You can browse the directory without signing in. If you choose Google login, the site stores the minimum profile and session records needed to keep you signed in, while external source and download pages remain governed by their own privacy policies.
Local search
Search runs in the browser against a static index. It does not require a backend search service.
Google sign-in
Login uses Google Identity Services and an HttpOnly site session cookie.
External downloads
Download buttons leave this site and open original source or release pages.
What login stores
- Google subject ID, email, email verification status, display name, avatar URL, locale, and login timestamps.
- A random HttpOnly session token in the browser and only its hash in the D1 session table.
- No Google password, raw Google credential, or payment information.
What this MVP still does not collect
- No comments, favorites, memberships, payment data, or public submission profiles.
- No server-side search query history from the local search page.
- No self-hosted download logs for large AI resource files.
Operational data
Hosting providers, CDNs, browsers, and external destination sites may process standard technical data such as IP address, user agent, referrer, timestamps, and request paths. That operational data is controlled by the relevant infrastructure provider or external site.
If analytics are added later
Analytics must stay lightweight and aggregate-first. Any future analytics change should be documented before launch and should not turn the optional account system into behavioral profiling.