Last updated: 8 August 2026
Short version: OSSDrop doesn't sell your data, doesn't run ads, and doesn't track you across other websites. You can browse the entire site without an account. This page explains exactly what we store and why.
If you just browse: we record the page path and a two-letter country code so we can see which pages are useful. That's it — no cookie, no IP address stored, nothing that identifies you.
If you create an account: we store your username, email address, display name, and avatar. If you sign in with GitHub or Google, those come from the provider. Anything else on your profile — bio, location, company, links — is optional and only there if you add it.
What you post: tool submissions, votes, comments, forum posts, and your profile are public by design — that's the point of a community directory.
If you sign up with email and password, your password is hashed (PBKDF2) before it is stored. We never store it in readable form and we can never see it. If you sign in with GitHub or Google, we never receive a password at all.
One cookie keeps you signed in for 30 days. Our own analytics use no cookies. We also use Google Analytics, which sets its own cookies — see “Third parties” below.
We keep these to a minimum, and none of them get your data to sell:
We don't sell or rent your data. We don't run advertising networks or tracking pixels. We don't email you marketing you didn't ask for. We don't use dark patterns to keep you here.
You can edit or clear your profile details at any time in settings. If you want your account and its data deleted, email us and we'll do it — no retention games. Public contributions you've already made may remain, anonymised, so discussions stay readable.
OSSDrop isn't intended for anyone under 13.
If this policy changes in a way that matters, we'll update the date at the top and say so on the site. No quiet rewrites.
Questions about privacy, or want your data removed? Get in touch. OSSDrop is run by Matily, a nonprofit open-source studio.