Honest by design
A green graph is a bad metric, and most developers know it. So we built the tool so that the person who clicks the repo sees exactly what happened, and so that undoing it is one click. This page says everything out loud.
What actually happens
When you execute a fill, RetroFill does four things to your GitHub account, and only these four:
- Creates one new repository with the name you typed, on your account. If a repository with that name exists, we stop.
- Pushes real git commits to it. Each commit has a real diff — a note, a utility function and its test, a journal entry — a varied commit message, and an author date you chose or the realism engine generated, in your timezone.
- Signs them with your GitHub noreply address (
<id>+<login>@users.noreply.github.com) and your display name. That is why GitHub counts them; it is also why they are unmistakably yours. - Records the job in your History so it can be undone.
Autopilot does the same, one day at a time, into a dev-journal repository it creates once, and only on days you have not already contributed for real.
What we never do
- Touch any other repository. You choose which repositories RetroFill may reach, and GitHub enforces it: a write anywhere else is refused, and a private repository you did not pick is invisible to us. On top of that, the engine records the id of every repository it creates, refuses to write to any repository whose id it did not record, and undo deletes only those.
- Ask for more access than the next step needs. Sign-in is read-only. Write scopes are requested when you press EXECUTE, not before.
- Hide the repository. It is public by default, on your profile, under a name you chose. Private repos are an option on paid tiers and follow GitHub’s own “private contributions” switch.
- Fill someone else’s graph. You can preview any public username; you can only push to the account you signed in with.
- Sell or share your data, run ad trackers, or read the contents of your other repositories.
- Use words like “fake” or “trick”. These are real commits with real timestamps in a real repository. What you say they mean is up to you.
How anyone can tell
Anyone can open the repository and read every commit. They will see a small project that grew over time with plausible messages and plausible files — with the realism engine it will not scream “generator” — but the repository was created on one day and the commits carry earlier dates, and git makes no secret of that: the push date and the author dates are both there for anyone who looks.
We think that is the right amount of visible. It keeps the squares honest to anyone who cares enough to click, and it keeps the decision about what the squares mean where it belongs: with you.
Where we stand on GitHub's rules
Backdating commits in your own repository is a normal git feature — author dates have been settable since 2005 — and GitHub’s policies do not mention the contribution graph. GitHub’s Acceptable Use Policies do prohibit, in their words, “automated excessive bulk activity and coordinated inauthentic activity”, and inauthentic interactions such as fake accounts.
We built RetroFill to sit clearly on the right side of that line:
- One repository, on your own account, with your own name on the commits.
- Human-scale volumes with hard caps: at most 30 commits on any day and 20,000 per fill.
- No third-party filling, no bulk accounts, no reselling. The terms forbid using RetroFill to misrepresent work to an employer, client or school.
- Nothing touches other people’s repositories, issues, stars or pull requests. There are no “interactions” at all — only commits in a repository of yours.
- Undo is one click and deletes everything the fill created.
GitHub could change its rules or how contributions are counted. We cannot control that. If it happens we will say so here and in the app, keep undo working, and refund purchases that can no longer be used.
Push safety
The realistic risk with any activity generator is tripping a platform’s automated spam heuristics. We reduce it in the places we can:
- Caps on commits per day and per fill, and one running job per account.
- The Contribution Doctor warns accounts younger than 30 days before their first fill and suggests starting small.
- Commit times fall inside a safe window and look like work sessions, not a burst at midnight.
- Autopilot commits only on missed days, at human hours, never more than the persona would.
If GitHub ever asks us to pause a job, we will, and we will tell you.
What we store, and how to delete it
- Your GitHub profile
- id, login, name, avatar URL, primary email and account creation date — for sign-in, commit authorship and the account-age check.
- An OAuth token
- encrypted at rest with AES-256-GCM, used only to read your calendar and to create, push to and delete the one repository.
- Your plans and job logs
- the days you painted, the seed, the repo name and template, and the execution log — so History and undo work.
- A Stripe customer id
- if you buy something. Stripe holds the card; we never see the number.
Plus your purchases, product events such as sign-in, fill and undo, and the inviter’s code if you came through an invite link. No repository contents beyond what we write, no tracking pixels. “Delete account” in Settings removes all of it immediately. Repositories already on GitHub stay on GitHub, so use Undo first if you want them gone. The full list is in the privacy policy.
What it's for — and what it isn't
People use RetroFill for pixel art across the year, for restoring work GitHub never counted — a wrong email, a squashed history, a private employer account — for keeping a streak through a rough month, and because a green graph makes them happy. All fine.
Don’t present the squares as evidence of specific work. Not to an interviewer, not to a client, not on a résumé line. They will click the repo, and they should be able to. That rule is in our terms, and it is the one we will actually enforce.
Questions or something we got wrong? support@retrofill.dev.
Ready to go green?
Free to paint. A few dollars to push. One click to undo.
Connect GitHub> press CONNECT to begin · read-only sign-in