Privacy

Last updated: 2026-10-01. DeepFeather keeps a small data footprint.

What we collect

  • Votes — anonymous “I replaced this” / “I want to replace this” counts per app. Abuse controls persist only a salted IP digest, never the raw IP, and expired limiter rows are pruned.
  • Digest / waitlist — email address and signup source if you subscribe.
  • App tips — name, URL, email, and optional note when you use /submit.
  • Outbuild Weekly — maker submissions include a product name and URL, contact email, short description, proof URL, and the core workflow claimed. Submissions stay private while pending; an approved entry may publish the product-facing fields, never the contact email.
  • Outbuild ballots — one best-effort ballot per campaign. We store a salted network digest instead of a raw IP so a voter can change or withdraw a ballot and so concurrent or abusive votes can be rejected. A coarse country code supplied by Cloudflare and a short campaign referral code may be stored for integrity and attribution; neither is precise location. Public results contain only aggregate counts.
  • Outbuild ratings and reasons — after voting, a visitor may score workflow fit, switching ease, and proof quality and optionally leave a short reason. The scores are aggregated; comment text stays private until manual approval. Ratings and reasons use the same campaign-scoped salted digest as the ballot so they can be updated or withdrawn without storing a raw IP.
  • Outbuild sponsor inquiries — contact email plus an optional product name, product URL, and message. This is an inquiry only: it does not take payment, reserve a placement, or affect the challenger board.
  • First-party analytics — only if POSTHOG_KEY is configured: page views and explicit product events (successful prompt copy, agent launch click, votes, campaign views, shares, referrals, and submissions). Autocapture and session recording are off. No advertising pixels.
  • Google Analytics 4 — only if configured and you allow analytics: until you allow it, no Google script is loaded at all. After you allow, Google receives page visits and explicit site action events, including campaign attribution and the page URL. No form text, email address, or copied prompt body is intentionally sent. You can decline or change your choice using “analytics settings” in the footer; withdrawing also reloads the page so the Google script is unloaded. Google Analytics may use analytics cookies after you allow it; advertising consent remains off.
  • Cloudflare Web Analytics — Cloudflare may inject a performance beacon. It is designed without cookies, local storage, or cross-site tracking, and sends aggregate measurements through this site's own /cdn-cgi/rum endpoint.

What we do not do

  • No user accounts.
  • We do not sell personal data.
  • We do not store prompt bodies you copy from the page.
  • Outbuild Community Pick results never change an editorial verdict or evidence level, and sponsorship cannot buy an entry, vote, rank, or review outcome.
  • Sponsorship checkout (when enabled later) is handled by Stripe; card data never touches our servers.

Retention

Vote counters, Outbuild ballots, ratings/reasons, audit rows, and rate-limit rows live in Cloudflare D1. Waitlist rows stay until processed or deleted; app tips, Outbuild maker submissions, and sponsor inquiries stay until we process or delete them. Analytics retention follows the PostHog project settings when enabled; GA4 retention follows the site's Google Analytics property settings.

Contact

Questions: hello@deepfeather.com