Skip to content
Draft — not reviewed by a lawyer. This page describes what findsafeskills actually collects and does today, in plain language, so it exists and is honest in the meantime. It is not a finished legal document.

Privacy policy

What we collect

  • Anonymous visitor cookie. A random identifier (no personal information) stored in your browser, used to deduplicate page views and searches for analytics and to prevent trivially inflating a listing's view count.
  • Search activity. Your search query, any filters used, and how many results were returned — used in aggregate for the traffic stats shown on the home page, not tied to your identity.
  • Account info, if you sign in. You sign in with GitHub, Google, Microsoft, or Facebook; we store the profile information that provider shares (such as your name, email, and avatar). We don't collect or store a password. We also count sign-ins by provider over time, tied to your account, for aggregate statistics only.
  • What you post while signed in. Ratings, comments, suggestions, safety-rating disputes, and listing reports are stored with your account so we can enforce one vote per listing and follow up on disputes and reports. Reports are visible only to the reviewer, not shown on listings. Ratings and comments are shown on listings.
  • A GitHub permission, if you sign in with GitHub. We ask for the permission GitHub requires to star a repository on your behalf (public_repo) and store the resulting token encrypted. It is used only when you click Star. If you'd rather not grant it, sign in with another provider.
  • IP address, for rate limiting. To stop abuse we keep a short-lived record of how often each IP address calls our write and search endpoints. These records are cleaned up automatically after about two days. Our hosting provider also logs requests under its own policy.
  • Anonymous page-view counts. Daily totals per page, with no visitor identifier, used to understand overall traffic.
  • Listing claims. If you claim a listing, we store your account id and a random validation key that is not secret. The verification result is shown publicly on the listing as a badge, without the key.
  • Listing submissions. If you submit a listing, the information you provide (repo URL, description, author info, etc.) is published publicly as part of that listing.

What we don't do

  • We don't sell your data.
  • We don't use search queries to target ads to you individually.

Third parties

findsafeskills is hosted on Vercel, uses a Postgres database (Neon), your chosen sign-in provider for OAuth, and an embeddings API to power search, and reads public repository data from GitHub and other code hosts. These providers may process data as part of operating the service. If we show ads in the future, the ad network will be named here.

Questions about this policy are welcome via /suggest.