Privacy
Privacy notice
What Component Hunt records, why it is needed, and how to request access, correction, or deletion.
Last updated July 28, 2026
Public browsing
Public discovery does not require an account. The application records a random per-tab identifier for aggregate product events such as searches, filters, previews, shares, and source clicks. The API stores only a one-way hash of that identifier and does not attach submission contact details or operator identity to analytics events.
GitHub account information
Signing in is optional. GitHub provides the public profile, verified email, and provider identity used to create an account. Component Hunt stores that profile, expiring session records, and encrypted OAuth tokens so it can authenticate the account. It does not receive the GitHub password.
Information you submit
Submission and issue forms may include a name, email address, source URL, and the evidence you provide. This information is used for editorial review, status updates, fraud prevention, attribution, and rights handling. Avoid including personal data that is not necessary for the request.
Favorites and interrupted saves
A saved Favorite records the account and Component relationship until it is removed or either record is deleted. If Save starts sign-in, the browser keeps the Component slug, internal return path, and creation time in that tab for no more than 15 minutes. The one-shot intent is removed when claimed, at sign-out, or when the tab session ends; malformed, expired, and external destinations are discarded.
Local storage and service providers
The per-tab analytics and operator session keys are kept in browser session storage and clear when that tab session ends. Signed-in users receive an HTTP-only account session cookie that expires after seven days and is revoked on sign-out. A separate random abuse-prevention key remains in local storage so the API can apply rate limits; the API does not store that key in analytics. The application does not set advertising cookies. GitHub provides account authentication. Cloudflare provides hosting, request protection, operational logs, and database infrastructure; each provider may process technical data needed to deliver the service.
Retention and requests
Editorial, submission, security, and audit records are retained while needed to operate the catalog, document decisions, resolve disputes, and meet legal obligations. To request access, correction, or deletion, email privacy@componenthunt.dev. Some audit and rights records may need to be preserved after public content is removed.