Privacy Policy
How SetFork collects, uses, and protects your personal data.
This is where we describe how we handle your "Personal Data" — information that is directly linked or can be linked to you. It applies to the Personal Data that the operator of SetFork processes as the "Data Controller" when you use websites, applications, and services that display this policy (collectively, "Services").
Effective date: July 10, 2026
Email support is not yet live
The contact addresses referenced on this page are still being set up and may not receive mail yet. You can exercise most privacy rights directly in your account settings (profile editing, data export via git, account deletion). This notice will be removed once support channels are operational.
Personal Data we collect
From you
- Account data. When you open an account we collect your username, email address, and a password (stored only as a salted hash). If you sign in with GitHub, we receive your GitHub username and the email address you have authorized GitHub to share.
- User content. Content you create through the Services — lists, steps, blocks, suggestions, issues, comments, releases — including any Personal Data you choose to include in it.
- Profile information. Optional details you add to your profile, such as a display name or biography.
- Support data. Information you send us when you contact support.
Automatically
- Service usage information. Standard technical logs: IP address, user-agent, date and time of requests, and pages or API endpoints accessed. We use these for security (for example, rate limiting and abuse prevention) and troubleshooting.
- Essential cookies. We use a session cookie to keep you signed in and remember essential preferences. We do not use advertising or cross-site tracking cookies, and we do not load third-party trackers. Because we only set cookies that are strictly necessary to provide the Services, no cookie consent banner is required.
- Analytics. We use a self-hosted instance of Umami, a privacy-focused, cookieless analytics tool, to understand aggregate site usage (page views, referrers, country-level location derived from IP). Umami does not set cookies, does not build cross-site profiles, and its data stays on our infrastructure. Visitor identifiers used for view statistics are anonymized with daily-rotating hashes and cannot be linked back to you over time.
- Notification emails. Our emails do not contain tracking pixels. You can control which notifications you receive in your settings.
How we use your Personal Data
- Service provision. To deliver the Services you request: hosting and displaying your lists, running lists, notifications, collaboration features, API and MCP access.
- Safety and security. To protect the Services and our users: abuse detection, spam prevention, and content moderation. New public lists are automatically analyzed for policy violations before becoming publicly visible; this analysis may use a third-party AI service (see "Sharing" below).
- Communication. To send you service notifications (which you can configure) and respond to your support requests. We do not send marketing email.
- Troubleshooting and improvement. To identify and fix technical issues and understand aggregate usage of features.
- Legal obligations. To comply with applicable law and resolve disputes.
We practice data minimization and use the minimum amount of Personal Data required. We do not sell your Personal Data, and we do not share it with third parties for advertising. We do not use your Personal Data or your content to train artificial intelligence models.
Sharing of Personal Data
We share Personal Data only with the following categories of recipients:
- Infrastructure providers. Our servers are hosted in a data center in Frankfurt, Germany (European Union). Cloudflare, Inc. provides content delivery and security services in front of the Services and therefore processes technical request data (such as IP addresses).
- Content moderation. When a public list is submitted for publication, its text may be sent to a third-party AI provider to classify it against our Acceptable Use Policy. We send only the content being reviewed, not your account details, and we use provider settings that do not permit training on the submitted data where available.
- Email delivery. A transactional email provider delivers our notification emails to your address.
- Other users and the public. Content you publish — public lists, suggestions, issues, comments, your username and profile — is visible to other users and the public, and is accessible through the API, the MCP server, and git clones. Be careful about including Personal Data in content you make public.
- Competent authorities. We may disclose Personal Data to law enforcement or other public authorities where required by a lawful request, or to protect our rights and the safety of our users.
We do not have advertising partners, and we do not share data with data brokers.
Lawful bases for processing (EEA and UK users)
We process Personal Data with a lawful basis for each activity:
- Contractual necessity — providing the Services under our Terms of Service (account, content hosting, notifications).
- Legitimate interests — securing the Services, preventing abuse, moderating content, and measuring aggregate usage, where these interests are not overridden by your data protection rights.
- Legal obligation — where processing is necessary to comply with applicable law.
- Consent — where we ask for it explicitly; you may withdraw consent at any time.
Your privacy rights
Depending on your residence location, you may have specific legal rights regarding your Personal Data:
- the right to access the data collected about you;
- the right to rectify or update inaccurate or incomplete Personal Data;
- the right to erase your Personal Data under specific conditions;
- the right to restrict or object to processing, as allowed by applicable law;
- the right to data portability — you can export your lists at any time via git clone or the API in standard formats;
- the right to withdraw consent, where processing is based on consent;
- the right to complain to your local Data Protection Authority (EU users can find contacts via the European Data Protection Board; UK users via the Information Commissioner's Office).
You can exercise most of these rights directly: edit your profile in settings, export your content via git or the API, and delete your account in settings. For anything else, email support@setfork.com. To verify your identity, we may request additional information before addressing your request.
Data retention and account deletion
We retain your Personal Data while your account is active. When you delete your account, your profile is removed and your personal identifiers are anonymized within 90 days; some information may persist in encrypted backups for a limited period. Public contributions that other users depend on — lists that have been forked, and your suggestions, issues, or comments on other users' lists — may be retained in anonymized form, attributed to a "ghost" account. Technical logs are kept for a limited period appropriate to their security purpose.
International data transfers
Your data is stored in the European Union (Frankfurt, Germany). Some of our service providers (such as Cloudflare and AI moderation providers) are based in the United States; where Personal Data is transferred outside the EEA or UK, we rely on appropriate safeguards such as the providers' standard contractual clauses or their certification under the EU-U.S. Data Privacy Framework.
Security
We use appropriate administrative, technical, and physical security controls to protect your Personal Data, including transport encryption (TLS), salted password hashing, and optional two-factor authentication for your account.
Information for minors
Our Services are not intended for individuals under the age of 13, and we do not intentionally gather Personal Data from them. If you become aware that a minor has provided us with Personal Data, please notify us at support@setfork.com.
Changes to this policy
We may periodically revise this Privacy Policy. If there are material changes, we will provide at least 30 days prior notice by updating our website or sending an email to the primary email address associated with your account.
Contact us
Questions or concerns about privacy on SetFork? Email support@setfork.com.
This policy is adapted from GitHub's site-policy documents (CC0-1.0) and reflects SetFork's actual data practices.