I absolutely understand the rationale of asking for permission to view my private repositories, but you're asking for read AND WRITE permissions to my (and I assume my company's) private repos without giving any information about how you protect my or my company's closed source code.
My suggestion (being completely unfamiliar with the Github permissions API) would be to only ask for read permissions to public repos for people who get to the login page by clicking "View live demo." I understand it might limit the live demo but personally I just want to see the UI and what have you. No need for write permissions.
edit: And you're also asking for permission to read AND WRITE my email, my followers and my profile. I cannot think of any web app I would grant those kinds of permissions to my Github account. I am sure this is just a benign mistake but it could be perceived as sloppy.