Privacy

Last updated 10 September 2026.

Catalogs is run by Founded Labs Inc. Where this page says "we", it means Founded Labs Inc. This page says what we store about you, why, who else sees it, and how to get rid of it. It is short on purpose. If you want to know something it does not answer, ask at hello@foundedlabs.com and we will tell you.

The short version: Founded Labs Inc. stores your GitHub identity, your email, and what you do here. We do not sell it and we do not share it for advertising. We count how the site is used with an analytics service that sets no cookies and is never told who you are; the Analytics section below says exactly what it gets.

Terms covers the rest of the deal.

What we store

Your account, when you sign in:

  • The identity GitHub gives us through our sign-in provider: an account id, your email address, your display name, and the web address of your profile picture. We do not get your GitHub password and we never see it.
  • A session record so you stay signed in, and which teams you belong to here.
  • Your GitHub account id and public username, kept so we can check whether a catalog you ask to claim is really yours. The id is the part that does the work, because a username can change hands and an id cannot.
  • If you claimed a catalog, the record of that check. If you asked to claim one and we did not already recognise you, the request itself: which catalog, when you asked, and what we decided.

What you do here, tied to your account when you are signed in:

  • Searches you run, including the words you searched for and whether they found nothing.
  • Items you open, pick, and add.
  • Sessions you link with a coding agent: the search behind them, the filters, any note, which items were shown, which you chose, and when.
  • Which client you last used, such as the command line tool or the agent connection.
  • Feedback you send us: what you wrote, the page you were on, and your email if you were signed in.

Server logs, which are deliberately thin:

  • The time, the request path, the response code, how long it took, which client asked, and whether the call was signed in.
  • A blunted version of your IP address rather than the address itself. For a normal IPv4 address that means the last number is thrown away before anything is written down.

Logs never contain your email, your name, or any token. They exist so we can see abuse and fix slow pages, and they are kept for a short time.

Cookies

Catalogs sets a cookie to keep you signed in, a small copy of your name and picture so the page does not flicker while it loads, and a few that remember your choices: light or dark, how you like results laid out, which setup guide you last read, and whether you have entered the product so the introduction does not appear on your next visit.

That is all of them. There are no advertising cookies and no tracking pixels anywhere on this site, and our analytics sets no cookies at all: it works without storing anything on your machine, which is what keeps it from recognising you tomorrow. The Analytics section below says how it counts a visit without that.

Analytics

Search counts distinguish requests made while typing from results you pause on or choose from. This helps us avoid counting unfinished words as failed searches.

Catalogs uses PostHog, an analytics service hosted in the European Union, to count how the site is used: which pages get opened and left, roughly how long people spend on them and how far they scroll, what people search for and whether it found anything, which items get looked at and picked, and how many visits reach sign-in. This is how we decide what to fix and what to build next.

For linked sessions, we count page visits and whether the session is open, sent, or expired, how many picks were sent (including none), and failed send requests. Private session links and your instructions are never included in these events.

The way it is set up is the point, so here it is, plainly:

  • It sets no cookies and stores nothing in your browser.
  • We never tell it who you are. No name, no email, no account id reaches it, signed in or not.
  • To count visits without keeping anything on your machine, PostHog works out a scrambled code on its own servers from your network address, your browser, and the site you are on. Within a single day, visits that share those count as one visitor. That is how we tell one person reading four pages from four people reading one.
  • The key that makes that code is thrown away every night and replaced. Once it is gone the codes cannot be unpicked or matched up again, by us or by PostHog. So we can see how many people came today, and nobody can follow you to tomorrow or to any other site.
  • Your IP address is one of the ingredients of that code and is discarded rather than stored. At most a country survives, never the address.
  • It records a short, fixed list of events we chose one by one, not everything you do. No screen recording or automatic reading of input fields. Search events include the search text sent when you submit or pause typing; other input fields are not collected.
  • If the page itself breaks, it reports the error so we can fix it: what went wrong and where in our code. The report names the page with any search text removed, and it never includes what you typed.
  • PostHog holds this data on behalf of Founded Labs Inc. and may not use it for anything else.

The command line tool and the agent connection do not talk to PostHog at all. What they report is described above under what we store, and it stays with us.

Email

Founded Labs Inc. uses your email address to run your account and to write to you about the beta: a welcome note, a change that affects you, a question about something you published. Creating an account is where you agree to that, and the Terms say so. We do not send marketing for anyone else, and we do not pass your address on.

You can take it back at any time. Your profile has a switch for occasional product emails. It starts on, because agreeing to them is part of creating an account, and turning it off stops them for good. Mail about your own account carries on either way. If you would rather a person did it, email hello@foundedlabs.com and say stop.

Nothing has been sent yet. Founded Labs Inc. has not sent a single product email, and that switch is what we will honor on the day we start.

What we never do

  • Founded Labs Inc. does not sell your data. Not to anyone, not in any form.
  • We do not share it with advertisers or data brokers, and we run no ads.
  • We do not build a profile of you to sell attention against.
  • We do not read your code. We only see what you publish here on purpose.

Who else sees it

Our sign-in provider handles the login itself and holds your identity as part of doing that. GitHub is where that identity comes from, so GitHub knows you signed in to Catalogs. Beyond those, the companies that host the site, run the database, store files, power search, and count usage for us (the Analytics section above) hold this data on behalf of Founded Labs Inc., and are not allowed to use it for anything else.

Founded Labs Inc. would hand over data if the law actually required it. Nothing else gets it. Ask at hello@foundedlabs.com if you want the current list of who those companies are, and we will tell you.

Getting your data deleted

Email hello@foundedlabs.com and ask. Founded Labs Inc. will delete your account, your sessions, your picks, and your feedback, and we will tell you when it is done. You do not have to give a reason.

Two honest exceptions. Thin server logs, which do not carry your name or email, age out on their own rather than being hunted down. And counts that no longer point at anyone, such as how many people searched for something in a given week, stay as counts.

You can also ask for a copy of what we hold about you, or ask us to correct something that is wrong. Same address.

Contact

Founded Labs Inc., hello@foundedlabs.com. A person reads it. That is the right place for deletion requests, questions about this page, and anything about your data you are not happy with.