Your information
Last updated
UsefulShelf is operated by Kartik Labhshetwar, based in India, who is responsible for the personal information described in this policy. This policy explains how UsefulShelf (“we”, “us”) handles information when you browse our directory, sign in, submit apps, use our tools, connect an MCP client, or buy a placement.
For privacy questions, access requests, corrections, or deletion requests, contact hello@usefulshelf.co. Our Terms of Service explain the rules for using UsefulShelf.
1. Information we collect
- Account information: Google account identifier, name, email address, email verification status, and profile image when you sign in. Authentication records can include provider tokens, sessions, IP addresses, browser information, and dates of access. We do not receive your Google password.
- App submissions: website URL, product name, description, category, tags, image URLs, selected plan, and any optional referral answer. We store the submitting account, review results, badge checks, publication state, and related dates.
- Website checks and drafts: URLs you ask us to inspect and content fetched from those public websites. Visibility checks store the URL and resulting report at a shareable link.
- Payments and bookings: listing or booking identifiers, payment provider references, amounts, currencies, statuses, and placement dates. Dodo Payments collects payment and billing details at checkout; UsefulShelf does not store full card numbers or security codes.
- Usage and technical information: page visits, referral sources, browser and device information, network information, and interactions collected by our infrastructure and analytics providers. Our own outbound-click records store a listing identifier and timestamp, without an account identifier or IP address in that click record. Website links to listed apps and ads add
utm_parameters, plusref=usefulshelfwhen the link has noref, so the destination site can see the visit came from UsefulShelf. - Communications and connections: messages and feedback you send, plus MCP client registrations, permissions, authorization tokens, and consent records needed to support connected applications.
2. How we use information
We use information to authenticate you, save and review submissions, verify badges, publish eligible listings, run requested tools, process purchases, display placements, send service messages, respond to requests, understand usage, and protect the service against abuse.
Where data protection law requires a legal basis, account, listing, and purchase processing is used to provide the service you request; security, support, and service improvement serve our legitimate interests, subject to your rights; records may also be needed to meet legal obligations. Where consent is required for a particular use, that use requires consent. Agreement to our Terms of Service is not consent to optional tracking.
3. What becomes public
Live listings expose their product details, website and image URLs, category, tags, and placement information to visitors, search engines, and AI tools, including through sitemaps and public MCP search. Your account email, payment records, and internal review notes are not part of the public listing. A listing’s public text may contain personal information if you include it yourself. While you have a live listing, your account name and profile photo may appear in the maker group on the homepage.
Pending or rejected submissions, unpaid dofollow submissions, and free dofollow submissions awaiting required badge verification are not published in the directory or its feeds. They can still be processed by our service providers to deliver review, payment, and account services.
Visibility reports are accessible to anyone with their report link. Only check public URLs; do not include private documents, credentials, or secret query parameters. Public listings and reports may be copied or cached by third parties. We cannot erase copies held independently by others.
Our Open stats page shares aggregate visitor and listing counts. Visitor totals come from Cloudflare’s network analytics, which use IP addresses to distinguish visitors and can include automated traffic. We publish only aggregate counts, not IP addresses. Listing owners can see counts of clicks to their own apps.
4. Providers and sharing
We use the following services for specific parts of UsefulShelf:
- Cloudflare: website hosting, database storage, request handling, security, and aggregate traffic analytics. Turnstile, where enabled, processes browser and network signals to help prevent bots. Optional AI autofill sends fetched public webpage content to Cloudflare Workers AI.
- Google: account sign-in and Google Analytics for website usage measurement.
- Umami Cloud: website traffic and usage analytics.
- Dodo Payments: checkout and payment handling. We send your email and listing, account, or booking identifiers needed to associate the purchase with your submission.
- Resend: service emails, including submission and review updates, using your email address and relevant listing details.
- classifier.dev: automated submission review using the submitted product details, website URL, and fetched public website text.
- UserJot: the feedback widget. When you are signed in, we send your account ID, email, name, and profile image to identify you in the widget, even before you submit feedback.
When you authorize an MCP client, it can receive the profile, email, and listing information allowed by the permissions you grant and perform authorized listing actions. That client’s provider handles the information under its own policies. Signing out of the website does not necessarily end an existing connection; contact us for help revoking access.
External app images and badges may be loaded from their publishers’ servers, which receive your browser’s request. Following a website link or opening an external AI service also subjects that visit to the destination’s privacy practices.
We may disclose information when required by law or when necessary to investigate abuse, protect rights, or resolve a dispute. Relevant provider notices include Cloudflare, Google, Umami, Dodo Payments, and UserJot.
5. Cookies, browser storage, and analytics
Sign-in uses cookies to keep your session working. We store your explicit theme preference in local storage and use session storage to recover unfinished submission forms in your browser tab. Clearing site data removes these browser-stored preferences and drafts and may sign you out.
Google Analytics uses cookies or similar identifiers for measurement. Umami describes its analytics as cookieless. These services can process visited URLs, referrers, device and browser details, and network information to produce usage reports.
Analytics scripts currently load when you visit the site; UsefulShelf does not currently provide an in-site analytics consent or opt-out control. You can block scripts and manage or delete cookies through your browser settings. Blocking cookies alone may not stop cookieless measurement, and blocking necessary storage may affect sign-in and draft recovery.
6. Retention and security
Account and listing records are kept to maintain your account, submissions, and publication history. Report records support shareable check results. Payment, support, and security records may need to remain for accounting, legal obligations, abuse prevention, or resolving disputes. The appropriate period depends on the record’s purpose, whether the service is still needed, and applicable obligations; there is no single deletion period for all records.
You can request deletion by email. We may need to verify that you control the account before providing information or acting on a request, and explain any records that must be retained. Removing public content cannot guarantee removal from external caches or search results.
We use access controls and authenticated connections to help protect information, but no online service can guarantee absolute security. Do not place sensitive personal information or secrets in listing fields, feedback, or URLs submitted to our tools.
7. International processing and your rights
Our providers operate internationally, so information may be processed outside your country, where data protection rules may differ. Applicable transfer requirements depend on your location and the provider involved. Contact us for information about a particular provider or processing activity.
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, object to or restrict certain processing, and withdraw consent where processing relies on it. Withdrawal does not affect processing already carried out lawfully. You may also complain to your local data protection authority.
Email hello@usefulshelf.co with the account email or listing URL concerned and the request you want us to address. We will handle requests under the rules that apply to them. You can browse public listings without signing in and choose not to provide optional submission details or use AI autofill.
8. Children and policy updates
UsefulShelf accounts and paid services are intended for adults. If you believe a child has provided personal information to us, contact us so we can investigate and address it.
We will update this page and its revision date when our practices change, and provide additional notice for material changes where required. Please review the policy when using new features or connecting another service.