GitHub public profile privacy checklist
A GitHub profile is a professional portfolio and a public identity surface. Your bio, profile README, pinned projects, and contribution activity can reveal different details, so hiding one element may leave others visible. This checklist helps you inspect your own profile, adjust what you share, and avoid confusing a matching username with proof that two accounts belong to one person.
Key takeaways
- Read your own GitHub profile while signed out and inspect its bio, README, pinned items, links, and contribution display.
- A private GitHub profile can still show optional public fields, so review those fields instead of relying on one privacy toggle.
- Use a MyRecon username search to discover possible reuse of your handle, then validate every candidate at its original public page.
Inspect every visible profile element
Open your profile in a signed-out browser and read it as a stranger would. Check the bio, avatar, location, links, profile README, pinned repositories, and contribution display. GitHub says public profiles showcase information you choose to share; its profile README is shown when the matching public repository and root README exist. Remove details you did not intend to publish rather than relying only on search engine changes.
Understand what a private profile still shows
GitHub's documentation says making a profile private hides several activity and social elements, but optional fields including the README, bio, and profile picture can remain publicly visible. Review those fields individually before assuming your profile is hidden. Also inspect any public repository descriptions or README files under your control because profile privacy is not a blanket change to published repository content.
Review cross-platform username exposure
Use MyRecon to check where your own public GitHub handle appears, then open the original results. The same handle can be reused by a different person, so a match is not identity proof. MyRecon's Android app is free with no signup; its Google Play listing remains in closed testing, so some visitors may not be able to install it yet.
Make deliberate changes and recheck
Edit or remove unnecessary profile fields, change the visibility of projects you control when appropriate, and review the signed-out view again. Keep a small dated record of what changed and which URL you checked. Do not publish private contact details in a profile README to make an account easier to verify.
Check a public username
Use accounts and identifiers you own or are authorized to review. A matching username is a lead, not proof of identity.
Frequently asked questions
Does a private GitHub profile hide the bio and README?
GitHub's profile documentation says the optional README, bio, and profile picture can remain publicly visible even when the profile is private. Inspect those fields in a signed-out session and edit them separately if they disclose more than you want.
Why inspect pinned repositories during a profile audit?
Pinned items are part of the public profile presentation and can point visitors toward projects and descriptions you chose to highlight. Open each linked repository that you control and check its own visibility and text instead of judging exposure from the profile card alone.
Can a matching handle establish that a GitHub profile is mine?
No. A handle match only identifies a candidate public page. Confirm it through a link you published yourself or another independent source you control, and keep uncertain matches out of definitive identity claims.
Sources
Review your public footprint with MyRecon
Put this guide into practice with a public username self-audit on your own accounts or accounts you are authorized to review. Check every candidate at its source. The Android app runs a username sweep from your phone and labels uncertain checks as unknown.
Core app tools are free and need no signup. The Google Play listing is in closed testing, so only eligible testers can access it until public release. View MyRecon on Google Play.