Public trust

Privacy

This privacy page is a plain-English launch note and not legal advice. It should be reviewed before a broader commercial launch.

What this static site collects

Core browsing and local saving do not require an account. Newsletter signup, optional account sync, analytics, ads, and hosted payment links may involve third-party providers and are optional.

Usage analytics

Analytics are disabled until a visitor explicitly chooses “Allow analytics” or “Allow analytics + ads.” If allowed, RepoRadar uses Google Analytics to understand aggregate page visits and product interactions such as applying a catalog filter, saving an item, or opening a comparison. Catalog search text, email addresses, saved-search names, and local dashboard contents are not sent as analytics event data. The “Privacy choices” control in every footer reopens the choice at any time; choosing “Essential only” records withdrawal, sends a denied consent update to an already initialized Google tag, and reloads the page so no previously loaded optional analytics or advertising runtime remains in the document.

Saved items, saved searches, comparison choices, and dashboard preferences stay in this browser unless you explicitly merge them into an optional account. RepoRadar does not silently upload or sync that local profile.

Optional accounts, synchronization, and teams

If you request an account link, RepoRadar stores your normalized email address, a hash of the one-time link, and later a hash of the revocable session token in Cloudflare D1. Link tokens expire after 15 minutes; sessions expire after 30 days. Short-lived, keyed abuse-prevention counters expire with their one-hour-or-shorter quota windows. RepoRadar never stores the plaintext session or private-RSS token.

Only an explicit merge or replace action uploads the bounded local profile. Synchronized saved items, searches, alert settings, comparisons, team membership, and alert-delivery records can include event and batch identifiers, delivery status, claim/send/failure times, and provider message identifiers. They remain until account deletion or a disclosed operational cleanup. Unlisted comparison links can be opened by anyone who has the link and are marked noindex. Team members can see data placed in that team workspace.

Team invitation targets are stored as versioned keyed hashes rather than plaintext invitee addresses. Pending invitations expire after seven days. Expired pending invitations are then eligible for deletion, while accepted, declined, expired, and revoked response metadata is retained for 30 days before a bounded, idempotent cleanup removes it in pages of at most 100 records.

The account page provides a scoped portable export and deletion. Export covers matching account-database rows, sanitized incoming or outgoing primary-team transfer direction, team, and timestamps, and the currently indexed newsletter record; transfer-counterparty account identifiers are omitted. Newsletter delivery suppression comes from the strongly consistent account database and exposes only safe generation/timestamp metadata, while eventual newsletter-store state is labeled separately as legacy cleanup work. The export does not claim that a synchronous response found an unindexed legacy newsletter orphan. Account deletion is blocked while you are primary owner of a team, and it reports pending instead of claiming completion while bounded legacy newsletter cleanup remains. Once eligible, deletion cascades through sessions, profiles, alert settings, private-feed credentials, memberships, delivery records, and unlisted comparisons. Shared teams require an explicit ownership decision.

Outbound links

RepoRadar links to third-party source, download, repository, paper, model, demo, or documentation pages. Those sites have their own privacy and security practices.

Advertising and cookies

Advertising is disabled until a visitor explicitly chooses “Allow analytics + ads.” RepoRadar may then use third-party advertising partners such as Google AdSense. Third-party vendors, including Google, may use cookies to serve ads, and those ads may be personalized or non-personalized depending on user settings, region, and consent choices. Visitors can withdraw optional consent through “Privacy choices” in the footer; “Essential only” denies future Google analytics and advertising storage and stops future ad initialization.

Users can manage ad personalization through Google’s ad settings. RepoRadar does not sell user data to advertisers and does not use ad status to influence rankings, scores, risk labels, visibility, tiers, or verdicts.

Email newsletter

If readers subscribe, RepoRadar stores the normalized email address, signup source, a bounded User-Agent, request and confirmation timestamps, confirmation-send count, and confirmation state in Cloudflare KV; the selected mail provider also processes the address and message. Unconfirmed records and their lookup index expire after 31 days. Confirmed records remain until unsubscribe or account deletion.

A signed unsubscribe POST immediately stores a generation-bound suppression record in the strongly consistent account database under a dedicated keyed identifier; this database record, not eventually consistent KV, blocks delivery. Bounded cleanup then removes indexed and legacy raw subscriber records and maintains a compatibility tombstone in KV; account deletion reports cleanup as pending until that scan completes. The suppression record is retained without a fixed expiry to honor the opt-out and is removed only after a later explicit signed confirmation bound to a newer generation.

RepoRadar does not sell email addresses. Newsletter sponsorships or tips do not influence ranking, scoring, visibility, risk labels, or verdicts.

Account email alerts and weekly digests default off. If enabled, the mail provider processes the account email and RepoRadar stores event/batch membership, statuses, timestamps, and provider identifiers needed for exact retry and duplicate prevention. Every saved-alert email includes a signed opt-out URL and, where the mail provider supports them, one-click List-Unsubscribe headers. Opening the URL with GET is scanner-safe and changes nothing; only the signed POST disables saved-alert email while leaving saved data, private RSS, and newsletter preferences unchanged. Private RSS uses a revocable signed URL containing a pseudonymous internal user identifier and generation, and is marked noindex; anyone with the URL can read that private feed until it is rotated or revoked.

Payments and tips

RepoRadar links out to hosted PayPal and Buy Me a Coffee checkout pages only. RepoRadar does not directly collect card numbers, bank details, wallet signing credentials, or recovery phrases.

Payment providers process payments under their own terms and privacy policies. If a user sends a tip, the payment provider may share limited payment metadata with the account owner.

Tips do not influence rankings, scores, risk labels, visibility, verdicts, popularity, or editorial treatment.

Corrections and contact

If you report an error by email, the information you send will be used to investigate the correction request and maintain editorial quality.