What our custom analytics records
Page visits, outbound-link clicks, clicks toward project submission, resource downloads, skill-command copies, product-listing impressions and product-link clicks, and sponsored-card impressions and clicks. An event contains a known page path, event category, a coarse referral category such as Google or ChatGPT, and an approved destination domain, resource name public product slug or public sponsorship campaign ID. Product pages publish aggregate estimated counts from up to the last 30 days.
Our custom dataset does not contain IP addresses, account identifiers, full referrer URLs, query strings, search text or form contents. Our custom analytics does not set cookies or generate visitor identifiers. These are event counts, not a count of unique people or completed submissions.
Google Analytics
We automatically use Google Analytics 4 to measure visits to public pages unless you turn it off below or your browser sends a supported privacy signal. It uses first-party analytics cookies to distinguish browsers and sessions. Our tag requests a 90-day cookie lifetime, disables Google signals and advertising personalization, and does not send account IDs, form contents, URL query strings or fragments. Google processes the browser and network information needed to receive these events. Aggregate Google visitor totals may appear publicly once reporting is configured.
Google Analytics is enabled by default without a consent popup. You can turn it off here at any time; opting out disables collection and removes accessible Google Analytics cookies. Your choice is stored locally in this browser, and previous opt-outs remain respected. Do Not Track and Global Privacy Control also disable Google Analytics. This choice is separate from our limited, cookieless Cloudflare event counts. Google privacy policy.
Google Analytics preferences
Checking your preference…
Optional accounts and community support
When you sign in with Google or GitHub, we request your profile and verified email. We store your provider account ID, display name, an HMAC hash of your email for duplicate-account checks, account status, and support votes in Cloudflare D1. We do not store your provider password, access token, raw email or profile photo. Signing in does not subscribe you to marketing.
A necessary HttpOnly session cookie lasts up to 30 days; a temporary sign-in cookie lasts 10 minutes. Session tokens are hashed in storage. Your individual votes are visible to you in your account; public pages show aggregate support counts. We retain a withdrawn vote’s original timestamp and a history of support actions to prevent repeated weekly voting and calculate votes active at each weekly cutoff. Final weekly rankings retain aggregate counts and product details, without identifying voters. Expired sessions and sign-in records are removed by scheduled maintenance, and daily action counters are removed after two days. Your IP is used for short-term rate limiting, not saved in the community tables. These records are separate from anonymous analytics.
Product discussions are public. Comments show your display name, text and posting date; a Maker badge identifies a verified GitHub account. Comments, reply relationships, reports and moderation records are stored in Cloudflare D1. Deleting your comment clears its text but keeps a placeholder and reply links. Moderator-hidden text is retained for review. Reports are private to moderators. Do not post personal or confidential information.
Contact support@sota.cc from your account’s verified email to request deletion. We will verify your request and remove your community account and votes, clear your comment text and anonymize retained reply and moderation records; backups follow Cloudflare retention. Billing records follow their separate retention requirements.
SOTA Weekly (optional)
Weekly email requires a separate request and explicit confirmation by email. Logging in, submitting a product or paying for Boost does not subscribe you. We store your email address, subscription and consent status, confirmation time, unsubscribe token and delivery references in Cloudflare D1. Resend delivers confirmation and weekly emails.
Opening a confirmation or unsubscribe link does not change your preferences by itself; press the button to confirm. Your email provider may also offer one-click unsubscribe. We stop future weekly sends when you unsubscribe, and suppress addresses reported as bounced or complained. A message already being sent may still arrive.
Unconfirmed requests are removed after 30 days. Queued email bodies are cleared after 30 days. We retain subscription status and delivery references to honor opt-outs and prevent duplicates. Contact support@sota.cc to request deletion. Resend and Cloudflare backups follow their own retention settings. Published editions contain product information, never subscriber lists.
Your browser preferences
Custom analytics is disabled when your browser sends Do Not Track or exposes Global Privacy Control. Theme and Card/List display preferences are stored locally in your browser. You can browse the collection with JavaScript disabled.
Optional AI-assisted submissions
When you choose Auto-fill with AI, we read the public product page you provide and send a limited extract to Cloudflare Workers AI. If you paste a description, we process that text instead. Do not include confidential information. AI drafts are suggestions for you to review, not editorial approval.
Generated drafts are cached for up to seven days. Public website analyses can be reused by other visitors submitting the same URL. Drafts generated from pasted text are scoped to a random token stored in your browser. We do not retain the original pasted description in the server cache. Your browser also saves up to five recent analysis results; expired local entries are removed on the next use. You can clear this data in your browser settings.
To limit abuse and cost, the analysis endpoint uses your IP address for short-term rate limiting and stores a daily hash for usage counters, deleted within two days. These operational counters are separate from our custom analytics. AI analysis does not submit a GitHub Issue or publish a product.
Your library and inbox
Saved products and followed products are private to your account and do not count as votes. We store your selections, when you followed a product, your optional on-site reply notification preference and your inbox read time in Cloudflare D1. You can remove saved products, unfollow or turn off reply notifications from your account. These actions do not subscribe you to email. Your inbox shows recent reviewed releases and visible replies; removed or moderated replies are excluded. Maker access uses a verified GitHub identity, not payments or matching display names.
Boost payments
Stripe handles payment details for Boost payments. SOTA stores the selected product and approved materials, week, accepted rules, consent time, amount, payment status, refund requests, ranking changes and payment references in Cloudflare D1 to fulfill promotions and reconcile payments. We do not store card numbers or raw payment notifications.
Your browser keeps a private payment reference for retries during the session. A necessary, random HttpOnly cookie authorizes payment retries and stopping your Boost, helps prevent duplicate pending payments for the same product in this browser, and expires after 30 days. If you switch browsers or clear this cookie, contact support through our contact form to recover access. It is not an analytics identifier. Keep that reference private; it provides access to the booking status. Before a first Boost payment, we send a verification code to the work email you enter and store that email, the product, your browser’s payment reference and the verification time. Codes are deleted within a day of expiring; verifications are deleted 90 days after they expire, and the verified email is kept with any order you place so we can handle support and disputes. A separate public campaign ID is used for anonymous sponsored-card statistics. Payment records are separate from our browsing analytics. Stripe privacy policy.
For campaign reports, we retrieve the email address provided at Stripe checkout and use Resend to send transactional email. Our private delivery queue temporarily stores the recipient and report content for retries; these are removed from the active queue during the next scheduled maintenance after 30 days. We keep a delivery reference and status to prevent duplicate reports. Cloudflare backups and Resend records have their own retention settings. We do not use this address for marketing. Resend privacy policy.
Infrastructure and external services
Cloudflare hosts this website and processes network information needed to deliver and protect it. Custom events are stored in Cloudflare Workers Analytics Engine; infrastructure logs and retention are governed separately by Cloudflare’s service configuration. Cloudflare privacy policy.
Following an external link brings you to another service. Project submissions and corrections open GitHub, where submitted issues are public. Avoid including private information in those issues.
Contact messages
The contact form sends your email address, selected topic and message to our support inbox through Resend. We use them to respond to your request, not for marketing. Messages are not published. Correspondence remains in our support mailbox and Resend records according to their retention settings; contact us to request deletion.
Our application database stores only hashed delivery references and temporary abuse counters, not message bodies or email addresses. Your IP is used for short-term rate limiting and a daily salted hash. Records older than two days are cleared during subsequent form requests.
Questions
Use our contact form for privacy or billing questions. This page was updated on September 30, 2026.