What we store, and what we don’t.
Effective 16 August 2026 · JCIT Systems LLC
What we hold about you
- Your email address, so you can sign in. It lives in our authentication provider and appears nowhere public.
- Your handle and bio, which are public because they are how you are credited.
- What you wrote — field notes, vouches, saved questions — attached to your account.
- Your credit ledger: every movement, with the reason for it.
- Your API keys, as a hash and a short visible prefix. The key itself is shown once, at the moment it is created, and is not stored — we cannot show it to you again, and we cannot hand it to anyone who asks for it either.
- What you asked the catalog, when you asked it signed in. Questions asked signed out are counted, not kept — see below.
- How you use the site, as product-analytics events — pages viewed, and actions like searches, outbound clicks, vouches, claims and purchases. This is processed by a third party, Amplitude, and when you are signed in it is tied to your account. What it is, and what it is deliberately not sent, is in Product analytics below.
What we deliberately do not hold
These are design decisions: the data isn’t collected, so it can’t be requested, leaked, or subpoenaed.
- No profile photos, ever. Your identity mark is drawn from your handle by a formula. Nothing is uploaded and nothing is stored.
- No raw IP addresses, in our own systems. Where we need to count distinct people — the free-question limit, our click counts — we store a keyed hash, not the address. Our analytics provider does receive your IP to derive an approximate location; see Product analytics.
- No email, keys, or your words in analytics.We never send your email address, your API keys, or the text of your questions, notes and vouches to Amplitude — only that an action of a given kind happened, and its shape (a query’s length, a product’s slug, a pack’s name).
- No link between a click count and an account. The outbound-click records that feed a product’s public totals carry no user column, so there is no query that could find them if you deleted your account. (The separate analytics event for the same click is tied to your account while signed in — that is what Product analytics discloses.)
Clicks and counting
When you follow a link from a listing to a product’s own site, we record that a click happened, which of our pages it came from, and a keyed hash of your address so one person is not counted as ten. Bots, prefetches and an owner clicking their own link are recorded but not counted.
Those raw rows are deleted after thirty days by a scheduled job, not by anyone remembering to run one. What survives is a daily per-product total — three numbers and a date, identifying nobody.
Product analytics
We use Amplitude, a third-party product-analytics service, to understand how the site is used — which pages are reached, and which actions people take: searches, outbound clicks, vouches, claims, submissions and purchases. This is how we learn what is worth building and what is broken, and it runs in your browser, so Amplitude receives your requests directly and, from them, your IP address, from which it derives an approximate location.
To do this it stores identifiers in your browser (cookies and local storage) that persist across visits, and while you are signed in, these events are tied to your account so a journey can be followed across sessions. This is the part the previous version of this page said we did not do; we do it now, and this section exists so that is stated plainly rather than discovered.
We never send your email, your API keys, or the text of what you write. A question, a note and a vouch reach Amplitude only as the fact that they happened and their shape (a length, a slug, a category), never their contents.
If your browser sends a Do Not Track or Global Privacy Control signal, we do not initialise analytics at all. You can also read Amplitude’s privacy policy for how they handle what they receive.
Asking without an account
The free-question allowance has to be counted against something, and the something is a keyed hash of your address plus the date, with no question text, no account, and nothing that survives the day it was counted. Those counters are deleted after three days, which is long enough to make the limit work across a timezone and short enough that there is nothing to hand over.
What we crawl
The catalog is built by fetching public product pages: the HTML, a screenshot, and what we extract from them. We fetch what a browser fetches, identify ourselves in the user agent, and never submit forms or sign in. If a page is behind a login we do not have, it is not in the catalog.
Screenshots and extracted text are stored so a listing can show its evidence and so a later crawl can be diffed against an earlier one. If your site is listed and you would rather it were not, the report path reaches a person.
Side-by-sides
We publish comparisons between products in the catalog. They are generated from what we crawled and they name companies who did not ask to be named — so every one is held for seventy-two hours before it is published, the owner of either product can opt out permanently, and a report takes a page out of circulation while a person looks at it.
We send two kinds of mail: a weekly digest of real change, and a one-time notice to a product’s public contact address telling them their product is listed. Accounts that already existed are subscribed to the digest by default; new accounts opt in. Either way, one click — in your account settings or in any email — turns it off for good, needs no account, and is permanent, and no later message can undo it.
Both are sent to United States recipients only. Elsewhere the rules differ, and we would rather not send under rules nobody has checked.
Who else sees it
Our hosting, database, payment and email providers process data on our behalf: Vercel and Fly.io (hosting), Supabase (database, sign-in and file storage), Stripe (payments), Resend (email), and Anthropic and Voyage AI (the models that read crawled pages and answer questions). All of them store this data in the United States. We do not sell personal information to anyone, and there is no advertising on this site to sell it to.
Card numbers never reach us. Checkout happens on Stripe’s own pages, and we are told the result rather than the card.
Deleting your account
You do it yourself, from your account settings. It takes effect immediately — there is no queue, no grace period, and no copy kept to restore from. That page counts what you are about to lose before you confirm it.
Your credits, API keys, vouches, ownership claims, saved questions and submitted jobs are deleted with the account. Unspent credits are not refunded, so spend them first if you want the value.
Threads and replies you wrote stay, with your name replaced by [deleted] — other people replied underneath, and their words are not ours to delete. Listings you own stay in the catalog and become unowned. Reports you filed stay open without your name on them.
Your handle is retired rather than released. The identity mark is derived from it, so giving it to somebody else would give them your identity — no one will ever be able to claim it again. Purchases are kept, without you attached to them, because a record of money that changed hands is an accounting obligation rather than ours to erase.
Your rights
If you are in California, you may ask what we hold about you, ask for it to be deleted, and ask us to correct it. We do not sell or share personal information as those terms are defined there, so there is nothing to opt out of. Deletion is self-service and immediate at your account settings; for access or correction, email us and we will action it within forty-five days.
These rights are written for California because that is where our obligations are settled. We do not currently offer the site to, or send email to, people outside the United States, because we haven’t reviewed the rules elsewhere.
Children
This is a tool for people who build and buy software. It is not for anyone under 13, and we do not knowingly collect anything from them.
Changes
If this changes materially we will say so here and date it. The practices above are enforced in code, so a change to them is a change to the software, not to a document.
Contact
JCIT Systems LLC
228 Park Ave S PMB 734263
New York, NY 10003-1502
United States