GitHub asks for read:user, plus repo when private repos are ticked
(GitHub has no read-only private scope) and read:org when org repos are ticked too.
The token is used for this one generation, then revoked: never stored, never logged.
Tick private repos only when the username is your own GitHub account: a sign-in with private access as another account is refused.
Signed in as another account, you get public data only.