Privacy
What we collect, and what we deliberately don't.
Last updated: 2026-08-25
Browsing the gallery
View and try events are recorded with a rotating anonymous identifier (a first-party cookie that cannot be linked back to you) and a hashed browser signature for deduplication. Event payloads contain no IP address, no email, and no page URLs beyond the project being viewed. Aggregate traffic is measured by Cloudflare's cookieless zone analytics. There are no advertising trackers on this site.
Signing in
Accounts use OAuth (X, Google, or GitHub). We store the username, avatar, and email your provider shares, and use them for account features only: claiming a project, favorites, comments, and messages. We never post on your behalf.
The API and MCP server
Calls to the reference API and MCP server log the search text (as an anonymous product signal — what people are looking for) and the calling tool's user-agent. No IP address and no identity are attached. API keys are stored only as SHA-256 hashes, with per-day usage counts.
Catalog listings
Project listings are assembled from makers' own public announcements (X posts, Show HN, and similar) and from what a project's public URL serves. A listing shows the maker's public handle and links to the source post. Makers can claim their listing any time, and can write to us to correct or remove it.
Who processes data
Supabase (database and authentication), Google Firebase App Hosting (serving the site), Cloudflare (CDN and aggregate analytics), and Resend (transactional email). A daily public snapshot of catalog data — never user data — is published to GitHub.
Retention and contact
Anonymous event rows are kept for aggregate statistics; identifiers rotate and cannot be joined back to a person. Delete your account (or ask us to) and profile data goes with it. Questions, corrections, removals: [email protected].