Privacy
Last updated 2026-08-30. This page is written from the code, not from intent — every claim below is checkable in the repository that builds this site. If something here does not match what the site does, that is a bug and we want to hear about it.
The short version
This is a static site with no accounts and no server we operate. It counts page views without identifying you and stores nothing of its own in your browser. It carries Google ads, which do use cookies.
Analytics
We use Cloudflare Web Analytics. It is cookie-less, does not fingerprint you, and does not follow you across sites. It records page views and coarse technical facts — referrer, country, browser and device class — which Cloudflare aggregates. We see counts, never individuals, and there is no way for us to single you out from them. See Cloudflare Web Analytics.
Cookies and browser storage
This site sets none of its own; Google sets cookies for the ads — see Advertising. It writes nothing to localStorage or sessionStorage. Your filter, sort and search state lives in the URL, which never leaves your browser unless you copy the link yourself.
What a page loads
Fonts and stylesheets are served from this domain — there are no third-party webfonts. There are no social widgets, no tag managers, and no scripts beyond the analytics counter named above, the ad script described below, and the small amount of filtering code in the page itself. The optional comments client is not present or requested until you scroll its panel near the viewport; a page you open without scrolling down to the comments contacts no third party for them.
Community comments
Plugin detail pages can offer comments through Giscus, an open-source widget backed by GitHub Discussions. If you choose to load comments, your browser contacts giscus.app and GitHub. Comments, reactions, GitHub usernames and timestamps are public in the repository’s GitHub Discussions; you need a GitHub account to post. Giscus and GitHub process that interaction under their own terms and privacy policies. The site does not store a comment copy, and it never loads the widget for visitors who do not scroll to it.
Images inside plugin pages
Each plugin page reproduces that project's README, which may contain images. A README is written by a third party, so an image in it would otherwise be a request your browser makes to a host we do not control — which is exactly how a tracking pixel gets into a page. We therefore restrict those images to GitHub's own hosting (raw.githubusercontent.com, user-images.githubusercontent.com, camo.githubusercontent.com, github.com) and drop the rest, keeping their alt text. Because this site is itself served by GitHub Pages, GitHub already receives the request for the page — so the images that remain introduce no party that was not already there.
Hosting
The site is served by GitHub Pages. Like any web server, GitHub receives your IP address in order to answer the request. See the GitHub Privacy Statement.
Links you choose to follow
Listings link to GitHub repositories, npm packages, and plugin authors' own sites. Following one is your decision, and from that point you are on someone else's site under their terms. We do not add tracking parameters to these links.
The catalog file
/plugins.json is published for anyone to read, including the dsh-market plugin and third-party tools. It describes plugins — names, descriptions, categories, install commands — and contains nothing about visitors to this site.
Contributing
Submissions arrive as pull requests on GitHub, under GitHub's terms and with the visibility any public repository has. Nothing is submitted through this website; the optional comments UI writes to GitHub Discussions, not to a form or server we operate.
Advertising
This site carries ads from Google AdSense, loaded from pagead2.googlesyndication.com. Google sets cookies to serve and measure them and receives your IP address with each ad request. You can change what Google does with your data at My Ad Center.
Contact
Corrections and questions: open an issue.