Skip to content
SaaSquirrelBack to discovery

SAASQUIRREL / LEGAL

Privacy Policy

What the directory collects, what becomes public, and how your information is handled.

Last updated October 6, 2026

On this page

About this policyInformation we handleHow information is usedLegal bases for processingWhat becomes publicService providers and sharingProcessing locations and transfersCookies and browser storageOptional usage analyticsHow long information is keptYour privacy rightsSecurity and decision-makingChanges to this policy

About this policy

This policy covers personal information processed for the SaaSquirrel directory, accounts, submissions, and service communications.

Information we handle

  • Accounts: your email address, account identifier, optional display name, email-confirmation status, and authentication information handled by Supabase.
  • Projects: URLs, names, descriptions, categories, pricing labels, tags, logos, screenshots, maker names, social links, drafts, revisions, badge-verification results, and publication details you provide or approve.
  • Participation: your upvotes, submission-support progress, and associated project identifiers.
  • Service messages: notification content, recipient email addresses, delivery records, and bounced-email or complaint suppression records.
  • Security and support: request information used by our infrastructure, rate-limit counters derived from account identifiers, email addresses or IP addresses, moderation records, and information you send when asking for help.

How information is used

We use account information to authenticate you, confirm your email, recover access, and provide your workspace. Project information is used to save drafts, review submissions, verify badges, schedule launches, and publish listings. Votes support directory rankings and the submission flow.

We send account and project-related emails, such as confirmation, recovery, review feedback, and launch notifications. The current app does not include a marketing mailing-list signup.

Security records help prevent abuse and investigate problems. When you request website autofill or badge verification, we fetch the URLs you provide; please provide only websites you are authorized to represent.

Legal bases for processing

Where the GDPR applies, account and requested directory services rely on performance of a contract. Protecting accounts, preventing manipulation, maintaining the directory, handling support, and documenting moderation serve legitimate interests. Information may also be retained or disclosed to meet legal obligations.

Optional consent-based features require a separate choice; acknowledgement of this policy is not consent to unrelated marketing or tracking.

You can browse without submitting account or project information. An email address and authentication details are necessary for account features, and the required project fields are necessary to process a submission.

What becomes public

Approved project listings, maker names, logos, screenshots, descriptions, pricing labels, tags, and links can be viewed by anyone and indexed by search engines. Public vote totals are displayed; the directory does not display voter identities or other users’ vote history.

Your sign-in email, private drafts, and review feedback are not displayed as public listing fields. Avoid placing private or sensitive information in content you submit for publication. Removing a listing cannot immediately remove copies held by search engines or other websites.

Service providers and sharing

Supabase provides authentication, the database, and project-image storage. Resend delivers service emails. Providers receive the information needed for these functions.

Hosting services may process request metadata and operational logs. When you allow analytics, Google Analytics processes usage information to help us understand traffic and improve the directory. We do not enable Google advertising signals or advertising personalization.

We may also disclose information where required by law or necessary to investigate abuse and protect legal rights. Visiting a project’s own website is subject to that website’s privacy policy.

Processing locations and transfers

Our providers may process information outside your country.

Provider documentation is available in the Supabase data processing addendum and Resend data processing addendum.

Cookies and browser storage

The app uses browser storage for account access, the submission editor, and your analytics preference. Optional Google Analytics cookies are installed only after you choose “Allow analytics”.

Storage used by the current app
StoragePurposeDuration
Supabase authentication cookiesKeep you signed in and refresh your account session.Configured for up to 400 days; refreshed during use and cleared by sign-out. Session validity may be shorter.
Password-recovery cookieTemporarily authorize the password-reset flow.15 minutes, or cleared when the reset flow completes or you sign out.
Submission session storageKeep your edits in the current tab while you prepare a submission.The tab’s browser session, or until the editor clears it after submission. Browser session restoration may extend this.
Analytics preference (local storage)Remember whether you allowed or declined optional analytics.180 days. If browser storage is unavailable, the choice lasts for the current page.
Google Analytics cookies (_ga, _ga_*)Distinguish visits and sessions after you allow analytics.Up to 180 days, refreshed during use. Removed by the app when you decline analytics.

You can clear cookies and site storage in your browser. Blocking account cookies can prevent sign-in or password recovery; clearing submission storage can remove unsaved edits.

Use the “Cookie settings” button to allow analytics or withdraw your consent at any time. Declining keeps the directory and account features available.

Optional usage analytics

With your consent, we use Google Analytics to measure visits, referring sites and campaign attribution, general device and browser information, approximate location, engagement, directory searches and filters, public project interactions, and progress through authentication and project submission.

The app sends search length and result counts rather than search text. It removes private project identifiers and sensitive URL parameters, including email addresses, authentication tokens, and draft website URLs. It does not send passwords, account email addresses, private draft content, or raw error messages. Administrator and design-system pages are excluded. Advertising signals and personalization remain disabled.

The legal basis for optional analytics is your consent. Google’s tag loads only after you allow analytics. You can withdraw consent through “Cookie settings”; the app stops sending analytics events and removes its Google Analytics cookies. Declining does not affect your account or submissions. Consent choices and analytics-cookie durations are listed above.

Google may process data outside your country. More information about Google’s processing is available in How Google uses information from sites that use its services and the Google Ads Data Processing Terms. Withdrawing consent stops future collection; it does not erase data already received by Google. Google Analytics user and event retention is configured for 14 months; the user-retention period refreshes with new activity. These controls do not affect most aggregated reports.

How long information is kept

Account and project records are used while the account or listing is maintained. Moderation, delivery, suppression, backup, and support records have separate operational or legal purposes. A withdrawal from review does not automatically erase every stored record.

The app removes rate-limit records older than one day when the rate limiter next runs. Browser-storage durations are described above.

Your privacy rights

Depending on applicable law and the circumstances, you may request access to your personal information, correction, deletion, restriction, or a portable copy. You may object to processing based on legitimate interests and withdraw consent for any processing that relies on consent.

For access, correction, deletion, portability, an objection, or a privacy question, contact hello@saasquirrel.com. Include enough information to identify your account and the request. We may need to verify your identity before disclosing or changing personal data.

Under the GDPR, requests are generally answered within one month, with permitted extensions for complex or numerous requests. You can also complain to a competent data-protection authority, including the authority where you live or work. In Spain, the authority is the Agencia Española de Protección de Datos (AEPD).

You can edit your display name in your account and change your upvotes in the directory. Contact us for account deletion or other requests that cannot be completed in the current account interface.

Security and decision-making

The app uses authenticated access, restricted database permissions, private project-image storage, and rate limiting to protect account and submission data. No online service can promise absolute security.

Rankings use vote totals and the sort option you choose. Submissions are reviewed by administrators. We do not use automated decisions intended to produce legal or similarly significant effects on individuals.

Changes to this policy

We will update this notice when the service’s processing changes and show the revision date at the top. Material changes will be communicated where required. See the Terms & Conditions for the directory’s submission and community rules.

SaaSquirrel
TermsPrivacyCookiesLegal notice
Independently built. Openly shared.© 2026 SaaSquirrel