Privacy notice
Last updated: 22 September 2026.
Who is responsible
Petr Peller operates submitby.ai and is the controller of personal information used to run the directory. Our postal address is in the Legal notice. Contact support@submitby.ai for privacy requests. Include the project URL or submission ID where possible. Do not send passwords, editing tokens, or full payment-card details.
Information we use
We receive project names, URLs, descriptions, categories, tags, and submission requests. We retrieve public website text and metadata to check website control, badges, and compliance with our directory rules. We store verification results, website fingerprints, evidence references, review decisions, and recovery records. Information can come from a submitter other than the website owner, or from the public website.
Cloudflare processes request and network information to deliver and protect the service. Our application uses a hash derived from the request IP address to limit repeated requests. Application error reports use error codes rather than request bodies, editing tokens, or payment credentials. Infrastructure providers also process their own technical and security logs.
Stripe collects payment information at Checkout. We retain payment IDs, amounts, currency, payment status, and the related submission ID. We do not store full card numbers or card security codes. We also process messages and contact details that you send to support.
Purpose and legal basis
- We process requested submissions, payments, and support to provide our service and perform our contract with you.
- We use verification, review, and security records for our legitimate interests in preventing abuse and keeping the directory accurate. This also applies to public project information supplied by others. You can object to this processing.
- We retain records required by law for accounting, legal requests, and other legal obligations.
Required project and verification information is necessary to assess a submission. Without it, we cannot publish the listing. You can use the free badge route without payment information.
What becomes public
Published project listings are public. Ordinary API drafts remain private unless their owner enables public status. ChatGPT app submissions expose project details and progress to anyone who knows their submission ID. Use that route only for information you can share publicly. Badge code is public. Editing tokens and private review notes are not public.
Automated checks
Cloudflare Families DNS checks domains before we fetch their websites. We send public website text to TypeSafe AI's Jev service through Cloudflare for content flags and category suggestions. These requests do not include editing tokens or payment credentials. Automated checks can block unsafe domains or pause a submission for review. A human approves publication. You can request human review of a block or rejection through support.
Providers and international transfers
Cloudflare provides hosting, database storage, network protection, the AI connection, and email routing. TypeSafe AI processes website text. Stripe and Link handle payments, payment support, fraud checks, and their legal obligations. Support mail is forwarded to the operator's Apple iCloud mailbox. If you use ChatGPT or another agent, that provider processes your conversation under its own terms.
Our production database uses Cloudflare's EU jurisdiction setting. Other processing can take place outside the EEA, including in the United States. Cloudflare and TypeSafe AI's data processing terms include EU Standard Contractual Clauses for applicable transfers. Stripe and Apple describe their transfer safeguards in their privacy notices. Contact us for information about the safeguards relevant to your data.
- Cloudflare data processing terms
- TypeSafe AI data processing terms
- Stripe privacy notice and Link privacy notice
- Apple privacy notice
How long we keep information
Unverified drafts become eligible for deletion after 30 days without changes once their verification code expires. Verification, active jobs, recovery requests, listing claims, or payment records can prevent deletion. Completed and failed jobs expire after 30 days. Expired recovery records are removed after one day. Domain check caches last up to five minutes and are cleaned up after a further day. Rate-limit records expire after their limit window.
We keep active listings and the evidence needed to operate and recover them while the service continues. We review inactive listings, rejected submissions, and manual evidence for deletion when review, appeals, and abuse prevention no longer require them. Routine support messages are removed within 12 months after a request closes. Manual release backups are removed within 30 days unless needed for an incident.
Payment records and records needed for a dispute or legal obligation are kept for the applicable accounting, tax, or claim period. We restrict those records to that purpose and remove them when the requirement ends. Some deletion requires manual review. Provider backups expire under each provider's backup schedule and are not used as active records.
Cookies
The public directory does not set advertising or analytics cookies. The administrator login uses a necessary session cookie that expires after eight hours. Stripe, Link, and other sites you visit have their own cookie notices.
Your rights
Where applicable, you can request access, correction, deletion, restriction, or a portable copy of your personal information. You can object to processing based on legitimate interests. You can ask us to correct or remove personal details in a project listing. We may need limited evidence of your identity or website control. We normally respond within one month. We will explain any lawful extension or refusal.
You can complain to the Czech Office for Personal Data Protection, or the authority where you live, work, or believe a breach occurred. This notice will show a new date when our processing changes.