Privacy

Privacy

Most of what Superstables stores is about services, not people. This page lists exactly what the site records, why, and how to reach us about it.

Reading the index

Browsing the directory, calling the JSON API, using the MCP server or the natural-language endpoint requires no account, key or login. We do not set cookies for these. Requests pass through our hosting provider, which keeps standard request logs (IP address, user agent, path, time) for a limited period as part of operating the service; we do not build profiles from them.

On public pages, Google Analytics 4 may load when a measurement ID is configured, and the X (Twitter) conversion tracking pixel loads so we can measure and reach visitors with X ads. Neither is ever loaded in the private review area. Events recorded are limited to page views and the start and completion of the early-access form. Your theme preference is kept in your browser's local storage only.

Data about services

Index records describe endpoints: name, description, category, URL, payment rails, chains, assets, advertised price, facilitator, the sources the entry was found in, and the results of our liveness probes (time, status code, latency, how the challenge was detected). Probe history is kept indefinitely. This is information the services publish about themselves; if you operate a listed service and want a record corrected or removed, contact us and we will delist it.

Listing a service

When you submit a service, we store the endpoint URL, the name and the contact you give us, and the time of submission. We probe the endpoint once immediately and, when notifications are configured, notify our team by email with the result. The contact is used only to reach you about the listing. Repeated submissions of the same endpoint within 24 hours are deduplicated.

Early access

The early-access form stores your email address, your answers to the qualifying questions, your optional free-text note, a short share code, the share code of whoever referred you, and the browser user agent and referring page at the time you submitted. One row is kept per email; submitting again updates it. When notifications are configured, our team receives an email for each application and a copy is posted to an internal webhook. Your place in line is derived from these rows and can be looked up with your share code; that lookup returns position and referral count only, never your email.

Demo feedback

The demo feedback form is hosted by Tally. A submission stores your written report, any screenshots you attach, and a contact if you choose to give one, together with the fixed context of the form (which page it was on, testnet). Each submission is copied into our issue tracker so the team can act on it. Nothing from the form is written to the index database, and the page forwards nothing from your browser's address bar to the form.

Review build

The password-gated product preview keeps everything you do in it (sample keys, policies, wallets, activity) in your browser's local storage. It sends nothing to a backend and moves no money. A small operator-editable settings store on the server holds site settings such as a published contract address; it contains no personal data.

Where data lives

The site is served from Vercel and the database is Neon Postgres. Transactional email, when configured, is sent through Resend. Demo feedback is collected by Tally and copied into Linear, our issue tracker. These providers process data on our behalf under their own terms.

Your choices

You can ask us to delete your early-access application, your service submission, your demo feedback, or a listed service record, or to tell you what we hold about you. Use the contact links in the footer of any page. Standard AI crawler directives for this site are published in robots.txt, and machine-readable guidance in llms.txt.

Last updated 2026-09-25. Also available as markdown.