Privacy

Last updated: 2026-08-26. DeepFeather keeps a small data footprint.

What we collect

  • Votes — anonymous “I replaced this” / “I want to replace this” counts per app. Abuse controls persist only a salted IP digest, never the raw IP, and expired limiter rows are pruned.
  • Digest / waitlist — email address and signup source if you subscribe.
  • App tips — name, URL, email, and optional note when you use /submit.
  • Outbuild Weekly — maker submissions include a product name and URL, contact email, short description, proof URL, and the core workflow claimed. Submissions stay private while pending; an approved entry may publish the product-facing fields, never the contact email.
  • Outbuild ballots — one best-effort ballot per campaign. We store a salted network digest instead of a raw IP so a voter can change or withdraw a ballot and so concurrent or abusive votes can be rejected. A coarse country code supplied by Cloudflare and a short campaign referral code may be stored for integrity and attribution; neither is precise location. Public results contain only aggregate counts.
  • Outbuild ratings and reasons — after voting, a visitor may score workflow fit, switching ease, and proof quality and optionally leave a short reason. The scores are aggregated; comment text stays private until manual approval. Ratings and reasons use the same campaign-scoped salted digest as the ballot so they can be updated or withdrawn without storing a raw IP.
  • Outbuild sponsor inquiries — contact email plus an optional product name, product URL, and message. This is an inquiry only: it does not take payment, reserve a placement, or affect the challenger board.
  • First-party analytics — only if POSTHOG_KEY is configured: page views and explicit product events (successful prompt copy, agent launch click, votes, campaign views, shares, referrals, and submissions). Autocapture and session recording are off. No advertising pixels.
  • Cloudflare Web Analytics — Cloudflare may inject a performance beacon. It is designed without cookies, local storage, or cross-site tracking, and sends aggregate measurements through this site's own /cdn-cgi/rum endpoint.

What we do not do

  • No user accounts.
  • We do not sell personal data.
  • We do not store prompt bodies you copy from the page.
  • Outbuild Community Pick results never change an editorial verdict or evidence level, and sponsorship cannot buy an entry, vote, rank, or review outcome.
  • Sponsorship checkout (when enabled later) is handled by Stripe; card data never touches our servers.

Retention

Vote counters, Outbuild ballots, ratings/reasons, audit rows, and rate-limit rows live in Cloudflare D1. Waitlist rows stay until processed or deleted; app tips, Outbuild maker submissions, and sponsor inquiries stay until we process or delete them. Analytics retention follows the PostHog project settings when enabled.

Contact

Questions: hello@deepfeather.com