Catalog privacy
The catalog is readable without an account. Its app titles, descriptions, statuses, links, thumbnails, and heart totals are public.
When you add a heart
Your browser creates a random token and keeps it in first-party local storage. The service also receives your visitor IP address through its trusted Cloudflare connection. It immediately turns the token and a bounded network prefix into separate, generation-scoped HMACs. Raw tokens and IP addresses are not stored.
Those hashes are pseudonymous, not anonymous. They are stored in Postgres, included in normal database backups, and retained while that app generation remains listed. Deleting the catalog entry cascade-deletes its vote rows.
Privacy signals and limits
If your browser sends Global Privacy Control or Do Not Track, voting returns without creating stable hashes. Clearing this site's data removes the local browser token.
Hearts are best-effort signals, not verified unique people. One vote is allowed per browser or network, so shared networks may share one vote. Changing both the browser token and network can allow another vote.