# Privacy Policy

Draft privacy policy: which personal data the ClarkCant Marketplace stores, why, for how long, and how to export or delete it.

> **Draft — requires legal review before production launch.** This text describes how the service works today. It is not final legal terms, and placeholders marked TO BE CONFIRMED still need an owner's decision.

## Controller

[TO BE CONFIRMED: legal name and registered address of the operator]. Privacy questions: [TO BE CONFIRMED: privacy contact email].

## What we store and why

| Data | Why | Kept until |
| --- | --- | --- |
| Account: name, email, email-verified flag, profile image URL | To run your account | You delete the account |
| Password (as a salted hash), passkeys (public keys only) | To sign you in | You remove them or delete the account |
| Sessions: token, IP address, browser user agent | To keep you signed in and detect misuse | The session expires (7 days, extended while you use it) or you sign out |
| GitHub sign-in link (only when GitHub sign-in is enabled): GitHub account id and OAuth tokens | To sign you in with GitHub | You delete the account |
| API tokens (stored only as a SHA-256 hash), OAuth grants, linked ClarkCant devices | To let tools act for you with the scopes you chose | You revoke them or delete the account |
| Publisher memberships, invitations, domain and repository verification records | To run publisher organisations | You leave the publisher or delete the account |
| Package submissions and the audit log of changes you make | Accountability for changes to public content | [TO BE CONFIRMED: audit retention period] |
| Rate-limit counters keyed by IP address and endpoint | To protect sign-in and the APIs from abuse | Overwritten within minutes to hours |
| Request logs (request id, method, path, status, duration; no request bodies) | Operating and debugging the service | Cloudflare's log retention for the account [TO BE CONFIRMED] |

Package listings themselves are public information published by package authors on npm.

## What we do not do

- No advertising, no analytics and no tracking cookies. If analytics is ever added it will only run after you opt in through the [cookie settings](/cookies).
- We do not sell personal data.

## Your controls

- **Export:** download everything we hold about your account from [your account page](/account) or `GET /api/v1/me/export`.
- **Delete:** delete your account from the account page or `DELETE /api/v1/me`. Sessions, tokens, OAuth grants, device links and media you uploaded that nothing else uses are removed. The audit log keeps only ids and counts for the deletion itself.
- **Revoke:** revoke API tokens, OAuth grants and linked ClarkCant devices individually at any time.

See [Your GDPR rights](/gdpr) for the full list of rights and how to exercise them, and [Subprocessors](/subprocessors) for who processes data for us.

## Third-party content in your browser

Pages load fonts from Google Fonts (fonts.googleapis.com, fonts.gstatic.com), and package README images are loaded from the jsDelivr CDN. Your browser contacts those services directly, which exposes your IP address to them. [TO BE CONFIRMED: whether to self-host fonts before launch.]