How information is used

Privacy information

This describes the application’s current behavior. The operator’s identity, monitored contact, retention periods and account-removal procedure still need confirmation before public beta. Those outstanding details are not a completed privacy policy.

Account and sign-in

Sign-in uses Google or GitHub through Supabase Auth. Supabase stores account identifiers and identity information supplied by the sign-in provider, which can include an email address and provider profile information. The application uses a verified account identifier to connect you to your profile and contributions.

Authentication cookies keep your session and support the sign-in return flow. Signing out ends the current app session; it does not delete your account or promise to end sessions on other devices. Your sign-in email is not a public profile field, and provider names and email addresses are not automatically copied into the public profile.

Public and restricted information

Your profile identifier, handle, display name, bio and any profile website are public. Published project previews include the title, summary, author and creator attribution, category, robot, resource kinds and aggregate like count.

Published projects that are not hidden, including their full details, resource links and visible comments, can be read without signing in. Readers can copy or share that information. Sign-in is required to share or edit projects, comment, like, save or report content, and use a personal workspace.

Drafts, archived or hidden projects and revision history have restricted owner or staff access. Staff can access content for moderation. Access controls do not prevent authorized readers from copying information.

Saved projects, likes and reports

Ordinary members can access their own bookmarks and individual like records, not another member’s records. Like totals are visible. A saved project is omitted from your saved list when it is no longer available to you.

Reports include the reporter’s account, the target and the explanation. They are available to the reporter and authorized moderators. Staff can see report reasons and moderation history, including reasons for hiding content or restricting posting. These records are not published in the feed.

Authorized service operators with database access can access stored information to operate the service. “Private” here describes the community’s member-facing access controls; it does not mean content is encrypted so the operator cannot read it.

Usage events and operational logs

The app records bounded usage events such as project views, publication, resource openings, added bookmarks and feedback-contact openings. Records can include an account identifier, project or resource identifier and a timestamp. Anonymous usage recording can use a daily rotating keyed hash derived from the network address for rate limiting.

Usage records are stored privately. Application request logs contain a request ID, a route category, request method, response status and duration. Hosting and authentication services also process connection and service information. Opening a resource does not prove reuse; opening feedback does not prove a message was sent or received.

The app is built for Cloudflare Workers and uses Supabase for authentication and database storage. Google or GitHub handles the identity sign-in you choose. Google Fonts is loaded for the site’s fonts; optional project demonstrations can load an embedded YouTube player from youtube-nocookie.com. Those requests disclose connection information to the respective provider.

Project resources, social-sharing links and a configured feedback form can take you to other services with their own privacy practices. An embedded player can contact its provider when it loads. Contributor uploads and browser simulation are currently disabled.

Retention and removal requests

The app has no self-service account-deletion feature. Removing your own comment, unpublishing or archiving a project, and signing out do not delete the account. Comment deletion removes its body from normal discussion views; moderation records and other related records are separate.

Retention periods, removal or anonymization of contributions and interactions, treatment of reports and audit records, session handling and backup expiry still require an approved operator procedure. There is no automatic deletion schedule or guaranteed removal deadline stated here.

Use Feedback & support for the contact status and instructions for a privacy or removal request. If no contact is configured, this request route is not yet available. Do not send passwords, tokens or session cookies, and do not post private requests in comments.

See also the community guidelines.