What we collect
When you sign in with GitHub, we request your public profile,
verified email, and a list of GitHub organizations you belong to
(the read:org scope). The org list is used to let you
pair a GitHub org as a dartpub publisher org from Settings →
Organizations; we do not store the membership list itself, only the
orgs you explicitly pair. Stored fields in our users table:
handle, display name, avatar URL, GitHub login, and verified email.
How we use it
Identity is used to associate your bookmarks, upvotes, comments, plugins, and billing records with a stable account. Your handle and display name are public on your publisher profile and on any plugin you own. Your email is private and used only for sign-in + critical account notifications (billing, security).
What we share
Plugin telemetry (install counts, usage events) sent by your apps via the runtime SDK is processed by us and aggregated per plugin. We do not share raw events with plugin authors — only the counts and tier transitions they need to bill.
Payment information is collected and stored by Stripe under their own terms. We store only Stripe's customer/account IDs, never card numbers or full bank details.
Cookies
We use a single httpOnly session cookie set by Supabase Auth on sign-in. No third-party trackers, no analytics that follow you off the site.
Data retention
Closing your account anonymizes the profile immediately and deletes bookmarks/upvotes/watches. Plugins you own can be archived (kept readable, no new installs) or deleted (irreversible). Payouts and receipts are retained for 7 years to satisfy tax/audit requirements.
Your rights
EU/UK/CCPA jurisdictions: you can request a full export or deletion of your personal data by emailing [email protected]. We respond within 30 days.