitHub)
This document provides a standardized description of a Computer Security Incident Response Team (CSIRT) following the RFC 2350 protocol. It details contact methods, the team's mission and authority, and specific procedures for handling security incidents.
Updated 13 Aug 2026
US
Firefox OS Privacy Notice by Mozilla
This privacy notice explains how an operating system handles user data related to updates, location services, and device activation. It outlines user options for disabling data sharing for app usage and search engine analytics directly within device settings.
Updated 13 Aug 2026
Denmark
Privacy Policy (Denmark) by Seedsummit
This internal data protection policy establishes how a company manages personal information in compliance with the EU General Data Protection Regulation. It defines processing principles such as data minimization and storage limitation, and outlines the responsibilities of a designated IT systems administrator in Denmark.
Updated 13 Aug 2026
US
Privacy Notice for Firefox for Fire TV and Firefox for Echo Show by Mozilla
This privacy notice informs users about the collection of technical and interaction data within browser applications for smart devices. It outlines how technical data, interaction data, and voice commands are processed, including the role of third-party services like Amazon Alexa.
Updated 13 Aug 2026
Report a Violation on Formulaic by Mozilla
This notice explains how users can report content policy violations on a digital platform and outlines the subsequent moderation and appeals process. It specifies the information required for a report, the potential penalties for publishers, and the six-month window for appealing a moderation decision.
Updated 13 Aug 2026

Frequently asked questions

A template isn't binding on its own - like any contract, it becomes binding once it's properly completed and signed. Templates in our curated library are professionally drafted for US or UK law; review any template before you sign it.

Yes. Chat with GitLaw to edit any section, or make changes directly in the editor.

Yes, read about team plans here.

Describe what you need in the chat and GitLaw will draft it for you.

Templates in our curated library are professionally drafted for US or UK law. The wider library comes from the GitLaw community and public sources - a solid starting point, but check any template fits your situation before you rely on it.

Mostly US and UK law. Some templates use general commercial terms that work across jurisdictions, and many note which law they're written for.

It depends on the situation. Templates work well for routine business agreements. For anything involving significant money, complex IP, employment, or areas you're unsure about, it's worth getting professional advice before you sign. GitLaw provides templates and tools, not legal advice.

Open any template in GitLaw and describe the change you want in the chat — 'make clause 4 mutual' or 'add a 30-day notice period', for example. GitLaw drafts the revised language and shows it as a suggested edit. You accept, reject, or keep editing from there.

Yes. Upload a Word, PDF, or Markdown file and GitLaw will open it in the editor. You can review, edit, or chat with GitLaw about it the same way you would with any template from the library.

Trusted by 5,000+ businesses

Nexus logoMlabs logoTechstars logo

From template to signed, in one place

Every template opens in an editor with an AI agent alongside it.

1

Open

Pick a template and open it. Nothing to download, and no credit card to start.

Free to open

2

Edit with AI

Describe your situation in chat and the agent adapts the wording, clause by clause.

Tracked changes you can review

3

Send and sign

Share it for negotiation, then collect signatures without leaving GitLaw.

eSign included

Built for your legal work,
with practicing lawyers

Trained on 5,500+ clauses and specialist areas of law. Built with a standards committee of independent lawyers.

As seen in

Law360
Artificial Lawyer
Insider
Axios Pro
San Francisco Business Times
Built In
Startups Magazine
Business Reporter
Tech.eu

Ready to get started?

No sales calls, no credit card. Just chat with GitLaw.

GitLaw provides templates and tools, not legal advice. Templates are a starting point, not a substitute for advice on your situation - for anything significant, speak to a qualified lawyer.