Privacy

Short version: no ad tech, no cross-site tracking, no selling data. We collect the minimum needed to run an account-based community site.

Analytics

We use PostHog for page analytics, configured to collect as little as it can: memory-only persistence, so no analytics cookie and nothing in local storage; no autocapture of your clicks; no session recordings; no advertising identifiers. We also capture unhandled errors so we can fix them.

Because nothing is stored on your device and no persistent identifier follows you between visits, this runs on legitimate interest rather than consent — which is why you are not being asked to dismiss a cookie banner.

PostHog is a US company and our project currently runs in their US region, so these anonymous page events are processed in the United States under the EU–US Data Privacy Framework. We are moving this project to PostHog's EU region (Frankfurt); this page will say so once it is done.

Accounts

Signing in (GitHub OAuth or email magic link) stores your email, username, and avatar. Your profile, prompts, votes, and reports are linked to that account. The community forum shares the same identity via single sign-on.

Where your data lives

Everything account-related — the database, authentication, and the community forum — runs on a server we operate ourselves in Canada. We run the Supabase and Discourse software, but neither company receives your data. Canada holds an EU adequacy decision, so this is not a transfer that needs extra safeguards.

Cookies

The only cookies are the authentication session (when you sign in) and your theme preference. Neither tracks you across sites, and analytics sets none.

Third parties

Your data

To export or delete your data, email [email protected] from your sign-in address. Deletion removes your profile and anonymizes contributions where their license permits.