Skip to content

Legal

Privacy

We collect an email address when you give us one, and a vote signature that cannot be read back into an identity. That is close to the whole story.

Last updated 15 September 2026

What we collect

  • Email address — when you submit a product, claim a listing, subscribe to the newsletter, request investor access or ask about sponsorship.
  • Submission data — the product URL and the copy you or we drafted from the public page.
  • First-touch attribution, when you submit a product: the referring site’s hostname (e.g. chatgpt.com) and any utm campaign tags you arrived with, so we know which channels bring submissions. Captured once per session, client-side, on the first page you land on.
  • A vote signature — a one-way hash of your network address and browser string, used to stop the same person voting twice. We do not store the address or the browser string themselves and the hash cannot be reversed.
  • An audit record — for writes: which action ran, against which listing, and when. This is what makes rate limits and abuse investigation possible.

We measure site traffic with Umami, self-hosted on our own infrastructure: it is cookieless, sets no cookies and does not track you across sites, does not store your IP address in the clear, and produces aggregate statistics only, which we alone see and which are never sold or shared with advertisers. We run no advertising pixels and no third-party cookies.

Badge referrer registry: when a page you embed a toolfound badge on is viewed, we record the hostname the badge was requested from (for example example.com), a product slug and a date, so we can show a public list of the sites that embed a badge at toolfound.com/found-on. We never store the full URL, the path, the query string or your visitors’ IP addresses, and a badge is never required for a listing, a link, or anything else on toolfound.

Public discovery plugin

Toolfound’s public ChatGPT plugin provides read-only access to public directory information. Depending on the tool you use, it processes a search query, product slug, time period or calendar horizon. It returns public product and launch information from Toolfound, with links back to the relevant public pages. Product copy and other listing claims can come from the product’s submitted or public source material; Toolfound does not independently verify every such claim. When the plugin reports maker verification, that field describes Toolfound’s separate ownership-verification status.

The public plugin does not require an account and does not ask for your name, email address, credentials or conversation history. Its discovery tools do not create audit records, send email, change listings or write analytics events. Requests still pass through our hosting infrastructure. If a request produces application diagnostic output, local operational logs may contain standard request information such as network address, user agent, requested endpoint and time. These files have no fixed-day retention period: each service keeps at most three files of 10 MB and deletes older data as those files rotate. The proxy does not keep an access log. If an unexpected application error reaches our error-monitoring provider, Sentry, it may process related diagnostic request metadata for up to 30 days. You can ask us to delete information linked to you using the contact below.

Toolfound also has an older MCP integration with write actions for submissions, claims and listing management. When you choose one of those actions, its audit records may contain a one-way network actor hash and action metadata such as an email address, product URL or listing slug. Those audit records are covered by the twelve-month period below. This data is not collected by the public discovery tools.

Why we collect it

Contract, for anything you asked us to do — sending a verification link, holding a queue slot, replying about sponsorship. Legitimate interest, for abuse prevention, for keeping the index accurate, and for first-touch attribution (knowing which channels bring submissions). Consent, for the newsletter, which is double opt-in.

How votes are counted

A vote is stored as a listing identifier plus the hashed signature described above. There is no account behind it, so we cannot tell you what you voted for and neither can anyone else.

Email

Transactional email — verification links, queue confirmations, launch-day notices — goes to the address you gave for that purpose. Marketing email means the weekly newsletter and nothing else. Every message we send carries a one-click unsubscribe header as well as a link, and unsubscribing is immediate.

If we contact the owner of an unclaimed listing, it is a single message about that listing with at most one follow-up, and it always includes a removal link.

Who else sees it

Our hosting provider, our database provider, our email provider and our error-monitoring provider process data on our behalf under contract. We do not sell data, we do not share contact details with investors or sponsors, and we do not run advertising networks on the site.

Your rights

Ask us for a copy of what we hold, ask us to correct it, or ask us to delete it: email [email protected] and we will act within 30 days, and usually within two working days. Deleting your email address also removes you from the newsletter and from any pending submissions.

Unverified submissions are deleted automatically after 14 days. Newsletter addresses are kept until you unsubscribe. Audit records and first-touch attribution (referrer hostname and utm tags) are kept for twelve months.