Privacy
What the site stores
The site runs on Vercel. Its database and sign-in run on Supabase.
- Your account: your email address and a hash of your password, kept by the sign-in service. If you sign in with Google or GitHub, it keeps the name, picture address, and account ID that service sends instead of a password; the name may fill in your profile, which stays private until you publish it. Only you and the admins can see your email address.
- Your profile, if you make one: a name, a handle, a short bio, a picture, and links. It stays private until you publish it. Once published, anyone can see it. The picture is kept at a web address that anyone who has it can open, so a private profile keeps no picture: making a profile private deletes it.
- Your requests and their replies. Only you and the admins can read them, and you cannot edit or delete them. A request goes on the public board only if you agreed and an admin listed it, and you can take it off from My requests.
- Community posts, replies, and bounties, which are public under your profile name, as is your name on a bounty you claim. Votes, one per account per item. Reports: who reported what, why, and what an admin did about it. A hidden post, reply, or bounty is kept with the reason, which its author can see.
- The apps your account can use. For an app you connect, the name it gives your computer and when it connected. Connecting with a typed code keeps a keyed hash of your network address to limit guessing, never the address itself.
- To limit repeated tries, for up to an hour: a keyed hash of your network address with your email address each time you sign in or create an account, with your authenticator each time you enter a two-step code, and alone for each page count. Never the address or the email address itself.
- If you work with pid1 as a developer: that role, the apps you work on, and your share terms, earnings, and payouts. If an admin credits you on an app, your name and one line about what you did appear on its page while your profile is public. A repository you add to Repos shows your name and picture there while your profile is public.
- A record of each change an admin makes, such as giving your account an app.
Page counts
The site counts views of its main pages and app pages, and which apps are shown, opened, or followed out to. Nothing is sent to an advertising or analytics company.
A count records the page, which app or link was shown, opened, or followed, the name of the site that sent you, any campaign tags in the link, whether you are on a phone, a tablet, or a computer, and a country worked out by the host. The host sees your network address to deliver each page; the site does not store it (only the hour-long keyed hash above), and nothing fingerprints your browser.
When you are signed in, a count is tied to your account. When you are not, it carries a random number from a cookie, stored only as a one-way hash. Signing in does not tie earlier counts to your account. Counts are kept until an admin deletes them.
What stays on your computer
What you do in the desktop apps stays on your computer. For Lead Finder that means leads, companies, research, and outreach drafts. The site does not receive them.
What your browser keeps
- Sign-in cookies, which only the site's server can read, while you are signed in, and while a sign-in with Google or GitHub or a password reset is under way. Signing out clears them.
- A cookie for fifteen minutes while you reset a password.
- Two cookies for page counts, each a random number: one for the visit, kept until thirty minutes after your last counted page, and one for the browser, kept until thirty days after.
- The colour you picked on the colour line (pid1-hue) and the palette made from it (pid1-palette), once you pick one.
- A note that the opening has played, so it plays only on your first visit.
- A note that the film on the start page has played by itself (pid1-film), so it does that only on your first visit.
None of them are used for advertising.
Removal
To see what the site holds about you, or to have it removed, send a request with the topic Something else from the account it is about.
A removal deletes at once your requests with everything written under them, your profile and its picture, your credits, and your votes. Your posts, replies, bounties, and the repositories you added stay, without a name, and a bounty you claimed but had not finished opens again. Your reports stay, without your name.
Your account, the apps it can use, and the page counts tied to it stay until the account itself is deleted, which you can ask for in the same request.
An account deleted without such a request loses its profile, its picture, and its page counts. Its requests are closed, taken off the board, and held for 30 days, then removed with their replies. Its posts and replies stay, without a name.