7.2. Content Removal Policies - Private Information Removal Policy
This document outlines a Private Information Removal Policy, detailing the process for requesting the removal of high-risk private information from a platform. It defines what constitutes private information and security risk, specifies appropriate and inappropriate removal requests, and explains the steps involved from investigation to resolution. The policy is designed for platforms hosting user-generated content, particularly software development communities.
Private Information Removal Policy
This document is taken from the GitHub website - more information about GitHub and its functions can be found at https://github.com/. Please note that many of the included provisions are designed for GitHub or similar site (such as for building and developing software with online communities), so they are not relevant to all types of business.
You can amend this document to be suitable for your own Community and purposes using the smart fields and customizing the bracketed sections. We recommend adding hyperlinks to your own policies and website pages - make sure your business has in place all the policies referred to here.
We offer this private information removal process as an exceptional service only for high-risk content that violates our Terms of Service, such as when your security is at risk from exposed access credentials. This guide describes the information [company name] needs from you in order to process a request to remove private information from a repository.
What is Private Information?
For the purposes of this document, “private information” refers to content that (i) should have been kept confidential, and (ii) whose public availability poses a specific or targeted security risk to you or your organization.
"Security risk" refers to a situation involving exposure to physical danger, identity theft, or increased likelihood of unauthorized access to physical or network facilities.
Private information removal requests are appropriate for:
Access credentials, such as user names combined with passwords, access tokens, or other sensitive secrets that can grant access to your organization's server, network, or domain.
AWS tokens and other similar access credentials that grant access to a third party on your behalf. You must be able to show that the token does belong to you.
Documentation (such as network diagrams or architecture) that poses a specific security risk for an organization.
Information related to, and posing a security risk to, you as an individual (such as social security numbers or other government identification numbers).
Private information removal requests are not appropriate for:
Internal server names, IP addresses, and URLs, on their own. You must be able to show that their use in a particular file or piece of code poses a security threat.
Mere mentions of your company's identity, name, brand, domain name, or other references to your company in files on [company name]. You must be able to articulate why a use of your company's identity is a threat to your company's security posture.
Entire files or repositories that do not pose a specific security risk, but you believe are otherwise objectionable.
This is a preview. The full template is free on GitLaw.
5.0 out of 5 on Google
Read reviewsAs seen in








United States note
This version is drafted for US law generally. Contract, employment and consumer rules vary by state — for example on non-competes and at-will employment. Tell GitLaw which state applies and it adjusts the draft.
Frequently asked questions
A template isn't binding on its own - like any contract, it becomes binding once it's properly completed and signed. Templates in our curated library are professionally drafted for US or UK law; review any template before you sign it.
Yes. Chat with GitLaw to edit any section, or make changes directly in the editor.
Yes, read about team plans here.
Describe what you need in the chat and GitLaw will draft it for you.
Templates in our curated library are professionally drafted for US or UK law. The wider library comes from the GitLaw community and public sources - a solid starting point, but check any template fits your situation before you rely on it.
Mostly US and UK law. Some templates use general commercial terms that work across jurisdictions, and many note which law they're written for.
It depends on the situation. Templates work well for routine business agreements. For anything involving significant money, complex IP, employment, or areas you're unsure about, it's worth getting professional advice before you sign. GitLaw provides templates and tools, not legal advice.
Open any template in GitLaw and describe the change you want in the chat — 'make clause 4 mutual' or 'add a 30-day notice period', for example. GitLaw drafts the revised language and shows it as a suggested edit. You accept, reject, or keep editing from there.
Yes. Upload a Word, PDF, or Markdown file and GitLaw will open it in the editor. You can review, edit, or chat with GitLaw about it the same way you would with any template from the library.
Trusted by 5,000+ businesses


From template to signed, in one place
Every template opens in an editor with an AI agent alongside it.
Open
Pick a template and open it. Nothing to download, and no credit card to start.
Free to open
Edit with AI
Describe your situation in chat and the agent adapts the wording, clause by clause.
Tracked changes you can review
Send and sign
Share it for negotiation, then collect signatures without leaving GitLaw.
eSign included
Built for your legal work,
with practicing lawyers
Trained on 5,500+ clauses and specialist areas of law. Built with a standards committee of independent lawyers.
As seen in








Ready to get started?
No sales calls, no credit card. Just chat with GitLaw.
GitLaw provides templates and tools, not legal advice. Templates are a starting point, not a substitute for advice on your situation - for anything significant, speak to a qualified lawyer.



