GSH

Privacy

What this site collects, and what it does not

A short page, because the answer is short. Everything below describes what this site actually does — what it stores, what it sets in your browser, and what it never asks anyone else for.

Reading the catalogue

No cookie is set for a visitor who browses, and no file a catalogue page loads comes from another company — styles, icons and everything else are served from this domain. What the catalogue does do is count, and it counts on our own server rather than in your browser, so your network tab still shows requests to this domain and nowhere else. There is no consent banner here because there is nothing to consent to.

What we count

Three things, and nothing else: that an entry's page was served, that a reader followed a link out to a vendor, and that someone sent an entry in. Each count is one row in a database on the same server as this site, holding the name of the event, the entry it concerns and the time. There is no address, no browser string, no cookie and no identifier of any kind in it, so a count cannot be traced back to a person. The counter does note the country the request arrived from — and that is this server's own address, not yours, so the map it draws is of our machine and not of our readers. Because of all that, the numbers are counts of events and not of people: we cannot tell a returning reader from a new one, and we do not try to.

Signing in

Sign-in exists so that a submitted entry has an author — a claim nobody can be asked about is a claim nobody can check. It goes through GitHub, so no password ever reaches us: GitHub tells us your account id, your login, your display name, the public email address on your profile if there is one, and your avatar URL, and those are stored in our own database. With them comes a signed session cookie that keeps you signed in for two weeks; signing out deletes it. It is not readable by scripts, and nothing else on the site uses it.

Clicking through to a vendor

Following a link out is counted, and the count says two things: which entry was left and which kind of link it was — website, repository, documentation or pricing. It says nothing about you, because it is sent by our server and not by your browser. The page itself reads one setting, how many seconds to wait before opening the vendor in a new tab, and that is all. The only trace on your side is a flag in that tab's own storage saying you have already seen the page; it stays on your machine and is never sent to us. On the vendor's site, the vendor's rules apply.

What we do not do

We do not sell or share what we hold, we do not run advertising or profiling scripts, we do not embed third-party widgets, and we do not hand our numbers to anyone else: the counter is ours, on the same server as this site. No link on this site earns us a commission today; if one ever does, it is labelled where it appears, and it never changes what an entry says or how entries are ordered.

Server logs

The site runs on a server we rent in Germany. The web server in front of it writes no access log, so browsing the catalogue leaves us no per-visitor record — no list of who read which page. What the application does write is an error log when something fails: a message and a stack trace, so the fault can be found and fixed. If you send us an email, that email is kept; answering it is the only reason the address exists.

Asking about your data

Write to contact@getselfhosted.com and say what you want removed. Your account and the identity fields in it are deleted on request — a person reads that address and does it, which is also why there is no self-service delete button to click. If you sent in an entry, the record of who sent it is part of how it was reviewed, so tell us in the same email what you want done with that and we will deal with it too.

This page is code

This policy lives in the site's own repository and changes in the same commit as the behaviour it describes, so it cannot quietly fall behind what the site does. The counting described above is part of that repository, and this page changed in the same commit as the code that sends it.

How to reach us

Back to the catalogue