Privacy Policy

What Awesome Indie collects when you browse, sign in or submit a product — why we have it, who else sees it, and how to get it back or get rid of it.

Last updated
12 August 2026
Applies to
awesomeindie.com
Contents15 clauses
  1. 01Who we are
  2. 02What this policy covers
  3. 03What we collect
  4. 04Why we use it
  5. 05Automated checks
  6. 06What is public
  7. 07Who else processes it
  8. 08Where your data goes
  9. 09How long we keep it
  10. 10Your rights
  11. 11Cookies and analytics
  12. 12How we protect it
  13. 13Children
  14. 14Changes to this policy
  15. 15Contact

What we hold

Your sign-in details from Google, X or GitHub, the profile you write, what you do on the site, and anything you send us in the support chat.

What we never do

We do not sell your data, we run no advertising network, and we never see your password.

What you control

Edit or hide any part of your profile in Settings, or delete the whole account yourself in one step.

A summary, not a substitute — the numbered clauses below are what applies.

Who we are

Awesome Indie is a directory of trending micro startups and indie products at awesomeindie.com. It is an independent project, run from Portugal by its founder, Diogo Capela — not a company with a privacy department, which is why this document is written in sentences rather than in clauses borrowed from someone else's policy.

For data-protection purposes we are the controller of the personal data described here. Reach us at [email protected] for anything in this document, including a postal address if you need one in writing.

What this policy covers

This covers the website at awesomeindie.com, the API at api.awesomeindie.com that serves it, and the emails we send you. It does not cover the products listed in the directory: those are other people's websites, and once you click through you are on their terms and their privacy policy, not ours.

It also does not cover what you choose to publish. A bio, a product description or a comment is public the moment you save it — see clause 06.

What we collect

Sign-in and account

There is no password on Awesome Indie. You sign in with Google, X or GitHub, and we receive from that provider your name, email address, a profile picture URL and an account identifier, plus the access and refresh tokens that keep the connection working. We copy the picture to our own storage so your avatar is served from our domain, and we generate a username for you.

The profile you write

Anything you fill in on Settings → Profile: display name, username, bio, country, location, links to X, Instagram, Facebook, GitHub, LinkedIn, Threads, Pinterest and Bluesky, whether the account is a business account, and whether you appear on the makers map. Some accounts also carry approximate coordinates — a city-level point, never a precise location — used only for that map pin.

What you do here

Products you submit, upvotes, comments, who you follow and who follows you, the days you were active (which is what the streaks and the leaderboard are built from), and a count of how many times your profile and your products have been viewed.

Requests, sessions and devices

Each sign-in creates a session row holding a session token, the IP address the request came from and your browser's user-agent string, so signing out really ends the session and so we can spot a stolen one. Our web server and Cloudflare also keep short-lived request logs. Separately, a random identifier in a cookie (_dh) lets us count a product view once per device instead of once per refresh — it is generated in your browser, is tied to no account, and tells us nothing about who you are.

Submissions and reports

A submitted product carries everything on the form — title, tagline, description, website, categories, maker credits, video and social links — along with the device identifier above, which is how we notice fifty submissions arriving from one browser. Reporting a product does not need an account: a report stores the reason, your notes, the IP address it came from and, if you are not signed in and choose to give one, an email address so we can reply.

Payments

Buying a launch day or a sponsorship happens on Polar, which is the merchant of record: your card details go to them and never reach our server. What we keep is the record of the sale — which account and which product it was for, Polar's order and checkout identifiers, the amount, the currency, and whether it has been redeemed, launched or refunded. Your invoices and payment methods live in Settings → Billing, which is Polar's own portal.

Newsletter and email to us

Subscribing to the newsletter stores your email address and nothing else. If you write to us, we keep the correspondence for as long as it takes to sort out and a reasonable while after.

We also keep a log of every email the site sends you — the address it went to, the subject, the date and the message itself — so that "did that arrive, and what did it say" is answerable without guessing. The one-time links in a sign-in or email-change message are stripped out of the copy we keep.

The support chat

The chat bubble in the corner is Crisp. It loads on every page, and what you type into it is stored by Crisp on our behalf: your messages and any file you attach, plus the IP address and browser you wrote from and the page you were on. If you are signed in we also hand Crisp your email address, your username, your avatar and a link to your profile, so a conversation reaches us with a name on it instead of an anonymous visitor number.

Crisp keeps the IP address of anyone who actually starts a conversation indefinitely, and discards it about thirty minutes after the visit for anyone who opens the chatbox but never writes. Treat the chat like email rather than something private to your browser: it is not the place for a card number, a password to one of your own accounts, or anything else you would not put in writing to us.

Why we use it, and our legal basis

Under the GDPR every use of personal data needs a lawful basis. Ours are below. "Contract" means we cannot run the account you asked for without it; "legitimate interests" means we judged our reason to outweigh the intrusion, and you can object at any time under clause 10.

What we doData usedLegal basis
Sign you in and keep you signed inSign-in identifiers, tokens, session token, IP address, user agentContract
Show your public profile and your submissionsProfile fields, products, upvotes, comments, followsContract
Rank products and run the streaks leaderboardUpvotes, views, active days, publication datesContract
Email you about your own products and accountEmail address, notification preferencesContract
Take payment for a launch day or a sponsorshipAccount and product it is for, Polar order identifiers, amount paidContract
Keep the record of that sale for tax, refunds and chargebacksThe same purchase recordLegal obligation
Answer you in the support chatYour messages, email address, username, avatar, IP addressLegitimate interests
Send the newsletterEmail addressConsent
Screen and moderate submissions, comments and profilesSubmitted text, comment text, profile text, the linked page, device identifierLegitimate interests
Handle reports and enforce the rulesReport contents, reporter IP address, account statusLegitimate interests
Keep the site up and defend it from abuseIP addresses, request logs, session dataLegitimate interests
Understand how the site is usedAnalytics and session-replay data — see clause 11Consent
Meet a legal obligation or answer a lawful requestWhatever the obligation requiresLegal obligation

We do not build advertising profiles, we run no ad network, and we do not sell or rent personal data to anyone. Nothing here is used to make decisions about you outside Awesome Indie itself.

Automated checks and AI review

What you post here is checked by a large language model, hourly, and that check can act on its own — so this clause sets out exactly how far it goes. The text you wrote is sent through OpenRouter to a model: a product's details together with the copy and images of the page it links to, a comment, or the name, bio, location and social links on a profile. No email addresses, IP addresses, payment details or tokens are sent. A profile check also returns a guess at whether the account represents a business rather than a person.

This is the whole of what that check may do without a person:

  • A product waiting for review, which nobody but you can see, may be accepted — which books its launch day and emails you the date — or refused. It may only refuse on a short list of things a machine can be sure about: a website that does not load, a broken link in the website field, placeholder or gibberish copy, and impersonating somebody else's brand. A refusal is not emailed to you; the reason is written on the product in My Products, and fixing what it names and resubmitting puts you back in the queue.
  • A comment may be hidden — for adult or illegal content, spam, a phishing or malware link, harassment, or gibberish. Hiding is reversible and deletes nothing.
  • A product already on the site is re-checked whenever you edit it and can never be taken down automatically, and a profile is never acted on automatically at all. Nothing about your account — a ban, a spam mark, being hidden from the map or the leaderboards — is ever automatic.

Every other conclusion, however confident the model sounded, is handed to a person together with the reason it gave.

Where something was decided automatically you have the right to have a person decide it instead, to say why you think it is wrong, and to contest the outcome. Write to [email protected] and a human will look at it themselves and tell you what they concluded.

What is public, and where it travels

Awesome Indie is a public directory, so most of what you add is meant to be seen. Publicly visible, to anyone and to search engines:

  • Your profile: avatar, username, display name, bio, country, location, social links and join date
  • Your view count, your streak numbers and your position on the leaderboards
  • Products you submitted, products you upvoted, your comments, and who you follow and who follows you
  • An approximate pin on the makers map, if your account has coordinates and you have left the pin switched on

Your email address is never published, and neither are IP addresses, sessions, support chats, reports you file or anything we hold for moderation.

Off the site

When a product is featured we announce it automatically on our own social accounts — X, Bluesky and Mastodon — which normally means the product name, tagline, link, image and any maker handle credited on the submission. Listings also appear in our RSS feed, our sitemap and the newsletter. The Open Analytics page publishes site-wide totals only, never anything about an identifiable person.

Turning it down

Clear a field in Settings → Profile and it stops being shown; switch off the map pin there too. Delete a comment or a product and it goes. Deleting your account removes the lot — see clause 09. What has already been posted to a social network or crawled by a search engine is outside our control, though we will remove our own posts on request.

Who else processes it

We keep the list of companies with access to this data as short as we can. Each one acts on our instructions, for the purpose named, and no more.

ProcessorWhat it does for usWhere
OVHThe single server that runs the site, the API and the databaseFrance (EU)
CloudflareDNS, CDN, TLS, firewall, and R2 storage for avatars and product imagesGlobal
Google Analytics 4Aggregate audience and traffic measurementUnited States
Microsoft ClarityHeatmaps and session replay of how pages are usedUnited States
MapboxMap tiles on the makers map — loaded only when you open that pageUnited States
CrispRuns the support chatbox: your messages, and who you are when signed inNetherlands (EU)
ResendSends transactional email (email verification, launch reminder, product featured)United States / EU
PolarMerchant of record for paid launch days and sponsorships: checkout, invoices, taxUnited States
OpenRouterRoutes the spam-screening prompt described in clause 05 to a modelUnited States
TelegramInternal operational log, which can include account details of an eventUnited States
Better StackChecks the site is answering; no personal data involvedGlobal

Product screenshots are taken by our own server. There is no third-party screenshot or advertising service in the stack.

Beyond these, we disclose personal data only when the law requires it, when we need it to establish or defend a legal claim, or to protect someone's safety. If the project ever changes hands you will be told before your data moves.

Where your data goes

The database, the application and every backup live on one server in France, inside the EU. The processors marked "United States" in clause 07 mean some data leaves the EEA — analytics events, an email we send you, a sponsorship payment, a screening prompt.

The support chat is the one worth spelling out, because it is EU-hosted but not only EU-hosted. Crisp is a French company and holds the conversations themselves in the Netherlands, with its own add-on data in Germany. It also routes the chatbox through relay servers in the United States, the United Kingdom and Singapore to keep it responsive. Those relays store no messages — only connection logs: an IP address, a timestamp, a browser user-agent and the site you were on.

Those transfers rest on the European Commission's Standard Contractual Clauses in each provider's data processing agreement, and on the EU–US Data Privacy Framework where the provider is certified under it. Ask us at [email protected] and we will tell you which applies to which.

How long we keep it

DataKept for
Account, profile and everything attached to itUntil you delete the account, then gone
Products, comments and upvotesDeleted with the account that made them
SessionsUntil they expire or you sign out; deleted with the account
Active days and streaksDeleted with the account
Reports you filedKept for abuse triage; the link to your account is severed when the account goes
Newsletter subscriptionUntil you unsubscribe
Log of emails we sent youDeleted with the account
Record of a launch day or sponsorship you paid forKept after the account goes — see below — as tax law and chargebacks require
Email to and from usUp to 2 years after the conversation ends
Support chat conversationsHeld by Crisp until we delete them — indefinitely otherwise; ask and yours goes
Server and Cloudflare request logsDays, not months — they roll over
Operational log entries in TelegramPer our Telegram workspace retention
Google AnalyticsUp to 14 months
Microsoft ClarityUp to 13 months
Database backupsRolling; a deleted account disappears from backups as they cycle out

Your rights, and how to use them

If you are in the EU or the UK, the GDPR gives you the right to:

  • Get a copy of the personal data we hold about you, and know where it came from
  • Correct anything wrong or incomplete
  • Delete it, where we have no overriding reason to keep it
  • Restrict or object to a use of it that rests on our legitimate interests
  • Withdraw consent you gave — for the newsletter, or for analytics
  • Take it elsewhere in a portable, machine-readable form

Most of this is faster to do yourself: edit or clear any field in Settings → Profile, change what we email you in Settings → Notifications, and change your email address, connect or disconnect a sign-in provider, or delete the account outright in Settings → Account.

For anything else, email [email protected]. We answer within 30 days, free, and we will only ask you to prove who you are if the request does not come from the address on the account. If we get it wrong you can complain to your national data protection authority — in Portugal that is the CNPD — or go to court.

Cookies, storage and analytics

We set as few cookies as the site can work with. These are all of them.

CookieSet byWhat it is forExpires
_dhUsA random device identifier, so a product view counts once per device90 days
_uacUsRemembers that you dismissed the cookie notice90 days
better-auth.session_tokenUsKeeps you signed in. Related short-lived cookies appear during an OAuth sign-in and then goSession
_gaGoogle AnalyticsTells one visitor from another for aggregate traffic reportingUp to 2 years
_clckMicrosoft ClarityTies page views into a session for heatmaps and replaysUp to 1 year
crisp-client/*CrispKeeps your support chat and its history attached to your browser between pages and visits6 months, renewed each visit

Your light or dark theme choice is kept in your browser's local storage, not in a cookie, and never leaves your device. Crisp keeps a copy of its chat session in local storage as well as in the cookie above.

Session replay

Microsoft Clarity records how pages are used — pointer movement, scrolling, clicks — and plays it back to us as a heatmap or a replay. It is aimed at layouts and broken flows, not at people. Clarity masks text input by default, so what you type into a form should not appear in a recording, but treat any recorded page as something we could see.

The support chat

The Crisp chatbox loads on every page too, before you click it and before you dismiss the cookie notice. Its cookie is what lets a conversation survive you moving to another page or coming back a week later, and it is not used to follow you around the site or to build a profile of you. Clause 03 covers what goes into a chat and clause 09 how long it stays.

Switching it off

Both analytics scripts load with the page on arrival, including before you dismiss the cookie notice. If you would rather not be measured, block googletagmanager.com and clarity.ms in your browser or with any content blocker, use Google's official opt-out add-on, or set Clarity's own opt-out on Microsoft's privacy dashboard. Blocking either changes nothing about how the site works for you. Blocking client.crisp.chat the same way removes the chat bubble, which does cost you something — there is then no way to message us from the site, though [email protected] still reaches us. Clearing cookies in your browser deletes our two as well; the sign-in cookie going means you will need to sign in again.

How we protect it

Traffic is encrypted end to end and sits behind Cloudflare's firewall. The database is not exposed to the internet. There are no passwords to leak, because we never hold any. Administrative access is limited to accounts that need it, backups run regularly, and privileged actions are logged.

None of that is a guarantee. This is one server run by a small project, and no service can promise perfect security. If a breach ever puts your rights at risk we will tell you and the supervisory authority within the deadlines the GDPR sets. If you find a vulnerability, please report it to [email protected] before making it public — we will credit you if you would like.

Children

Awesome Indie is for people aged 16 and over, and we do not knowingly collect anything from anyone younger. If you are a parent or guardian and believe your child has an account here, write to [email protected] and we will delete it.

Changes to this policy

When our practices change, this page changes with them, and the "last updated" date at the top moves. If a change matters to you — a new processor, a new purpose, a new kind of data — we will say so on the site and, where the law requires consent, ask for it before the change applies to you. Older wording is in the public git history of the site.

Contact

Privacy questions, requests and complaints: [email protected]. Anything technical or account-related: [email protected].

Also worth reading: the Terms of Use, which cover what you may submit and what we may do with it.