Information we process
When you sign in with GitHub, we process basic account details returned by GitHub, such as your username, avatar, and account identifier. We store associated activity when you save, comment on, or reply to a plugin.
When you contact us, we store the selected message type, message, optional contact details, locale, and the page where the form was submitted.
When you visit a public page or public API, we record the request time, canonical route, HTTP method, API status and server processing time, country or region, referring hostname, truncated User-Agent, bot indicator, and Vercel request identifier. Source IP addresses are encrypted with AES-256-GCM, while separate HMAC values support exact lookup and daily visitor deduplication. We do not store request or response bodies, cookies, Authorization headers, search terms, or complete query strings.
How we use it
We use this information only to provide account and community features, respond to messages, measure public page and API usage, identify bot traffic, protect the service, and improve the marketplace. We do not sell personal information or publish contact details supplied in a message.
Service providers
The site uses GitHub for sign-in and public repository data, Supabase for application data, and Vercel for hosting. Each provider may process technical information required to deliver its service under its own policy.
Retention and deletion
Encrypted source IP addresses and other raw traffic events are deleted automatically after 30 days. Daily aggregates that contain only summarized counts are retained for 13 months. Account, community, and contact data is kept only while it supports the purposes above.
Use “Send feedback” in the footer or email chuzhaojun6@gmail.com to request access to or deletion of associated contact, community, or traffic data. Daily visitor hashes do not use a persistent visitor cookie and do not identify a confirmed natural person.