What we hold, and how to have it removed
Most profiles on this site were built from activity people had already published, without us asking first. That deserves a plain explanation and a way out that takes one click, so both are on this page.
The unusual part, first
2,270 of the profiles here were created without the person being asked. We read public posts carrying #buildinpublic and similar tags on Mastodon, Bluesky, X and Show HN, followed the link to the product website the person had published, and read public GitHub activity where the account could be identified from that website. Nothing was taken from a private account, a direct message, or a page behind a login.
If that is you and you would rather not be here, ask us to remove it. No account, no sign-in, no explanation required. Your listing comes down immediately, your stored screenshots and avatar are deleted the same moment, and the rest of the record is purged after 30 days. We also add you to a do-not-list so the discovery pipeline cannot put you back.
What is stored about a listed builder
- Your public handle, display name and profile link on the platform where the post was found.
- Your product URL, and a screenshot, favicon and social image captured from it, plus the title and description the page itself publishes. We store the picture, not a copy of your site.
- Public activity timestamps — commits, releases and posts — used to work out a shipping streak. We store when something happened and what it was called, not the contents of your code.
- A location, only if you published one on your profile, resolved to an approximate point for the map.
We do not collect email addresses from public sources. Not because we could not, but because a listing is not permission to contact you.
If you sign in
Signing in with GitHub or Google is how you claim a page and take control of it. 0 people have an account; 1 profiles are claimed. We ask for the minimum each provider offers: your public profile and, from Google, a verified email address. We never request repository access, contacts, or permission to post.
We store your provider account id, your email, your name and your avatar. The access token from the provider is used for a single request and discarded — it is never written down. Your session is a signed cookie holding an account number and an expiry, nothing more.
The email is used to verify ownership when your address is on your product’s own domain, and to reply if you contact us. It is not sold, shared, or added to a mailing list.
Cookies
Three, all set by us, none for advertising. A session cookie when you sign in. A random identifier so an anonymous vote can be counted once, which identifies a browser and not a person. A theme preference. There is no Google Analytics, no tracking pixel, no third-party advertising script, and therefore no cookie banner asking you to accept any of it.
What we send elsewhere
- Nothing to advertisers or data brokers. Ever, including as part of a sale of the business.
- Email delivery uses Resend. Newsletter mail goes only to the 384 people who subscribed. A founder may receive one listing invitation and one follow-up at a public business contact address; claiming, replying, unsubscribing or asking for removal stops it.
- Hosting is Vercel; the database is Postgres on Supabase.
- Sign-in talks to GitHub and Google at the moment you use it, and to nobody afterwards.
How long things stay
A live listing stays while it is live. After a removal request, the profile disappears at once and the underlying record is purged 30 days later — the gap exists so a removal can be reversed if it was made in error, and so the do-not-list entry survives. 301 profiles have been removed this way. A signed-in account is kept until you ask us to delete it.
Your rights, and how to use them
Under UK and EU data protection law you can ask for a copy of what we hold, ask us to correct it, or ask us to delete it. In practice: the removal page does deletion in one click without an account, claiming your profile lets you correct anything on it yourself, and for a copy of your data write to the address below. We answer within 30 days and usually the same week.
There is no charge, and we will not ask you to justify the request.
Contact
Built In Public is run by one person. Write to andy@builtinpublic.dev for anything on this page, including complaints. If you are in the UK and unhappy with the answer, you can complain to the Information Commissioner’s Office at ico.org.uk.
Last updated 8 September 2026. The counts on this page are read from the database when you load it, so they are current rather than a figure typed in once.