PRIVACY POLICY
REBILT is a directory of independently built software. This policy explains what REBILT collects when you use rebilt.xyz, why, and what you can do about it. Questions or requests: support@rebilt.xyz.
The short version
- You can browse REBILT without an account. There are no ads, no third-party analytics and no tracking cookies.
- We count how often each project page is viewed and its links are clicked, as daily totals that aren’t tied to you or your device.
- If you sign in, we store the basics from Google or GitHub so we can tie your votes, comments, saves and submissions to you.
- We never sell your data. You can delete your account and everything tied to it from your account page.
What we collect
When you sign in
You sign in with Google or GitHub. We receive and store your name, email address, whether the provider has verified that email, your profile picture link (if there is one), and your account ID with that provider. We don’t get or keep your password, and we discard the access tokens the provider sends during sign-in. You can connect both Google and GitHub to the same account; each is stored as a separate login linked to your account.
To keep you signed in we store a session: a random token (also kept in a cookie in your browser), when it was created and when it expires, your IP address and your browser’s user agent. Sessions expire after about a week without use, and when you sign out.
What you do on REBILT
- Upvotes: which projects you upvoted. Vote counts are public; who voted is not.
- Public name: the name you choose on your account page. It’s shown next to your comments and you can change it any time. Until you choose one, nothing about you is public. It’s separate from the name and email your sign-in provider shares, which stay private.
- Comments: your comment and when you posted it, shown publicly with your current public name.
- Saved projects: the projects you save with the heart button. Your saved list is private: only you see it, and we don’t show save counts. Unsaving removes the entry.
- Project submissions: everything you enter in the submission form, including the contact email the form requires and an optional Discord invite, plus our decision and any reason we give. Only you and REBILT moderators see these. You can delete a submission from your account page; that doesn’t remove a listing that’s already been published on the wall, which you can ask us to change at support@rebilt.xyz.
Aggregate project statistics
For each project we count, per day, how many times its page was viewed and how many times its website, download and donation links were clicked. These are plain totals: we don’t store your account ID, IP address, a cookie or any other identifier with them, so they can’t be linked back to you. They include repeat visits and automated traffic, so they’re not a count of people. Moderators can export the totals; builders may see them.
Security and abuse prevention
We use Cloudflare Turnstile to check that project submissions come from a person, not a bot. It runs in a frame from Cloudflare, which processes signals about your browser and device to do this. We keep short-lived counters to limit how fast someone can try to sign in (by IP address) and how fast an account can vote, save, comment or change its public name. To stop floods of statistics requests, the server briefly keeps IP addresses in memory; they aren’t written to our database.
Hosting logs
REBILT runs on Cloudflare. Like any web host, Cloudflare processes request data such as IP addresses and keeps short-term logs that we use to fix errors and stop abuse.
Cookies and storage in your browser
- Session cookie (
better-auth.session_token, or__Secure-better-auth.session_tokenover HTTPS): keeps you signed in. Set only when you sign in; lasts up to about a week. - Sign-in state cookie (
better-auth.state): protects the sign-in round trip to Google or GitHub. Lasts five minutes. - Column choice (
rebilt:grid-columns, local storage): remembers whether you picked 3 or 5 columns. - Pending save (
rebilt:pending-save, session storage): if you tap the heart before signing in, remembers which project to save once you’re back. Cleared when it’s used or when you close the tab.
None of these are used for advertising or to track you across other sites.
Who else handles your data
- Cloudflare hosts the site and its database and runs Turnstile.
- Google and GitHub handle sign-in, under their own privacy policies.
We don’t share your data with anyone else unless the law requires it.
How long we keep it
We keep your account and what you’ve posted, saved and submitted until you delete it or we remove it for breaking the Terms. Sessions and the sign-in state cookie expire on their own, and rate-limit counters are short-lived. Aggregate project statistics don’t contain personal data and are kept as running totals.
Your choices and rights
- Delete your account any time from your account page. This permanently removes your account, sessions, sign-in methods, public name, upvotes, comments, saved projects and submissions.
- Unsave projects and delete your submissions individually from the same page.
- You can ask us for a copy of your data, to correct it, or to delete specific content by emailing support@rebilt.xyz.
- Depending on where you live, you may have further rights, including complaining to your local data protection authority.
Age
You need to be at least 13 to create an account, or older if the law where you live requires it.
Changes
If we change this policy we’ll update the date at the top, and for significant changes we’ll let signed-in users know.
Who runs REBILT
REBILT is operated by Filip Stopyra, an individual based in the United States, who is responsible for the personal data described here (the “controller” under laws such as the GDPR). Contact: support@rebilt.xyz.