Privacy
Privacy policy.
Fossfits is a public catalog of open-source AI tools. We collect only what we need to operate the site, improve search and listings, and protect the service from abuse. We do not sell personal information, we do not run an advertising network, and we do not require accounts to browse the catalog.
Last updated: 13 September 2026.
Data
What we collect.
- Product analytics events such as search submits and outbound clicks. Events are posted to our own
/api/eventsendpoint with an event name, path, and string payload. They are stored in our Postgres database for product decisions. - Hosting analytics from Vercel Analytics and Speed Insights, which help us understand aggregate traffic and Core Web Vitals. Those beacons are provided by our hosting platform under their privacy terms.
- Listing requests submitted through Suggest a project, including repository URL, category, optional contact field, and note. We use that data to review catalog additions.
- Routine server and security logs (for example IP address, user agent, and request path) needed for rate limiting, abuse prevention, and operational debugging. Logs are retained only as long as useful for those purposes.
- Optional API key headers when calling the catalog API. Public catalog reads work without a key; keys are used for higher rate limits and are not a consumer identity product.
Use
How we use information.
We use the information above to operate fossfits.com, keep search and listings accurate, measure which flows help people reach an install path, enforce rate limits, investigate abuse, and improve agent and developer documentation. We do not use catalog browsing data to build advertising profiles. We do not sell or rent personal information to data brokers.
Cookies
Cookies and local storage.
Fossfits may store a theme preference locally so light or dark mode survives a reload. Hosting analytics may set first-party cookies or similar identifiers according to Vercel's documentation. We do not use third-party advertising cookies. Clearing site data in your browser removes local preferences; analytics identifiers follow the controls of your browser and the hosting provider.
Processors
Service providers.
We rely on infrastructure providers to host the site and database (currently Vercel for application hosting and Neon for Postgres). When a GitHub token is configured, Fossfits may refresh public repository metadata from GitHub. Proprietary tool logos may load from Logo.dev when that key is configured. Those providers process data under their own terms to deliver the requested service.
Rights
Contact and requests.
If you submitted a listing request and want it deleted, or you have a privacy question about Fossfits itself, contact us through the channels on Contact. Include enough detail for us to locate the record (for example the repository URL you submitted). We will respond within a reasonable time. This policy may change as the product changes; material updates will be reflected on this page with a new last-updated date.