Privacy Policy
Effective . This version replaces any earlier one.
1. The short version
VSXRank needs an email address to sign you in and a record of what you asked us to track. That is very nearly all of it. We run no advertising or third-party analytics: there are no ad pixels, session recorders or cross-site tracking cookies. We count visits with our own cookieless site counter, described below.
Everything we store about you lives in one PostgreSQL database on a server we rent in the United States. You can ask for a copy of it, or ask us to delete it, at any time — see your rights and account deletion and data requests.
2. Who is responsible for your data
The data controller is Yash Agarwal, an individual based in India, who runs vsxrank.com. Write to [email protected] for any privacy question, to exercise any of the rights below, or to ask for a postal address. We answer privacy mail ourselves; there is no ticketing vendor in between.
3. What we collect, and why
Account
Your email address and the name you give when you create the account. If you sign in with Google, the name and profile image URL Google returns, plus Google’s account identifier for you and the OAuth tokens that identifier comes with. We store whether the address has been verified. You can add a webhook URL for alerts; if you do, we store that too. We need this to create the account and let you back into it.
Sign-in and sessions
One-time codes are stored hashed and expire in minutes. A session row holds the session token, the IP address and the browser user-agent string that created it, so that you can stay signed in and so we can recognise abuse of the sign-in endpoint. Sessions expire and expired rows are swept away.
What you ask us to track
The extensions on your watchlist, the keywords attached to them, the competitors you pin, your alert rules and the alerts we have sent, and the on-demand refreshes you request. A ledger records which extensions you opened with a research unlock, as a user id, a month and an extension key, so the monthly allowance can be counted.
Billing
Payments are taken by Dodo Payments, who are the merchant of record. We never see or store a full card number. We keep the subscription record — their customer and subscription identifiers, the plan, the interval, the status and the current period end — and the webhook messages they send us, which can include the card brand, the last four digits and the billing address you gave them. We keep those messages so a payment can be reconciled and so our tax records are complete.
Featured placements
If you buy a placement we store the extension, the blurb, the link, the scope and duration, the order status and the review decision. The card itself is public once it is live, and it is labelled as paid.
Transactional email — sign-in codes, alerts, billing notices — is sent from our own mailbox, [email protected], which Hostinger hosts; they process the recipient address and message for delivery. We send no marketing email to an address that did not ask for it.
Server logs
The web server keeps short-lived request logs with IP address, URL, status and user-agent, and the application logs errors. These exist for security and debugging, are not joined to your account for any other purpose, and rotate out.
Requests to our public API, MCP server and Markdown versions of pages (/api, /mcp, .md URLs, requests that ask for text/markdown, /openapi.json and /.well-known/mcp.json) are recorded in full: the IP address, the request with its headers and body, and the response we sent back. Cookie and Authorization headers are removed before anything is stored. We use these records to prevent abuse and to understand how the API is used. None of these surfaces reads an account, so the records are not linked to one. They are currently kept without a fixed expiry; when we set one, this page will say so.
Site traffic
We use first-party analytics to understand page visits and referral sources. It does not use analytics cookies or send data to an analytics provider.
Cookies and local storage
Two cookies, both set only after you sign in and both restricted to this site. The session cookie keeps you signed in; it is HTTP-only. A second, readable cookie (vsx_signed_in) holds no identifier or secret, only the fact that you are signed in, so cached public pages can show your account menu without a round trip; it expires with the session. Your light or dark theme preference is kept in your browser’s own storage and never sent to us. That is the entire list.
4. Public registry data is not about you
Separately from all of the above, we collect the public catalogues of the VS Code Marketplace and Open VSX: extension names, publisher names, install and download counts, versions, ratings, reviews and search positions. That data is published by the registries for anyone to read, it describes extensions rather than our users, and it is collected whether or not anyone has an account here. A published extension’s page exists on VSXRank because the registry lists it, not because its publisher is a customer. If you are a publisher and you believe a page about your extension contains personal data that should not be there, write to [email protected] and we will look at it.
5. Legal bases (GDPR art. 6)
- Performance of a contract. Your account, your watchlist, alerts, research unlocks and billing records. Without these there is no service to give you.
- Legitimate interests. Session metadata, rate limiting, server logs, API and MCP request records and fraud prevention, so that the service stays up, accounts stay secure and the public API is not abused. We keep this to what the purpose needs.
- Legal obligation. Invoices, payment records and the webhook messages behind them, which tax law requires us to be able to produce.
- Consent. Anything optional you switch on yourself, such as a webhook endpoint for alerts. You can withdraw it by removing the setting or by asking us to.
6. Where it lives, and who else touches it
Your data is stored in a PostgreSQL (TimescaleDB) database on a server rented from Hetzner in Ashburn, Virginia, in the United States, with an encrypted-in-transit nightly backup copied to a second server rented from Hostinger in India. It is not copied into a third-party analytics warehouse, and we do not sell or rent it to anyone, ever. These are the only processors involved:
- Hetzner Online GmbH — hosting and on-server backups, United States (Ashburn, Virginia).
- Hostinger International Ltd. — off-site backup storage (India), and hosting and delivery of our transactional email.
- Dodo Payments — merchant of record: checkout, card processing, invoicing, tax and refunds.
- Google — only if you choose to sign in with Google, and only for that sign-in.
We are based in India and the servers are in the United States and India, so if you are in the European Economic Area or the UK your data is processed outside it. Where a processor handles it there, the transfer relies on the standard contractual clauses or another safeguard permitted by Chapter V of the GDPR. We will also disclose data if a valid legal order requires it, and we will tell you unless we are forbidden to.
7. How long we keep it
- Account, watchlist, keywords, competitors, alert rules: while the account exists, then deleted with it.
- Sign-in codes: minutes. Sessions: until they expire, then swept.
- Billing records and webhook messages: kept while the account exists and afterwards for as long as tax and accounting law requires us to be able to produce them, which is longer than the account itself.
- Server logs: short-lived, rotated out.
- API, MCP and Markdown request records: kept for now, with no fixed expiry yet. Not linked to an account.
- Public registry data: kept indefinitely. It is the history the product is for, and it is not personal data about our users.
8. Your rights
If the GDPR or a comparable law applies to you, you have the right to:
- access the personal data we hold about you, and be told what we do with it (art. 15);
- correct anything inaccurate, including your email address (art. 16);
- have it erased — the right to be forgotten (art. 17);
- restrict our processing while a dispute about it is resolved (art. 18);
- receive a portable copy in a machine-readable format (art. 20);
- object to processing we base on legitimate interests (art. 21);
- withdraw consent at any time, where consent is the basis;
- complain to your national data protection authority. You do not have to come to us first, though we would rather you did.
Exercising any of these is free and we will not treat your account differently for it. We do no automated decision-making that has a legal effect on you, and we do not profile you for advertising.
9. Account deletion and data requests
Email [email protected] from the address on the account and say which you want: a copy of your data, a correction, or deletion. We reply from the same inbox. If the request does not come from the account address we will ask you to prove you control it, because handing an account’s data to the wrong person is the worse failure.
We action requests within 30 days, and usually within a few working days. If a request is genuinely complex we will tell you before that deadline and explain why, as art. 12(3) allows.
What deletion removes. The account row and, by cascade, every row tied to it: sessions, the linked Google account and its tokens, watchlist entries, keywords, competitors, alert rules and sent alerts, refresh requests and your research-unlock ledger. An active subscription is cancelled as part of the same request.
What survives, and why. Payment and invoice records — and the Dodo webhook messages behind them — are kept for the statutory accounting period; they are detached from the deleted account and retained only for that purpose. A Featured placement that has run keeps its order record, detached from your account, for the same reason. Public registry data about an extension is not deleted, because it is the registry’s public information about a piece of software rather than personal data about you. Short-lived server logs age out on their own.
Cancelling is not deleting. Cancelling a subscription in the billing portal stops the billing and keeps the account, so your watchlist and history are waiting if you come back. Ask us explicitly if you want the account itself gone. Deletion cannot be undone, and we do not keep a shadow copy to restore it from.
10. Security
The site is served over TLS only. Sign-in codes are stored hashed, session cookies are HTTP-only and site-scoped, and every per-user query is scoped to the signed-in account on the server rather than in the browser. Plan limits are enforced server-side. Database access is limited to the application and to the operator. No system is perfect; if a breach affects your personal data we will notify the supervisory authority and, where the law requires it, you, without undue delay.
11. Children
VSXRank is a tool for people who publish software and is not directed at children. Do not create an account if you are under 16. If we learn that an account belongs to a child under 16 we will delete it.
12. Changes to this policy
The effective date at the top of this page changes whenever this policy does. We will email account holders before a material change takes effect, and the Terms of Service and Refund Policy are versioned the same way.
13. Contact
Privacy questions, data requests and deletion: [email protected].