Privacy Policy
Last updated 22 August 2026
The short version. We collect your email, what you list, and what you buy — because the marketplace cannot work without them. We never see your card details. We do not sell your data, and we do not run advertising trackers. You can have your account deleted by emailing us.
What we collect, and why
| What | Why |
|---|---|
| Email address | Signing in, receipts, sale notifications, and telling you if your demo breaks |
| Display name and bio | Shown publicly on your seller profile. You choose what goes here |
| Listings you create | Published on the marketplace once you set them live |
| Purchase history | Repository access, the refund window, and the seller's payout |
| Reviews and requests you post | Shown publicly, attributed to your display name |
| Waitlist email | Telling you when we open up. Nothing else |
| Aggregate page analytics | Which pages get visited. No cookies, no cross-site tracking, no individual profiles |
What we never see
Your card details. Payment happens on Stripe's own pages and their systems, never ours. We receive a confirmation that a payment succeeded and an identifier for it. Nothing more.
If you sell here, Stripe also collects identity and bank details to pay you. That goes directly to Stripe under their privacy policy — we only ever see whether your account is verified and able to receive money.
Who else touches your data
- Supabase — hosts our database and handles sign-in.
- Stripe — payments, seller identity verification, and payouts.
- Cloudflare — hosts the site and serves it to you.
- Resend — sends the transactional emails listed above.
Each of these sees only what it needs to do its job. We do not sell your data to anyone, and we do not share it for advertising.
What is public
Some things are public by design, and it is worth being clear which:
- Your display name and bio
- Listings you have set live, and their changelogs
- Reviews you write, with your display name attached
- Requests you post on the request board
Your email address is never public. Neither is your purchase history, your drafts, or anything about your Stripe account.
Cookies
We use a small amount of browser storage to keep you signed in. That is a functional necessity, not tracking. We do not use advertising cookies and we do not follow you across other sites.
How long we keep things
- Account data — while your account exists.
- Purchase records — kept after account deletion, because tax and accounting rules require it. Stripped of anything not needed for that.
- Waitlist emails — until you ask us to remove them, or until we launch and they have served their purpose.
Your rights
Wherever you live, you can ask us to:
- Show you what we hold about you
- Correct anything wrong
- Delete your account and personal data, subject to the purchase-record exception above
- Send you a copy of your data in a portable format
Email support@forkable.dev and we will do it. If you are in the UK or EU, the GDPR gives you these rights explicitly; we extend them to everyone because having two standards is more work than having one.
Children
Forkable is not for people under 18. We do not knowingly collect data from anyone younger. If you believe a child has an account here, tell us and we will remove it.
Security
Access to data is enforced at the database level, not just in the interface — the rules about who can read what are applied by the database itself, so a bug in the website cannot expose data the rules forbid. Repository access is gated on an actual completed purchase. Sensitive columns are unreadable through the public API.
No system is perfect. If you find a security problem, please email support@forkable.dev before disclosing it publicly, and we will fix it quickly and credit you if you would like.
Changes
If we change this policy in a way that matters, registered users get an email before it takes effect.
Contact
support@forkable.dev — a real person reads it.