Privacy
Last updated 2026-07-31.
What we collect
Signing in with GitHub imports your public profile: avatar, display name, bio, location, website, and public repository metadata (names, descriptions, star counts, primary language, creation dates). We never fetch, read, or store the contents of any repository.
Anything you type directly — profile text, project descriptions, technology tags, Launch Week headlines, votes — is stored as you entered it.
Verifying a domain stores the DNS TXT record we asked you to publish and the result of checking it. Connecting App Store metadata stores the public listing data Apple's own lookup API returns for the URL you provided.
What we don't collect
- No advertising or tracking cookies. No third-party analytics pixels.
- No repository source code, ever, under any connected provider.
- No customer-level payment data — Stripe holds that; we hold only aggregate subscription state.
What is public
Nothing is public until you explicitly publish your Passport or a project. Importing and syncing never changes visibility on their own. A published Passport shows what you chose to include; anything left in draft, and any revenue figures, stay private by default.
How credentials are stored
Provider tokens (GitHub, and others as they are added) are encrypted at rest with AES-256-GCM and are never written to logs, error reports, or any response body. Moving a token out of the identity provider's own storage and into this encrypted vault happens automatically the moment you sign in.
Who we share data with
We do not sell data, and we do not share it with anyone except the providers you explicitly connect (GitHub, Stripe once billing is enabled) and infrastructure we operate the service on (hosting, database, email delivery). None of them may use your data for their own purposes.
Your data, your control
You can export a copy of everything tied to your account, or delete your account entirely, from your account settings. Deletion removes your identifying information immediately; it does not retroactively erase evidence that was already publicly verifiable (for example, a domain you verified and then made public) before deletion.
Contact
Questions about this policy can be sent to the address listed on the homepage.
