Legal
Privacy Policy
Last updated 24 August 2026
This describes what the site actually does, read off the code that runs it. There is no advertising network here, no analytics tag, no tracking pixel and nothing to sell: we count what people open so that a catalog of tools can be ranked by something other than who paid.
When you are just reading
You never have to say who you are, and we do not try to work it out. Our server, and the CDN in front of it, necessarily see the ordinary shape of a web request — the URL, the time, the browser string, the IP address it came from. That is how a request reaches a server at all; what matters is that none of it is assembled into a profile of you, and none of it is passed to anyone who would.
The one thing we set is a random session id in a cookie called sid, and only when you click through to a tool, when a listing reports that it was viewed, or when you send us something — a form, a sign-in, a save. Reading a page on its own sets nothing. The id is a random number: it is not derived from you, and it says nothing about you beyond tying your own actions together so a reload is not counted as a second visitor.
What an event row holds
When you view a listing, click out to a tool, save one, rate one or post on one, we append a row with:
- what happened (view, click-out, save, rating, post);
- which tool it was about;
- the random sid, and your account id if you are signed in;
- the page that referred you, when your browser sends one;
- a two-letter country code, from the CDN — country only, never a city, coordinates or an address;
- one of three device buckets — desktop, mobile or bot — derived from the browser string. The browser string itself is not stored.
No IP address is written to our database. Addresses are used only in short-lived abuse counters held in memory and in our cache — a per-address request budget that expires within minutes, and a daily counter of how many distinct sessions one address presents, kept in a structure that counts without storing what it counted. Neither is joined to the events above.
What these numbers are for: the counts you see on a card, the click-out totals a listed tool’s owner is shown for their own tool, and the demand signal in the effect score. Owners see aggregates for their own listing, never a list of people.
If you make an account
An account is optional. Everything in the catalog is readable without one; an account exists so that saves, reviews and questions have an author.
What we store:
- your email address, and either a hash of your password (never the password) or the id of the Google account you signed in with;
- a display name and an @handle, which is public — reviews, questions and answers are published under it;
- anything you choose to add to your profile: bio, website, country, social links. All optional, all public, all editable at /settings/profile;
- a profile photo, if you upload one. We keep a 256-pixel square we make from your picture, on our own server; everything else in the file — camera details, location metadata — is discarded at upload. It is public wherever your name appears, and the file is deleted the moment you replace or remove it, or delete the account. We never load a photo from a link you paste, so no other site learns who views your profile;
- what you post and what you save, and the reputation points those earn;
- your up/down votes on tools. Only the two totals are ever shown — the list of who voted stays on the server. A vote lives until you retract it (clicking the same thumb removes it) or until the account is deleted, which deletes every vote with it.
Sign in with Google is optional and asks Google for the standard sign-in scope only — openid, email and profile. It works only with a Google-verified email, and we store the account id, the email and the name. We are never given your Google password and never ask Google for anything else.
Submitting a tool stores what the form asks for, including the email you give us, so we can tell you the outcome. It does not subscribe you to anything.
Email we send
Transactional only, and only about something you started: your submission was received, approved, or rejected with the reason. There is no newsletter and no marketing email today. If that ever changes it will be something you opt into, not something that arrives.
Who else touches the data
Cloudflare
DNS and CDN in front of the site. It terminates the connection, so it sees your IP address and the request, and it is where the country code on an event comes from.
Resend
Sends the transactional email above. It receives the recipient address and the message. No marketing list runs through it.
Google
Only if you choose Sign in with Google. We ask for openid, email and profile, and Google tells us your account id, email address and name.
Nobody else. We do not sell data, we do not share it with advertisers or data brokers, and there is no third-party tracker embedded in these pages. We would disclose data if a valid legal order compelled us to, and we would say so publicly where the law allows it.
The site runs on our own server rather than a platform, so the database and the cache are ours and the data in them is not passed to anyone beyond the services listed above.
How long we keep it
- Abuse counters — minutes for a request budget, at most a couple of days for the per-address session counter. Then they are gone.
- Sign-in sessions — 30 days, or until you sign out.
- Profile photo — until you replace or remove it, or delete the account. The previous file is deleted on the spot, not kept as a version.
- Event rows — kept while they are useful for the counts and rankings they feed. We do not yet run an automatic purge, and we would rather say that than print a retention period no job enforces.
- Account data — until you ask us to delete it.
Your choices
You can read the catalog without an account, edit or empty your profile at any time, sign out to drop your session, and clear our cookies from your browser.
Ask us and we will give you a copy of what your account holds, correct it, or delete the account and the content posted under it. There is no self-service delete button yet — a person handles the request — and we will confirm when it is done. Content already published under your handle is removed with it; the anonymous event rows are not tied to your identity and are not individually recoverable from it.
Depending on where you live — the EU, the UK, California and others — the law gives you rights of access, correction, deletion, portability and objection. We will honour a request on those grounds. What we will not do is claim a compliance certification nobody has audited: this is a young site describing its actual practice, and the practice is meant to be the honest one rather than the well-worded one.
Requests reach us through the channels on the contact page.
Children
The site is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has created an account, tell us and we will remove it.
Changes, and how to reach us
When this changes we update the date at the top. A change that affects what we collect, rather than how it is worded, will be said plainly rather than folded into a paragraph.
Questions about any of this go through the contact page.