Legal · Updated July 26, 2026
Privacy Policy
Information we collect
We collect account details, submitted product information, moderation history, payment references, and limited usage events such as listing views, searches, and outbound clicks. Publicly reachable product pages may contain personal data supplied by the website owner. When you enable automated submission, we also store API-key metadata, a one-way hash of each secret key, and the request status needed to make write operations safely retryable. Raw API-key secrets are never stored.
How we use information
We use data to operate accounts, review submissions, publish listings, process featured purchases, prevent abuse, make automated submissions safely retryable, measure referral performance, improve discovery, and communicate about moderation.
AI-assisted processing
OpenAI processes bounded public website text and source URLs to prepare listing drafts, and processes submitted listing text, destination URLs, public website excerpts, and a pseudonymous safety identifier for text-and-link safety review. Listing images and screenshots are not sent to OpenAI for these workflows. Responses API storage is disabled where the integration supports that control; OpenAI may otherwise process and retain request data under its applicable service terms and abuse-monitoring controls.
Service providers
Supabase processes database, authentication, and storage data. Stripe processes payment information. OpenAI processes the limited website and submission data described above for draft preparation and safety review. Ahrefs processes aggregated, cookie-free website usage events. Hosting and network providers may process operational logs.
Analytics and retention
Our directory analytics and Ahrefs Web Analytics do not use cookies or local-storage identity. Raw IP addresses are discarded or salted and hashed before storage, referrers are reduced to hostnames, and coarse device and location data may be recorded. Terminal agent-operation records are retained for 30 days after their final status update. Revoked API-key metadata is retained for 30 days after revocation, and expired API-key metadata for 30 days after expiration. Completed and failed website-scan records, including prepared draft results, are retained for 30 days after their final update; active scans and the 24-hour result-cache window are not deleted. We otherwise retain data only as needed for platform operation, security, reporting, financial records, and legal obligations.
Your choices
You can revoke an automated-submission API key from account settings. You may request access, correction, or deletion of personal data by contacting us. Public listing information may remain in backups for a limited period after removal.