UserTrack
Legal

Privacy Policy / Datenschutzerklärung

This policy explains which personal data UserTrack (usertrack.dev) processes, why, on which legal basis, and what you can do about it. The German summary below is binding for the identity of the controller and your rights; the English text is the full policy.

Effective date: 2026-09-04

Kurzfassung auf Deutsch

Verantwortlicher: The CodeCave GmbH, Alfred-Nobel-Str. 29, 50226 Frechen, Deutschland, vertreten durch die Geschäftsführer Aleksandar Jovanovic und Tilman Kieselbach. Kontakt: info@thecodecave.de, +49 152 04943138. Ein Datenschutzbeauftragter ist nicht bestellt, da keine gesetzliche Pflicht besteht.

Betroffenenrechte: Sie haben das Recht auf Auskunft (Art. 15 DSGVO), Berichtigung (Art. 16), Löschung (Art. 17), Einschränkung der Verarbeitung (Art. 18), Datenübertragbarkeit (Art. 20) und Widerspruch (Art. 21), sowie das Recht, eine erteilte Einwilligung jederzeit mit Wirkung für die Zukunft zu widerrufen (Art. 7 Abs. 3). Konto löschen und Daten exportieren können Sie selbst unter /app/settings#data-privacy; alle anderen Anfragen richten Sie an info@thecodecave.de. Beschwerden nehmen die Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (Kavalleriestraße 2–4, 40213 Düsseldorf, Germany) oder jede andere Aufsichtsbehörde entgegen.

Cookies und Analyse: UserTrack setzt nur das technisch notwendige Sitzungs-Cookie des Logins und nutzt eine selbst betriebene, cookielose Reichweitenmessung ohne Tracking über Websites hinweg. Ein Einwilligungsbanner ist deshalb nicht erforderlich.

1. Controller

The controller within the meaning of Art. 4(7) GDPR is The CodeCave GmbH, Alfred-Nobel-Str. 29, 50226 Frechen, Nordrhein-Westfalen, Germany, represented by its managing directors Aleksandar Jovanovic and Tilman Kieselbach. Register: Amtsgericht Bielefeld, HRB 44492. Contact: info@thecodecave.de, +49 152 04943138. See the Impressum. No data protection officer has been appointed because none is legally required.

2. What UserTrack is

UserTrack is a free, public leaderboard of SaaS and app user growth. Founders connect a data source they own (an authentication provider, a read-only database role, an analytics tool, a billing tool for conversion counts, or our SDK), UserTrack reads aggregate counts only — never revenue, never customer lists — and publishes a growth page, rankings, share cards, embeds, a JSON API and an MCP server for AI agents.

Two groups of people are affected: founders with an account, and visitors who browse public pages, call the API or view an embed. Founders should note that the end users of their own products are not identified to UserTrack: we receive counts and, where a founder enables cohort matching, salted hashes of internal ids (section 3.4).

3. Data we process

3.1 Account

Managed by the Better Auth library inside our database: email address, display name, password hash (never the password), email-verification status, session tokens, sign-up and sign-in timestamps. If you use one of the sign-in providers we offer (Google, GitHub, X), we receive the provider’s user id, your name, email and avatar URL from that provider and store the provider id to recognise you next time. We never receive your provider password.

3.2 Founder profile

Username, display name, avatar URL, bio, website, GitHub, LinkedIn and X handle, location, notification preferences, follower count and the profile-visibility settings you choose; if you arrived through a tracked link (a badge, share card or email), the source tags of that link (ref / utm_*) and the time of that first visit are stored with the profile once. Everything except email, settings and the sign-up source is published by design on your founder page unless you switch the profile to private, anonymous or hidden (section 9).

3.3 Products and connected sources

Product name, slug, URLs, category, description, logo, platform type, founding month and visibility toggles. To sync a source we store the credentials you provide (API keys, read-only database connection strings, service-role keys, OAuth tokens where a provider uses them). They are stored server-side in our database, used read-only by the sync jobs, and are never returned to the dashboard, the API or an agent. We also log each sync run (status, error message, duration, row counts) so you can see why a source stopped working.

3.4 Growth data

Per product and per stage (reached, signed up, activated, trial, converted): totals and daily counts, snapshots every four hours, ranking and benchmark positions, milestones and computed trust scores. For cohort matching a source may report internal user ids; each id is hashed as SHA-256(IDENTITY_SALT · project · id) inside the sync job before it is stored. Anything that looks like an email address is dropped at parse time. The salt is a server secret, so the hashes cannot be reversed or linked across projects, and nothing on UserTrack ever displays an individual subject — only counts and medians per signup month.

3.5 Email

Your email preferences and a delivery log per message: recipient address, message type (welcome, verification, password reset, milestone, digest, monthly report …), status, timestamps, the provider’s message id and the template variables used. Bounce and complaint signals from our email provider are stored per address to suppress further mail. Message bodies and any authentication links are not kept in the log.

3.6 Developer tokens, API usage and audit log

API keys and MCP tokens are stored hashed (SHA-256) together with a name, prefix, scopes, creation, expiry, revocation and last-use timestamps. Usage is counted per token, day and endpoint category. Writes performed with a token and onboarding steps are recorded in an audit log (action, project, success, short detail — never configs or secrets).

3.7 Webhooks

Endpoint URL, description, subscribed events, signing secret (shown once, then kept server-side), delivery attempts with HTTP status, timing and error text. Response bodies are not stored.

3.8 Embeds, follows and share cards

When a badge or widget is loaded from another site we record the referring host name only (no path, no visitor data) to show “embedded on N sites”. Follows link your profile to the products and founders you follow. Share and card views are counted per product and card type without identifying the viewer.

3.9 Connected X account (optional)

If you connect X, we store the X user id, handle, name, avatar URL, the access and refresh tokens with their scopes, the connection status, the last post made and, if you enable auto-posting, the posts published on your behalf. Tokens are used only to post what you opted in to and to refresh the handle and avatar.

3.10 Server logs and abuse prevention

Our hosting providers keep request logs (IP address, user agent, requested URL, response status, timestamp) for a short period for security and debugging. Anonymous API, badge, embed and card requests are rate-limited per IP address; the counters live for at most ten minutes. We do not build visitor profiles from these logs.

3.11 Analytics

Cookieless page-view statistics as described in section 8. No account data is sent to the analytics service.

4. Purposes and legal bases

PurposeDataLegal basis
Providing the account, the dashboard, syncs, public growth pages, API, MCP, webhooks, embeds and transactional email (welcome, verification, password reset, sync failures)3.1 – 3.4, 3.6 – 3.8, transactional part of 3.5Art. 6(1)(b) GDPR — performance of the contract described in the Terms
Security, abuse and fraud prevention (rate limiting, trust scores, audit log, email-verification, bounce suppression), debugging3.6, 3.10, sync logs, trust signalsArt. 6(1)(f) GDPR — our legitimate interest in a reliable, un-gamed leaderboard and a secure service
Cookieless reach measurement3.11Art. 6(1)(f) GDPR — legitimate interest in understanding which pages are used; no cookies or device fingerprints, so § 25 TDDDG consent is not required
Product nudges, growth emails, weekly digest, monthly report, followed-product alerts3.5 (non-transactional)Art. 6(1)(a) GDPR — consent via the notification preferences; withdraw any time at /app/settings/notifications or the unsubscribe link
Posting to your X account, importing handle and avatar from X3.9Art. 6(1)(a) GDPR — consent when you connect X and enable a posting category; disconnect at any time
Publishing founder profile and growth data3.2 – 3.4 (public projections only)Art. 6(1)(b) GDPR — publication is the core of the service you request; visibility controls in section 9

5. Processors and third countries

We use the following processors under Art. 28 GDPR contracts. Where a processor is located in the United States, transfers rely on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and, where the provider is certified, on the EU-US Data Privacy Framework.

ProviderRoleLocation / safeguard
Convex, Inc.Database, backend functions, authentication storage, scheduled jobsUSA — SCCs
Railway Corp.Hosting of the web application (request logs)USA — SCCs; EU region where available
Resend, Inc.Transactional and notification email deliveryUSA — SCCs
Cloudflare, Inc.DNS, CDN and DDoS protection in front of usertrack.devGlobal edge, EU data localisation — SCCs
Google LLCSign in with Google (only when you choose it)USA — SCCs / DPF; Google acts as independent controller for its own account data
GitHub, Inc. · X Corp.Sign in with GitHub / X (only when you choose it; a GitHub or X sign-in imports your handle and avatar into your founder profile, which you can edit); X additionally for the optional account connection and postingUSA — SCCs; independent controllers for their platforms
The CodeCave GmbH (self-hosted Rybbit)Cookieless web analytics operated by us on EU infrastructureEU — no third-party access

Your connected data sources (Clerk, Supabase, Firebase, Auth0, PostgreSQL, PostHog, Plausible, GA4, Stripe, RevenueCat, Paddle, Lemon Squeezy, Chargebee, your own endpoint) are your processors or controllers; UserTrack only reads from them with the credentials you provide. We do not sell data and do not share it with advertisers.

6. Retention

  • Account, profile, products, connected-source configuration, growth aggregates, follows, tokens: until you delete them or your account.
  • Raw 4-hour snapshots: thinned to one sample per day after 180 days (per stage for activation / conversion samples); the daily rows are kept as the product’s history.
  • Sync runs: 30 days.
  • Webhook deliveries: 30 days, once a delivery has succeeded or exhausted its retries.
  • API usage counters: 90 days.
  • Email delivery log: 180 days; bounce and complaint suppression until you ask us to lift it.
  • Audit log: 365 days.
  • History-import log: 90 days. Background-job log: 90 days (no personal data).
  • Sign-in state for connecting X (CSRF / PKCE): 1 day.
  • Server request logs: a few days at the hosting provider.
  • After account deletion: personal data is removed immediately; frozen monthly rankings keep only the product name and position as historical record, and pseudonymous identity hashes become unlinkable because the project key is gone.

Statutory retention duties (e.g. § 147 AO, § 257 HGB for business correspondence) prevail where they apply.

7. Cookies

UserTrack uses only strictly necessary cookies: the Better Auth session cookie that keeps you signed in (and its short-lived CSRF / state cookies during sign-in with a provider). They are required to provide the service you asked for (§ 25(2) no. 2 TDDDG), so no consent banner is shown. There are no advertising, tracking or third-party cookies, and embeds and badges set no cookies on the sites that host them. Local storage is used for interface preferences such as chart ranges and, while you are signed in, for the pseudonymous analytics id described in section 8.

8. Analytics

We measure page views and product usage with Rybbit, an open-source analytics tool that we host ourselves on EU infrastructure operated by The CodeCave GmbH. It is cookieless, performs no cross-site tracking and does not use session replay. Besides page views we record product events (for example “sign-up completed”, “source connected”, “badge snippet copied”), clicks on outbound links, button clicks and form submissions (the fact of a submission, never what was typed), Core Web Vitals and JavaScript errors. Event properties are limited to categories such as a provider name or a step number — never e-mail addresses, handles or third-party URLs. Your IP address is used only to derive a daily-rotating, salted hash for counting unique visitors and is never stored; coarse location (country / region), browser family, referrer and page path are aggregated; the paths of password-reset and e-mail-preference links are masked so tokens never reach analytics. While you are signed in, events are linked to your pseudonymous account id (a random identifier, never your name or e-mail) so that we can see where founders get stuck between sign-up and a published page; it is kept in your browser’s local storage and removed when you sign out. This processing is based on our legitimate interest in understanding and improving the service (Art. 6(1)(f) GDPR). If you still prefer not to be counted, set localStorage.setItem("disable-rybbit", "1") in your browser.

9. Public by design

A founder profile and the growth data of a published product are intentionally public: that is what UserTrack is for. Only what the founder publishes is shown (per-metric visibility toggles; conversion data is private by default), and every number carries its verification label. Founders control the exposure from the dashboard: unpublish a product, switch the profile to private, use anonymous mode (product shown without the founder), and hide from search engines (pages served with noindex). Public data may be cached by search engines and reused under the licence in our Terms; we cannot recall copies made by third parties while a page was public.

10. Your rights

Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). Where processing is based on consent you may withdraw it at any time with effect for the future (Art. 7(3)). We do not use automated decision-making within the meaning of Art. 22.

To exercise these rights, email info@thecodecave.de from the address of your account; we answer within one month. You also have the right to lodge a complaint with a supervisory authority, in particular the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.

11. Deletion and export

You can delete your account yourself at /app/settings#data-privacy (Settings → Data & privacy → Delete account; you confirm by typing DELETE and receive one confirmation email). Deletion removes your account, profile, products, connected-source credentials, tokens, webhooks, follows, preferences and email log; public pages disappear immediately and the sitemap is updated at the next crawl. You can also export everything we hold about you from the same panel (“Download my data”, /api/account/export) as a machine-readable JSON file (Art. 20). Individual products, sources, tokens and the X connection can be removed separately from their own pages.

12. Children

UserTrack is a service for founders and is not directed at children. You must be at least 16 years old to create an account. If you believe a younger person has registered, tell us and we will delete the account.

13. Security

Traffic is encrypted in transit (TLS, HSTS), passwords are hashed, tokens are stored as hashes, connected-source credentials are stored server-side and never returned by any interface, every outbound fetch to a founder-supplied host is checked against private and internal address ranges, and request rates are limited. Sync jobs read aggregates only; they never write to your systems.

14. Changes

We update this policy when the service or the law changes. The effective date at the top tells you the current version; material changes are announced by email to account holders before they take effect. Earlier versions are available on request.