Privacy Policy

What we store about you, why we store it, who else processes it, and how to get it removed. This describes what the software actually does, not what a marketplace typically does.

Last updated 8 August 2026

1. What we collect

Because you signed up

  • Your email address, and the display name and avatar your sign-in provider gives us if you use GitHub or Google.
  • Anything you choose to add to your public profile: a biography, a GitHub handle, a website address.

Because you bought or sold something

  • Purchase records: what you bought, which licence, which version, what you paid, how much store credit or discount applied, and the licence key issued.
  • Payout records: what the platform owes or has paid you, and the transfer reference from our payment provider.
  • For sellers, the packages you upload, plus the structural fingerprints computed from them that let us detect plagiarism.

Because of security

  • If you turn on two-factor authentication, we store the authenticator factor through our authentication provider, and a one-way hash of each recovery code. We cannot recover the codes themselves, that is why they are shown only once.
  • A security log of second-factor and payout-destination changes, each with the IP address the change came from, so you can see activity you did not expect. You can read your own log at account security.
  • Short-lived request counters used for rate limiting. These are held in memory and are not a profile of you.

What we do not collect

  • We never see your card number, bank details or billing address. Those go directly to our payment provider. We store only that provider's identifiers for you.
  • No advertising or analytics trackers, and no third-party advertising cookies. The only cookies we set are the ones that keep you signed in.

2. Why we are allowed to hold it

  • To perform our contract with you, you cannot be sold a licence, or paid for one, without a record of it.
  • Our legitimate interest in keeping the marketplace safe: fraud prevention, plagiarism detection, rate limiting, and the security log.
  • Legal obligation, transaction records are kept for tax and accounting purposes.
  • Your consent, for anything optional you choose to publish on your profile.

3. Who else processes your data

These are the only third parties involved in running the service:

  • Supabase, database and authentication, including the emails that carry your sign-in links.
  • Stripe, payments, subscriptions, money held in escrow, and seller payouts. Stripe is the controller of the payment data you give it directly.
  • Cloudflare. R2 object storage for code packages, and Turnstile, which checks that uploads come from a person rather than a bot.
  • Vercel, application hosting. Request logs pass through it.

We do not sell your data, and we do not share it with anyone for their own marketing. Data is processed in the United States.

4. How long we keep it

  • Account and profile data: until you ask us to delete the account.
  • Purchase and payout records: retained after account closure where tax and accounting law requires it.
  • Rejected submissions: the listing and its uploaded package are hard-deleted 7 days after rejection.
  • Unreferenced uploads: a package that never became a listing is deleted 72 hours after it was uploaded.
  • Recovery code hashes: deleted as soon as two-factor authentication is turned off or a recovery code is redeemed.
  • Download records: when a download link is issued for something you bought, we record which account and which package, along with your IP address and browser identifier. We keep this for 2 years and then delete it. It is how we answer a payment dispute that claims an order was never delivered, and it is not used for anything else.

5. Your rights

You can ask us to give you a copy of your data, correct it, or delete it, and you can object to processing we do on the basis of legitimate interest. Write to our contact form.

Two limits worth stating plainly rather than burying. We cannot delete a purchase record while we are required to keep it for tax purposes. And deleting a seller account does not withdraw packages already delivered to buyers, because those buyers paid for continued access to them.

If you are in the UK or EEA you may complain to your data protection authority. If you are in California, we do not sell or share personal information as those terms are defined by the CCPA, and we will not discriminate against you for exercising any right above.

6. Cookies

We set cookies to keep you signed in and to complete the sign-in exchange securely. They are necessary for the service to function, so there is no consent banner asking you to accept tracking, there is no tracking to accept. Clearing them signs you out.

7. Security

Data is encrypted in transit. Access to your rows is enforced in the database itself, not only in the application. Actions that move money are performed by server-side code that checks who you are, and the most sensitive of them additionally require a code from your authenticator app. Recovery codes are stored only as hashes.

No system is perfect. If we discover a breach affecting your data we will tell you and the relevant authority within the time the law requires.

8. Children

The marketplace is not for anyone under 18. If we learn that we hold data about a child, we delete it.

9. Changes and contact

The date at the top of this page reflects the current version. For anything about your data, write to our contact form.