Other Site Policies Guidelines For Legal Requests Of User Data (GitHub)

OLOpen Legal LibraryUpdated 12 Aug 2026

Guidelines for Legal Requests of User Data

Are you a law enforcement officer conducting an investigation that may involve user content hosted on [company name]? Or maybe you're a privacy-conscious person who would like to know what information we share with law enforcement and under what circumstances. Either way, you're on the right page.

In these guidelines, we provide a little background about what [company name] is, the types of data we have, and the conditions under which we will disclose private user information. Before we get into the details, however, here are a few important details you may want to know:

We will notify affected users about any requests for their account information, unless prohibited from doing so by law or court order.

We will not disclose location-tracking data, such as IP address logs, without a valid court order or search warrant.

We will not disclose any private user content, including the contents of private repositories, without a valid search warrant.

About these guidelines

Our users trust us with their software projects and code—often some of their most valuable business or personal assets. Maintaining that trust is essential to us, which means keeping user data safe, secure, and private.

While the overwhelming majority of our users use [company name]'s services to create new businesses, build new technologies, and for the general betterment of humankind, we recognize that with millions of users spread all over the world, there are bound to be a few bad apples in the bunch. In those cases, we want to help law enforcement serve their legitimate interest in protecting the public.

By providing guidelines for law enforcement personnel, we hope to strike a balance between the often competing interests of user privacy and justice. We hope these guidelines will help to set expectations on both sides, as well as to add transparency to [company name]'s internal processes. Our users should know that we value their private information and that we do what we can to protect it. At a minimum, this means only releasing data to third-parties when the appropriate legal requirements have been satisfied. By the same token, we also hope to educate law enforcement professionals about [company name]'s systems so that they can more efficiently tailor their data requests and target just that information needed to conduct their investigation.

[company name] terminology

Before asking us to disclose data, it may be useful to understand how our system is implemented. [company name] hosts millions of data repositories using the [version control system]. Repositories on [platform name]—which may be public or private—are most commonly used for [primary use case], but are also often used to work on [other use cases].

Users: Users are represented in our system as personal [company name] accounts. Each user has a personal profile, and can own multiple repositories. Users can create or be invited to join organizations or to collaborate on another user's repository.

Collaborators: A collaborator is a user with read and write access to a repository who has been invited to contribute by the repository owner.

Organizations: Organizations are a group of two or more users that typically mirror real-world organizations, such as businesses or projects. They are administered by users and can contain both repositories and teams of users.

Repositories: A repository is one of the most basic [company name] elements. They may be easiest to imagine as a project's folder. A repository contains all of the project files (including documentation), and stores each file's revision history. Repositories can have multiple collaborators and, at its administrators' discretion, may be publicly viewable or not.

Pages: [company name] Pages are public webpages freely hosted by [company name] that users can easily publish through code stored in their repositories. If a user or organization has a [company name] Page, it can usually be found at a URL such as [url] or they may have the webpage mapped to their own custom domain name.

User data on [company name].com

Here is a non-exhaustive list of the kinds of data we maintain about users and projects on [company name].

Public account data: There is a variety of information publicly available on [company name] about users and their repositories. User profiles can be found at a URL such as [url example]. User profiles display information about when the user created their account as well their public activity on [company name].com and social interactions. Public user profiles can also include additional information that a user may have chosen to share publicly. All user public profiles display:

Username

The repositories that the user has starred

The other [company name] users the user follows

The users that follow them

Optionally, a user may also choose to share the following information publicly:

Their real name

An avatar

An affiliated company

Their location

A public email address

Their personal web page

Organizations to which the user is a member (depending on either the organizations' or the users' preferences)

Private account data: [company name] also collects and maintains certain private information about users as outlined in our Privacy Policy. This may include:

Private email addresses

Payment details

Security access logs

Data about interactions with private repositories

Organization account data: Information about organizations, their administrative users and repositories is publicly available on [company name]. Organization profiles can be found at a URL such as [url example]. Public organization profiles can also include additional information that the owners have chosen to share publicly. All organization public profiles display:

The organization name

The repositories that the owners have starred

All [company name] users that are owners of the organization

Optionally, administrative users may also choose to share the following information publicly:

An avatar

An affiliated company

Their location

Direct Members and Teams

Collaborators

Public repository data: [company name] is home to millions of public, open-source software projects. You can browse almost any public repository to get a sense for the information that [company name] collects and maintains about repositories. This can include:

The code itself

Previous versions of the code

Stable release versions of the project

Information about collaborators, contributors and repository members

Logs of Git operations such as commits, branching, pushing, pulling, forking and cloning

Conversations related to Git operations such as comments on pull requests or commits

Project documentation such as Issues and Wiki pages

Statistics and graphs showing contributions to the project and the network of contributors

Private repository data: [company name] collects and maintains the same type of data for private repositories that can be seen for public repositories, except only specifically invited users may access private repository data.

Other data: Additionally, [company name] collects analytics data such as page visits and information occasionally volunteered by our users (such as communications with our support team, survey information and/or site registrations).

We will notify any affected account owners

It is our policy to notify users about any pending requests regarding their accounts or repositories, unless we are prohibited by law or court order from doing so. Before disclosing user information, we will make a reasonable effort to notify any affected account owner(s) by sending a message to their verified email address providing them with a copy of the subpoena, court order, or warrant so that they can have an opportunity to challenge the legal process if they wish. In (rare) exigent circumstances, we may delay notification if we determine delay is necessary to prevent death or serious harm or due to an ongoing investigation.

Disclosure of non-public information

It is our policy to disclose non-public user information in connection with a civil or criminal investigation only with user consent or upon receipt of a valid subpoena, civil investigative demand, court order, search warrant, or other similar valid legal process. In certain exigent circumstances (see below), we also may share limited information but only corresponding to the nature of the circumstances, and would require legal process for anything beyond that. [company name] reserves the right to object to any requests for non-public information. Where [company name] agrees to produce non-public information in response to a lawful request, we will conduct a reasonable search for the requested information. Here are the kinds of information we will agree to produce, depending on the kind of legal process we are served with:

With user consent: [company name] will provide private account information, if requested, directly to the user (or an owner, in the case of an organization account), or to a designated third party with the user's written consent once [company name] is satisfied that the user has verified his or her identity.

With a subpoena: If served with a valid subpoena, civil investigative demand, or similar legal process issued in connection with an official criminal or civil investigation, we can provide certain non-public account information, which may include:

Name(s) associated with the account

Email address(es) associated with the account

Billing information

Registration date and termination date

IP address, date, and time at the time of account registration

IP address(es) used to access the account at a specified time or event relevant to the investigation

In the case of organization accounts, we can provide the name(s) and email address(es) of the account owner(s) as well as the date and IP address at the time of creation of the organization account. We will not produce information about other members or contributors, if any, to the organization account or any additional information regarding the identified account owner(s) without a follow-up request for those specific users.

Please note that the information available will vary from case to case. Some of the information is optional for users to provide. In other cases, we may not have collected or retained the information.

With a court order or a search warrant: We will not disclose account access logs unless compelled to do so by either (i) a [court order reference], or (ii) a [search warrant reference]. In addition to the non-public account information listed above, we can provide account access logs in response to a court order or search warrant, which may include:

Any logs which would reveal a user's movements over a period of time

Account or private repository settings (for example, which users have certain permissions, etc.)

User- or IP-specific analytic data such as browsing history

Security access logs other than account creation or for a specific time and date

Only with a search warrant: We will not disclose the private contents of any account unless compelled to do so under a search warrant issued under the procedures described in the Federal Rules of Criminal Procedure or equivalent state warrant procedures upon a showing of probable cause. In addition to the non-public account information and account access logs mentioned above, we will also provide private account contents in response to a search warrant, which may include:

Contents of secret Gists

Source code or other content in private repositories

Contribution and collaboration records for private repositories

Communications or documentation (such as Issues or Wikis) in private repositories

Any security keys used for authentication or encryption

Under exigent circumstances: If we receive a request for information under certain exigent circumstances (where we believe the disclosure is necessary to prevent an emergency involving danger of death or serious physical injury to a person), we may disclose limited information that we determine necessary to enable law enforcement to address the emergency. For any information beyond that, we would require a subpoena, search warrant, or court order, as described above. For example, we will not disclose contents of private repositories without a search warrant. Before disclosing information, we confirm that the request came from a law enforcement agency, an authority sent an official notice summarizing the emergency, and how the information requested will assist in addressing the emergency.

Cost reimbursement

Under state and federal law, [company name] can seek reimbursement for costs associated with compliance with a valid legal demand, such as a subpoena, court order or search warrant. We only charge to recover some costs, and these reimbursements cover only a portion of the costs we actually incur to comply with legal orders.

While we do not charge in emergency situations or in other exigent circumstances, we seek reimbursement for all other legal requests in accordance with the following schedule, unless otherwise required by law:

Initial search of up to [free identifiers number]: [free cost]

Production of subscriber information/data for up to [free accounts number]: [free cost]

Production of subscriber information/data for more than [paid accounts threshold]: [cost per account]

Secondary searches: [cost per search]

Data preservation

We will take steps to preserve account records for up to 90 days upon formal request from U.S. law enforcement in connection with official criminal investigations, and pending the issuance of a court order or other process.

Submitting requests

Please serve requests to:

[company address / legal service address]

Courtesy copies may be emailed to [company legal support email]

Please make your requests as specific and narrow as possible, including the following information:

Full information about authority issuing the request for information

The name and badge/ID of the responsible agent

An official email address and contact phone number

The user, organization, repository name(s) of interest

The URLs of any pages, gists or files of interest

The description of the types of records you need

Please allow at least two weeks for us to be able to look into your request.

[jurisdiction reference: federal law / state law]

By submitting legal process to [company name], you attest that the legal process does not relate to the violation of any law that creates liability for abortion-related conduct that is lawful in [state name].

Requests from foreign law enforcement

As a [jurisdiction country] company based in [jurisdiction state], [company name] is not required to provide data to foreign governments in response to legal process issued by foreign authorities. Foreign law enforcement officials wishing to request information from [company name] should contact the United States Department of Justice Criminal Division's Office of International Affairs. [company name] will promptly respond to requests that are issued via U.S. court by way of a mutual legal assistance treaty (“MLAT”) or letter rogatory.

Questions

Do you have other questions, comments or suggestions? Please contact [support link].

5.0 out of 5 on Google

Read reviews

As seen in

Law360
Artificial Lawyer
Insider
Axios Pro
San Francisco Business Times
Built In
Startups Magazine
Business Reporter
Tech.eu

California note

This version is drafted for California. US contract and employment rules vary by state, so it will not transfer cleanly elsewhere. Tell GitLaw where the parties are and it adjusts the draft.

Jurisdiction
California (US)
Source
G
Other Site Policies Guidelines For Legal Requests Of User Data (GitHub)
from GitHub
Document info
GitLaw document. Document created on Mon Oct 6th, 2025. Last updated on Wed Aug 12th, 2026.
This document is public
Licensed under CC BY 4.0 (Attribution).
Come to agreements faster
Write, review, negotiate, and manage legal contracts
Related documents
Denmark
Privacy Policy (Denmark) by Seedsummit
This internal data protection policy establishes how a company manages personal information in compliance with the EU General Data Protection Regulation. It defines processing principles such as data minimization and storage limitation, and outlines the responsibilities of a designated IT systems administrator in Denmark.
Updated 13 Aug 2026
US
VPN Privacy Notice by Mozilla
This privacy notice explains how a VPN service handles user data, encryption, and third-party sharing. It details the collection of account info, approximate location via IP address, and limited billing details from providers like Stripe or Apple.
Updated 13 Aug 2026
US
Firefox Relay Privacy Notice by Mozilla
This privacy notice outlines how an email alias service handles user data, including the processing of email messages and account information. It details data collection for Firefox Accounts, interaction logs, and technical device data while clarifying that email content is not read or stored.
Updated 13 Aug 2026
European Union
Content Moderation Practices by Mozilla
This document outlines how an organization manages content moderation for user-generated text, images, and software applications. It specifies the human-led review process for reports of illegal or policy-violating content and the subsequent appeals procedure for both reporters and account holders.
Updated 13 Aug 2026
England & Wales
Firefox Focus and Firefox Klar Privacy Notice by Mozilla
This privacy notice explains how a browser developer processes technical, interaction, and browsing data. It details user rights under data protection laws and provides options for managing data collection and search preferences.
Updated 13 Aug 2026
European Union
Privacy Policies Github Subprocessors (GitHub)
This document lists authorized subprocessors permitted to handle personal and customer data on behalf of an enterprise service provider. It includes a structured table for detailing the processor name, location, and the specific nature of data processing activities.
Updated 13 Aug 2026

Frequently asked questions

A template isn't binding on its own - like any contract, it becomes binding once it's properly completed and signed. Templates in our curated library are professionally drafted for US or UK law; review any template before you sign it.

Yes. Chat with GitLaw to edit any section, or make changes directly in the editor.

Yes, read about team plans here.

Describe what you need in the chat and GitLaw will draft it for you.

Templates in our curated library are professionally drafted for US or UK law. The wider library comes from the GitLaw community and public sources - a solid starting point, but check any template fits your situation before you rely on it.

Mostly US and UK law. Some templates use general commercial terms that work across jurisdictions, and many note which law they're written for.

It depends on the situation. Templates work well for routine business agreements. For anything involving significant money, complex IP, employment, or areas you're unsure about, it's worth getting professional advice before you sign. GitLaw provides templates and tools, not legal advice.

Open any template in GitLaw and describe the change you want in the chat — 'make clause 4 mutual' or 'add a 30-day notice period', for example. GitLaw drafts the revised language and shows it as a suggested edit. You accept, reject, or keep editing from there.

Yes. Upload a Word, PDF, or Markdown file and GitLaw will open it in the editor. You can review, edit, or chat with GitLaw about it the same way you would with any template from the library.

Trusted by thousands of businesses

“I found GitLaw to be extremely useful and convenient in helping draft a contract. It has tracking, an easy to understand and familiar interface and has saved thousands of dollars in fees.”

MH

Michael Hawkes

Read more on Google

“I found GitLaw useful to review my medical contract. I was able to check differences from previous contract and tell me which parts are not standard.”

PM

Priyanka Mandal

Read more on Google

“Needed contracts for the brewery. Worked well, very timely, good comms. A+”

CE

Craig Edmunds

Read more on Google

“GitLaw saves us hours when reviewing contracts. The AI suggestions are useful, and the platform is easy to adopt even for non-lawyers”

BB

Bojana Banjac

Read more on Google

“GitLaw stands out because it combines AI with a practical legal workflow. It helped me understand contract terms much faster and made the review process much more efficient.”

KL

Kristijan Lazic

Read more on Google

“A thoughtfully designed legal AI platform. Whether you’re creating new agreements or reviewing existing ones, GitLaw makes the process smoother and easier to understand.”

AM

Andjela Milovanovic

Read more on Google

“I needed this! I own a small business and I wrote all my contracts by myself from templates I saw online, later switched to chatGPT, but when I found gitlaw I was genuinely blown away by it. Great value for the price!!”

RD

Romana Dražić

Read more on Google

“I’ve used this to analyse a number of contracts recently, and my initial concerns were quickly allayed. It picked up on inconsistencies that would have taken me far longer to spot on my own”

“Super useful service! I’ve used it to review a few contracts and I really like how it explains and highlights parts of the documents to review more closely or question.”

MK

Marc Kimmel

Read more on Google

“GitLaw is building an AI Legal Companion that's actually grounded in law.”

GG

Greg Gretsch

Managing Director

“They save time, reduce cost, and make legal work more accessible. It's still early days for AI in law, but the progress is already impressive.”

AB

Aleksandar Blazhev

Entrepreneur

“I found GitLaw to be extremely useful and convenient in helping draft a contract. It has tracking, an easy to understand and familiar interface and has saved thousands of dollars in fees.”

MH

Michael Hawkes

Read more on Google

“I found GitLaw useful to review my medical contract. I was able to check differences from previous contract and tell me which parts are not standard.”

PM

Priyanka Mandal

Read more on Google

“Needed contracts for the brewery. Worked well, very timely, good comms. A+”

CE

Craig Edmunds

Read more on Google

“GitLaw saves us hours when reviewing contracts. The AI suggestions are useful, and the platform is easy to adopt even for non-lawyers”

BB

Bojana Banjac

Read more on Google

“GitLaw stands out because it combines AI with a practical legal workflow. It helped me understand contract terms much faster and made the review process much more efficient.”

KL

Kristijan Lazic

Read more on Google

“A thoughtfully designed legal AI platform. Whether you’re creating new agreements or reviewing existing ones, GitLaw makes the process smoother and easier to understand.”

AM

Andjela Milovanovic

Read more on Google

“I needed this! I own a small business and I wrote all my contracts by myself from templates I saw online, later switched to chatGPT, but when I found gitlaw I was genuinely blown away by it. Great value for the price!!”

RD

Romana Dražić

Read more on Google

“I’ve used this to analyse a number of contracts recently, and my initial concerns were quickly allayed. It picked up on inconsistencies that would have taken me far longer to spot on my own”

“Super useful service! I’ve used it to review a few contracts and I really like how it explains and highlights parts of the documents to review more closely or question.”

MK

Marc Kimmel

Read more on Google

“GitLaw is building an AI Legal Companion that's actually grounded in law.”

GG

Greg Gretsch

Managing Director

“They save time, reduce cost, and make legal work more accessible. It's still early days for AI in law, but the progress is already impressive.”

AB

Aleksandar Blazhev

Entrepreneur

“I used git.law to prepare my documents for the French prefecture and it made the whole process so much easier. Everything was clear and well organized and I felt confident submitting my file. Highly recommend!”

MA

Maryia Alenina

Read more on Google

“Excellent! Really happy I found this. Easy to use and has saved me so much time”

NM

Nishant Mandal

Read more on Google

“Really impressed with the user experience. GitLaw simplifies complex legal tasks without sacrificing quality. Highly recommended”

AR

Aleksandra Radin

Read more on Google

“One of the most practical AI legal tools I’ve tried. Clean interface, helpful features, and a team that’s clearly focused on solving real business problems”

“I’ve been impressed by GitLaw’s approach to contract management. The platform is easy to use, and the AI suggestions are practical and well thought out”

AV

Anisija Vrućinić

Read more on Google

“I love it!!”

JD

Jelena Drazic

Read more on Google

“Love the founder and this company. Very beneficial for startups like ours since we can review contracts and get stuff done easily and quicker.”

TG

Tejas Gupta

Read more on Google

“The amount of time (and headaches) this saves is unreal. There’s an endless supply of templates to start from, and no futzing around with layout and formatting.”

TD

Thomas Daly

Read more on Google

“Love this! Huge opportunity to increase productivity and efficiency within SMEs who rely on regulatory compliance.”

AC

Alex Cole

Founder, TIN Ventures

“Tried the AI chat and I must say, solid UX and impressive prompt interpretation. The multi-user collaboration workflow is a clear win for in-house teams. 👏”

MB

Mrinal Bhatt

HR, People & Culture @ Peakflo

“This is so cool. I remember seeing the template library before, and pivoting to an AI agent that uses them as a foundation is genius.”

CH

Chris Hicken

Co-Founder & CEO of TheySaid

“I used git.law to prepare my documents for the French prefecture and it made the whole process so much easier. Everything was clear and well organized and I felt confident submitting my file. Highly recommend!”

MA

Maryia Alenina

Read more on Google

“Excellent! Really happy I found this. Easy to use and has saved me so much time”

NM

Nishant Mandal

Read more on Google

“Really impressed with the user experience. GitLaw simplifies complex legal tasks without sacrificing quality. Highly recommended”

AR

Aleksandra Radin

Read more on Google

“One of the most practical AI legal tools I’ve tried. Clean interface, helpful features, and a team that’s clearly focused on solving real business problems”

“I’ve been impressed by GitLaw’s approach to contract management. The platform is easy to use, and the AI suggestions are practical and well thought out”

AV

Anisija Vrućinić

Read more on Google

“I love it!!”

JD

Jelena Drazic

Read more on Google

“Love the founder and this company. Very beneficial for startups like ours since we can review contracts and get stuff done easily and quicker.”

TG

Tejas Gupta

Read more on Google

“The amount of time (and headaches) this saves is unreal. There’s an endless supply of templates to start from, and no futzing around with layout and formatting.”

TD

Thomas Daly

Read more on Google

“Love this! Huge opportunity to increase productivity and efficiency within SMEs who rely on regulatory compliance.”

AC

Alex Cole

Founder, TIN Ventures

“Tried the AI chat and I must say, solid UX and impressive prompt interpretation. The multi-user collaboration workflow is a clear win for in-house teams. 👏”

MB

Mrinal Bhatt

HR, People & Culture @ Peakflo

“This is so cool. I remember seeing the template library before, and pivoting to an AI agent that uses them as a foundation is genius.”

CH

Chris Hicken

Co-Founder & CEO of TheySaid

From template to signed, in one place

Every template opens in an editor with an AI agent alongside it.

1

Open

Pick a template and open it. Nothing to download, and no credit card to start.

Free to open

2

Edit with AI

Describe your situation in chat and the agent adapts the wording, clause by clause.

Tracked changes you can review

3

Send and sign

Share it for negotiation, then collect signatures without leaving GitLaw.

eSign included

Built for your legal work, with practicing lawyers

Trained on 5.5K+ clauses and specialist areas of law. Built with a standards committee of independent lawyers.

Portrait headshots of the independent lawyers on the GitLaw standards committee

As seen in

Law360
Artificial Lawyer
Insider
Axios Pro
San Francisco Business Times
Built In
Startups Magazine
Business Reporter
Tech.eu

Start free

No sales calls, no credit card. Just chat with GitLaw.

GitLaw provides templates and tools, not legal advice. Templates are a starting point, not a substitute for advice on your situation - for anything significant, speak to a qualified lawyer.