Last updated: October 3, 2026.
Data we collect
We may collect Google account profile details used for sign-in, newsletter email addresses, saved-library choices, vendor claim and update information, tool submissions, community reviews, explicitly saved AI utility results, enterprise matching requirements, commercial order status, aggregate product analytics, outbound tool clicks, and technical request data needed for security and reliability.
For attribution, the browser keeps the first on-site pathname for the current tab session. When a product page, comparison, alternative, vendor link, or commercial checkout is used, we may store the relevant on-site path, a sanitized referrer origin and path, a bounded user-agent value, and a hosting-provider supplied two-letter country code. Referrer credentials, query strings, fragments, raw IP addresses, and persistent visitor identifiers are not stored with these analytics events. A short-lived SHA-256 client-key hash may be stored separately to enforce abuse limits.
Community reviews
Review submissions store the signed-in account identifier, the public display name selected by the reviewer, rating, review text, use case, relationship disclosure, moderation state, and a SHA-256 content fingerprint used to detect duplicate submissions. The account email is available to moderators but is not displayed publicly. Only approved reviews, chosen display names, ratings, use cases, and disclosures are published. Vendor-affiliated reviews are disclosed but excluded from aggregate ratings.
AI developer utilities and saved history
When you use an AI reviewer, debugger, explainer, generator, or converter, the submitted code and instructions are sent to the configured AI provider, currently OpenAI, to produce the result. Provider requests set store: false. AIProgramming.app does not save utility inputs or outputs by default, and operational error logs record failure categories rather than submitted code.
If a signed-in user explicitly selects “Save to private history,” the generated result is stored with the account for up to 90 days. The source input is not stored separately, although generated output may repeat or transform submitted content. Saved results can be permanently deleted from the account history page. The provider still processes requests under its own terms and privacy practices, so do not submit secrets, regulated data, or code you are not authorized to share.
Accounts, email, and payments
Google processes the sign-in flow and supplies the basic profile and email authorized by the user. Resend processes transactional and subscription email delivery. Stripe-hosted Checkout and the Stripe Customer Portal process payment and billing details; AIProgramming.app stores order identifiers and fulfillment state, not complete card details.
Analytics and consent
Google Analytics loads with analytics storage denied by default and may send limited, cookieless measurement signals. Analytics storage and optional PostHog product analytics remain disabled until analytics consent is granted. Advertising-related Google consent signals also default to denied and can be changed from Privacy Settings. Sentry may receive technical error and request context needed to diagnose failures. These services operate under their respective terms and data-handling practices.
Enterprise matching
When you request a team-tool match, we store your email, team size, Git provider, selected needs, budget range, and optional notes. The form requires explicit consent before these details can be shared. An editor may share them only with selected vendors whose profiles have been manually approved. Lead records and their vendor-match records are automatically deleted after 180 days by the protected daily retention task; operational deletion may occur earlier, and backups may retain data for a limited period.
Vendor data
Approved vendor representatives can see only leads specifically matched to their claimed products. They may use lead details only to respond to the stated request. Vendor analytics contain aggregate referral counts and do not expose individual visitor records. Vendor claims require work-email verification and remain subject to manual review. Verification links expire after 24 hours. Expired verification credentials are cleared by the protected daily retention task while the claim record remains available for its review status.
How data is used
Data is used to operate and secure the service, provide explicitly requested history, moderate community reviews, review product information, improve comparisons, fulfill saved features and requested communications, measure referral activity, administer commercial products, and provide consent-based vendor introductions.
Retention and your choices
Saved AI utility results expire after 90 days and can be deleted earlier. Newsletter confirmation links expire after 48 hours, and unconfirmed signup records are removed by the protected daily retention task. Raw referrer and user-agent fields are cleared after 90 days while non-identifying aggregate event dimensions remain available for reporting. Confirmed newsletter data remains until unsubscribe or deletion; account, review, and editorial workflow records are retained while needed to provide the service, prevent abuse, or preserve review history. You may request access, correction, withdrawal of sharing consent, or deletion through service@AIProgramming.app. Withdrawing consent does not undo information already shared before the request was processed.