Privacy

How built4agents handles information about visitors and members. Updated 25 September 2026.

Controller and contact

Loris Podevyn, based in Belgium, is responsible for the personal data described here. Email contact@built4agents.com for privacy questions or requests.

What we collect and why

To provide your account and the community features, we use your email address, authentication identity, chosen display name when supplied, session records, product drafts and submissions, comments, votes, reports and ownership claims. The legal basis is performance of the service you request. An email address is needed for a member account; a public name is needed before posting publicly or submitting an ownership claim. Optional contributions are your choice.

We use records of moderation decisions, limited activity and product click counts to keep the directory useful, operate fair launches, detect abuse and resolve disputes. We use keyed representations of network addresses for rate limits and security; these remain personal data. Email send reservations contain a hash and timestamp to control sending and retries, without retaining the raw address or message body in that reservation. These activities rely on our legitimate interests in operating and protecting the service, balanced against members’ rights. We use contact emails to answer the request you send us, and process data when required to meet a legal obligation.

For Google sign-in, Google and Supabase provide the identity and email information needed to create your account. Email and password sign-in uses Supabase Auth. If you optionally connect GitHub to an ownership claim, we check your GitHub account ID, login and access to the official repository. We keep a private snapshot for manual review, not the GitHub access token. The application stores session records and encrypted sign-in provider tokens, but not your password. Resend sends account, submission, ownership, moderation and deletion emails. There is no marketing mailing list, advertising tracker or automated decision making with legal or similarly significant effects in this service.

What other people can see

Your display name, published product information, community suggestion attribution and visible comments can appear publicly. Vote totals are public, but individual votes are not shown as a public voter list. Your email, drafts, reports, ownership evidence and product click statistics are not published. A current product owner can see private statistics for that product; authorized reviewers see information needed to review submissions, claims and reports. Do not place secrets or another person’s private information in public fields.

Cookies and measurement

A necessary session cookie keeps a signed-in member authenticated for up to 30 days, unless they sign out or access is revoked sooner. Google sign-in and optional GitHub claim verification use short-lived cookies to secure their return. We record website and documentation link activations as separate product click counts, including anonymous clicks. We also record aggregate counts of started submissions, filtered searches and searches without results. These counters do not store search text or draft content. Temporary event identifiers prevent duplicate counts, and keyed network-address representations limit abuse. These counts do not identify unique visitors or verified customers. Signed-in members’ weekly activity supports aggregate service statistics; the individual activity is kept only for the period below. We do not use advertising or cross-site analytics cookies.

Retention and deletion

Authentication confirmation links expire after 15 minutes. Click deduplication and rate-limit records are eligible for cleanup after 24 hours. Individual weekly activity is scheduled for deletion after 90 days; aggregate counts do not contain member identities. Ownership proof, including optional GitHub claim evidence, is scheduled to be cleared 30 days after a decision, moderation event details after 180 days, email reservation hashes after 32 days, and delivery details in completed notification records after 30 days. Temporary image uploads are scheduled for cleanup before 24 hours.

Account and contribution records are kept while needed to provide the service; reports and related decisions may remain while needed to review a dispute. Contact messages are kept while needed to answer and follow up on the request. Ordinarily withdrawn product content can be restored for up to 90 days before its scheduled purge. Confirmed account deletion ends access immediately and starts erasure of affected account data and products still owned by that account, planned within 30 days. Previously transferred products remain. Deleted comments lose their authorship and text, and deleted members’ votes are excluded. Minimal internal deletion and restriction markers remain to prevent erased material from being restored. Cleanup can require operator follow-up if a job fails; provider backups and logs follow their own retention rules, and a recovery must not republish deleted content.

Providers and international processing

Supabase provides authentication, database and file storage; this project’s primary region is Paris (eu-west-3). Vercel hosts the website and its server functions are set to Paris (cdg1); Vercel also uses a global network. Resend sends service emails through Ireland (eu-west-1), but states that it stores customer data, including message content and delivery logs, in the United States. Zoho EU receives and stores messages sent to our contact mailbox. Google is involved only if you choose Google sign-in. GitHub is involved only if you choose to connect it to a product claim.

These providers and their subcontractors may process information outside the European Economic Area. The configured European regions do not mean every log, backup, support access or email remains there. Their published data protection terms describe applicable transfer safeguards; contact us if you need more information about a transfer affecting your data. See Supabase, Vercel, Resend and Zoho.

Your choices and rights

You can change your display name and edit or delete your comments in the service. You can request account deletion in account settings. Depending on the circumstances, you may also request access, correction, erasure, restriction, objection or portability. Email contact@built4agents.com; we may need to verify your identity. You may complain to a data protection authority, including the Belgian Data Protection Authority.

Contact