Privacy Policy
What Awesome Indie collects when you browse, sign in or submit a product — why we have it, who else sees it, and how to get it back or get rid of it.
- Last updated
- 12 August 2026
- Applies to
- awesomeindie.com
Contents15 clausesClose
What we hold
Your sign-in details from Google, X or GitHub, the profile you write, what you do on the site, and anything you send us in the support chat.
What we never do
We do not sell your data, we run no advertising network, and we never see your password.
What you control
Edit or hide any part of your profile in Settings, or delete the whole account yourself in one step.
A summary, not a substitute — the numbered clauses below are what applies.
Who we are#
Awesome Indie is a directory of trending micro startups and indie products at awesomeindie.com. It is an independent project, run from Portugal by its founder, Diogo Capela — not a company with a privacy department, which is why this document is written in sentences rather than in clauses borrowed from someone else's policy.
For data-protection purposes we are the controller of the personal data described here. Reach us at [email protected] for anything in this document, including a postal address if you need one in writing.
What this policy covers#
This covers the website at awesomeindie.com, the API at api.awesomeindie.com that serves it, and the emails we send you. It does not cover the products listed in the directory: those are other people's websites, and once you click through you are on their terms and their privacy policy, not ours.
It also does not cover what you choose to publish. A bio, a product description or a comment is public the moment you save it — see clause 06.
What we collect#
Sign-in and account
There is no password on Awesome Indie. You sign in with Google, X or GitHub, and we receive from that provider your name, email address, a profile picture URL and an account identifier, plus the access and refresh tokens that keep the connection working. We copy the picture to our own storage so your avatar is served from our domain, and we generate a username for you.
The profile you write
Anything you fill in on Settings → Profile: display name, username, bio, country, location, links to X, Instagram, Facebook, GitHub, LinkedIn, Threads, Pinterest and Bluesky, whether the account is a business account, and whether you appear on the makers map. Some accounts also carry approximate coordinates — a city-level point, never a precise location — used only for that map pin.
What you do here
Products you submit, upvotes, comments, who you follow and who follows you, the days you were active (which is what the streaks and the leaderboard are built from), and a count of how many times your profile and your products have been viewed.
Requests, sessions and devices
Each sign-in creates a session row holding a session token, the IP address the request came from and your browser's user-agent string, so signing out really ends the session and so we can spot a stolen one. Our web server and Cloudflare also keep short-lived request logs. Separately, a random identifier in a cookie (_dh) lets us count a product view once per device instead of once per refresh — it is generated in your browser, is tied to no account, and tells us nothing about who you are.
Submissions and reports
A submitted product carries everything on the form — title, tagline, description, website, categories, maker credits, video and social links — along with the device identifier above, which is how we notice fifty submissions arriving from one browser. Reporting a product does not need an account: a report stores the reason, your notes, the IP address it came from and, if you are not signed in and choose to give one, an email address so we can reply.
Payments
Buying a launch day or a sponsorship happens on Polar, which is the merchant of record: your card details go to them and never reach our server. What we keep is the record of the sale — which account and which product it was for, Polar's order and checkout identifiers, the amount, the currency, and whether it has been redeemed, launched or refunded. Your invoices and payment methods live in Settings → Billing, which is Polar's own portal.
Newsletter and email to us
Subscribing to the newsletter stores your email address and nothing else. If you write to us, we keep the correspondence for as long as it takes to sort out and a reasonable while after.
We also keep a log of every email the site sends you — the address it went to, the subject, the date and the message itself — so that "did that arrive, and what did it say" is answerable without guessing. The one-time links in a sign-in or email-change message are stripped out of the copy we keep.
The support chat
The chat bubble in the corner is Crisp. It loads on every page, and what you type into it is stored by Crisp on our behalf: your messages and any file you attach, plus the IP address and browser you wrote from and the page you were on. If you are signed in we also hand Crisp your email address, your username, your avatar and a link to your profile, so a conversation reaches us with a name on it instead of an anonymous visitor number.
Crisp keeps the IP address of anyone who actually starts a conversation indefinitely, and discards it about thirty minutes after the visit for anyone who opens the chatbox but never writes. Treat the chat like email rather than something private to your browser: it is not the place for a card number, a password to one of your own accounts, or anything else you would not put in writing to us.
Why we use it, and our legal basis#
Under the GDPR every use of personal data needs a lawful basis. Ours are below. "Contract" means we cannot run the account you asked for without it; "legitimate interests" means we judged our reason to outweigh the intrusion, and you can object at any time under clause 10.
| What we do | Data used | Legal basis |
|---|---|---|
| Sign you in and keep you signed in | Sign-in identifiers, tokens, session token, IP address, user agent | Contract |
| Show your public profile and your submissions | Profile fields, products, upvotes, comments, follows | Contract |
| Rank products and run the streaks leaderboard | Upvotes, views, active days, publication dates | Contract |
| Email you about your own products and account | Email address, notification preferences | Contract |
| Take payment for a launch day or a sponsorship | Account and product it is for, Polar order identifiers, amount paid | Contract |
| Keep the record of that sale for tax, refunds and chargebacks | The same purchase record | Legal obligation |
| Answer you in the support chat | Your messages, email address, username, avatar, IP address | Legitimate interests |
| Send the newsletter | Email address | Consent |
| Screen and moderate submissions, comments and profiles | Submitted text, comment text, profile text, the linked page, device identifier | Legitimate interests |
| Handle reports and enforce the rules | Report contents, reporter IP address, account status | Legitimate interests |
| Keep the site up and defend it from abuse | IP addresses, request logs, session data | Legitimate interests |
| Understand how the site is used | Analytics and session-replay data — see clause 11 | Consent |
| Meet a legal obligation or answer a lawful request | Whatever the obligation requires | Legal obligation |
We do not build advertising profiles, we run no ad network, and we do not sell or rent personal data to anyone. Nothing here is used to make decisions about you outside Awesome Indie itself.
Automated checks and AI review#
What you post here is checked by a large language model, hourly, and that check can act on its own — so this clause sets out exactly how far it goes. The text you wrote is sent through OpenRouter to a model: a product's details together with the copy and images of the page it links to, a comment, or the name, bio, location and social links on a profile. No email addresses, IP addresses, payment details or tokens are sent. A profile check also returns a guess at whether the account represents a business rather than a person.
This is the whole of what that check may do without a person:
- A product waiting for review, which nobody but you can see, may be accepted — which books its launch day and emails you the date — or refused. It may only refuse on a short list of things a machine can be sure about: a website that does not load, a broken link in the website field, placeholder or gibberish copy, and impersonating somebody else's brand. A refusal is not emailed to you; the reason is written on the product in My Products, and fixing what it names and resubmitting puts you back in the queue.
- A comment may be hidden — for adult or illegal content, spam, a phishing or malware link, harassment, or gibberish. Hiding is reversible and deletes nothing.
- A product already on the site is re-checked whenever you edit it and can never be taken down automatically, and a profile is never acted on automatically at all. Nothing about your account — a ban, a spam mark, being hidden from the map or the leaderboards — is ever automatic.
Every other conclusion, however confident the model sounded, is handed to a person together with the reason it gave.
Where something was decided automatically you have the right to have a person decide it instead, to say why you think it is wrong, and to contest the outcome. Write to [email protected] and a human will look at it themselves and tell you what they concluded.
What is public, and where it travels#
Awesome Indie is a public directory, so most of what you add is meant to be seen. Publicly visible, to anyone and to search engines:
- Your profile: avatar, username, display name, bio, country, location, social links and join date
- Your view count, your streak numbers and your position on the leaderboards
- Products you submitted, products you upvoted, your comments, and who you follow and who follows you
- An approximate pin on the makers map, if your account has coordinates and you have left the pin switched on
Your email address is never published, and neither are IP addresses, sessions, support chats, reports you file or anything we hold for moderation.
Off the site
When a product is featured we announce it automatically on our own social accounts — X, Bluesky and Mastodon — which normally means the product name, tagline, link, image and any maker handle credited on the submission. Listings also appear in our RSS feed, our sitemap and the newsletter. The Open Analytics page publishes site-wide totals only, never anything about an identifiable person.
Turning it down
Clear a field in Settings → Profile and it stops being shown; switch off the map pin there too. Delete a comment or a product and it goes. Deleting your account removes the lot — see clause 09. What has already been posted to a social network or crawled by a search engine is outside our control, though we will remove our own posts on request.
Who else processes it#
We keep the list of companies with access to this data as short as we can. Each one acts on our instructions, for the purpose named, and no more.
| Processor | What it does for us | Where |
|---|---|---|
| OVH | The single server that runs the site, the API and the database | France (EU) |
| Cloudflare | DNS, CDN, TLS, firewall, and R2 storage for avatars and product images | Global |
| Google Analytics 4 | Aggregate audience and traffic measurement | United States |
| Microsoft Clarity | Heatmaps and session replay of how pages are used | United States |
| Mapbox | Map tiles on the makers map — loaded only when you open that page | United States |
| Crisp | Runs the support chatbox: your messages, and who you are when signed in | Netherlands (EU) |
| Resend | Sends transactional email (email verification, launch reminder, product featured) | United States / EU |
| Polar | Merchant of record for paid launch days and sponsorships: checkout, invoices, tax | United States |
| OpenRouter | Routes the spam-screening prompt described in clause 05 to a model | United States |
| Telegram | Internal operational log, which can include account details of an event | United States |
| Better Stack | Checks the site is answering; no personal data involved | Global |
Product screenshots are taken by our own server. There is no third-party screenshot or advertising service in the stack.
Beyond these, we disclose personal data only when the law requires it, when we need it to establish or defend a legal claim, or to protect someone's safety. If the project ever changes hands you will be told before your data moves.
Where your data goes#
The database, the application and every backup live on one server in France, inside the EU. The processors marked "United States" in clause 07 mean some data leaves the EEA — analytics events, an email we send you, a sponsorship payment, a screening prompt.
The support chat is the one worth spelling out, because it is EU-hosted but not only EU-hosted. Crisp is a French company and holds the conversations themselves in the Netherlands, with its own add-on data in Germany. It also routes the chatbox through relay servers in the United States, the United Kingdom and Singapore to keep it responsive. Those relays store no messages — only connection logs: an IP address, a timestamp, a browser user-agent and the site you were on.
Those transfers rest on the European Commission's Standard Contractual Clauses in each provider's data processing agreement, and on the EU–US Data Privacy Framework where the provider is certified under it. Ask us at [email protected] and we will tell you which applies to which.
How long we keep it#
| Data | Kept for |
|---|---|
| Account, profile and everything attached to it | Until you delete the account, then gone |
| Products, comments and upvotes | Deleted with the account that made them |
| Sessions | Until they expire or you sign out; deleted with the account |
| Active days and streaks | Deleted with the account |
| Reports you filed | Kept for abuse triage; the link to your account is severed when the account goes |
| Newsletter subscription | Until you unsubscribe |
| Log of emails we sent you | Deleted with the account |
| Record of a launch day or sponsorship you paid for | Kept after the account goes — see below — as tax law and chargebacks require |
| Email to and from us | Up to 2 years after the conversation ends |
| Support chat conversations | Held by Crisp until we delete them — indefinitely otherwise; ask and yours goes |
| Server and Cloudflare request logs | Days, not months — they roll over |
| Operational log entries in Telegram | Per our Telegram workspace retention |
| Google Analytics | Up to 14 months |
| Microsoft Clarity | Up to 13 months |
| Database backups | Rolling; a deleted account disappears from backups as they cycle out |
Your rights, and how to use them#
If you are in the EU or the UK, the GDPR gives you the right to:
- Get a copy of the personal data we hold about you, and know where it came from
- Correct anything wrong or incomplete
- Delete it, where we have no overriding reason to keep it
- Restrict or object to a use of it that rests on our legitimate interests
- Withdraw consent you gave — for the newsletter, or for analytics
- Take it elsewhere in a portable, machine-readable form
Most of this is faster to do yourself: edit or clear any field in Settings → Profile, change what we email you in Settings → Notifications, and change your email address, connect or disconnect a sign-in provider, or delete the account outright in Settings → Account.
For anything else, email [email protected]. We answer within 30 days, free, and we will only ask you to prove who you are if the request does not come from the address on the account. If we get it wrong you can complain to your national data protection authority — in Portugal that is the CNPD — or go to court.
Cookies, storage and analytics#
We set as few cookies as the site can work with. These are all of them.
| Cookie | Set by | What it is for | Expires |
|---|---|---|---|
_dh | Us | A random device identifier, so a product view counts once per device | 90 days |
_uac | Us | Remembers that you dismissed the cookie notice | 90 days |
better-auth.session_token | Us | Keeps you signed in. Related short-lived cookies appear during an OAuth sign-in and then go | Session |
_ga | Google Analytics | Tells one visitor from another for aggregate traffic reporting | Up to 2 years |
_clck | Microsoft Clarity | Ties page views into a session for heatmaps and replays | Up to 1 year |
crisp-client/* | Crisp | Keeps your support chat and its history attached to your browser between pages and visits | 6 months, renewed each visit |
Your light or dark theme choice is kept in your browser's local storage, not in a cookie, and never leaves your device. Crisp keeps a copy of its chat session in local storage as well as in the cookie above.
Session replay
Microsoft Clarity records how pages are used — pointer movement, scrolling, clicks — and plays it back to us as a heatmap or a replay. It is aimed at layouts and broken flows, not at people. Clarity masks text input by default, so what you type into a form should not appear in a recording, but treat any recorded page as something we could see.
The support chat
The Crisp chatbox loads on every page too, before you click it and before you dismiss the cookie notice. Its cookie is what lets a conversation survive you moving to another page or coming back a week later, and it is not used to follow you around the site or to build a profile of you. Clause 03 covers what goes into a chat and clause 09 how long it stays.
Switching it off
Both analytics scripts load with the page on arrival, including before you dismiss the cookie notice. If you would rather not be measured, block googletagmanager.com and clarity.ms in your browser or with any content blocker, use Google's official opt-out add-on, or set Clarity's own opt-out on Microsoft's privacy dashboard. Blocking either changes nothing about how the site works for you. Blocking client.crisp.chat the same way removes the chat bubble, which does cost you something — there is then no way to message us from the site, though [email protected] still reaches us. Clearing cookies in your browser deletes our two as well; the sign-in cookie going means you will need to sign in again.
How we protect it#
Traffic is encrypted end to end and sits behind Cloudflare's firewall. The database is not exposed to the internet. There are no passwords to leak, because we never hold any. Administrative access is limited to accounts that need it, backups run regularly, and privileged actions are logged.
None of that is a guarantee. This is one server run by a small project, and no service can promise perfect security. If a breach ever puts your rights at risk we will tell you and the supervisory authority within the deadlines the GDPR sets. If you find a vulnerability, please report it to [email protected] before making it public — we will credit you if you would like.
Children#
Awesome Indie is for people aged 16 and over, and we do not knowingly collect anything from anyone younger. If you are a parent or guardian and believe your child has an account here, write to [email protected] and we will delete it.
Changes to this policy#
When our practices change, this page changes with them, and the "last updated" date at the top moves. If a change matters to you — a new processor, a new purpose, a new kind of data — we will say so on the site and, where the law requires consent, ask for it before the change applies to you. Older wording is in the public git history of the site.
Contact#
Privacy questions, requests and complaints: [email protected]. Anything technical or account-related: [email protected].
Also worth reading: the Terms of Use, which cover what you may submit and what we may do with it.