You're offline — showing the cached catalog.
📦 Web App Finder™
← Back to home

Privacy Policy

Last updated: September 2026

1. Privacy-First Philosophy

Web App Finder is designed to be lightweight, respectful, and transparent. We do not sell user data, we do not use third-party advertising networks, and we do not track you across the internet.

2. Data Stored Locally on Your Device (Client Storage)

To provide an installable, offline-first Progressive Web App experience and support honest community feedback, the following data is stored locally in your browser's localStorage and Cache Storage:

  • pwafinder-device: A randomly generated unique pseudonymous identifier (UUID). It is created solely to ensure fair voting (preventing multiple votes from the same browser on a single app) and to prevent automated spam in warning reports. It contains no personal identity, real name, email, or IP address.
  • pwafinder-voted: A list of app identifiers you have upvoted, stored locally so the user interface can highlight apps you already supported.
  • pwafinder-opens: A local counter tracking how many times you open an app from the directory. This data never leaves your device and is used solely to generate your private "📌 Personal PWA's" shelf.
  • pwafinder-warned: A local record of apps you reported a problem for, preventing duplicate submissions.
  • Service Worker Offline Cache: Caches directory HTML, stylesheet, and icon assets so Web App Finder continues to work when you have no internet connection.

You can delete all local data at any time by clearing your browser's site data / cache for webappfinder.app.

3. Cookieless Operation & EU ePrivacy Compliance

Why We Do Not Display a Cookie Banner: Under the European Union ePrivacy Directive (Directive 2002/58/EC as amended) and UK PECR, cookie consent banners are only legally required for non-essential tracking cookies, third-party analytics cookies, or behavioral advertising identifiers.

Web App Finder uses zero advertising cookies, zero cross-site tracking beacons, and zero commercial profiling scripts. The minimal storage mechanisms we use (such as localStorage for pseudonymous voting integrity and service worker cache for offline availability) are strictly necessary for the technical operation and functional integrity of the site requested by the user, and are therefore exempt from cookie consent banner mandates.

4. Data Transmitted to Remote Servers

Web App Finder only transmits data to backend servers when you explicitly initiate an action:

  • Community Votes & Public Comments: When you click the vote button on an app, the app slug, your pseudonymous pwafinder-device ID, and any optional public comment you type are sent to our database. Comments are published publicly on that app's page. You can withdraw your vote at any time by tapping the vote button again, which deletes your vote and comment from the database.
  • Problem Reports (Warnings): When you submit the "Report a problem" form, your selected reasons, explanation, app slug, and device ID are transmitted to a private database table. These reports are strictly confidential, never shown publicly, and used only by the curator to review potential scams, broken links, or harmful apps.

External Manifest Screenshots: Screenshots displayed on app details pages are linked directly from the external URLs declared in the respective app's Web App Manifest. When your browser renders these preview images, it communicates directly with the third-party publisher's server, which may log your IP address in standard server request logs. These requests are sent with referrerpolicy="no-referrer" to prevent transmitting your browsing history to the external server.

5. Privacy-Friendly Analytics (GoatCounter)

We use GoatCounter for aggregate website traffic statistics. GoatCounter is privacy-oriented and:

  • Does not use tracking cookies or persistent tracking beacons.
  • Does not track users across different websites.
  • Does not collect or store personally identifiable information (PII).
  • Generates anonymized hashes of visits to measure total page views.

6. No Session Replay, Keystroke Logging, or Wiretapping (CIPA Compliance)

No Surveillance Software: Web App Finder does not use session replay software, keystroke logging scripts, mouse-movement trackers, chat interception tools, or surveillance pixels (such as Hotjar, FullStory, Lucky Orange, or Meta Pixel). We do not record, intercept, or eavesdrop on your electronic communications, inputs, or browsing sessions.

This policy confirms our compliance with the California Invasion of Privacy Act (CIPA, Cal. Penal Code § 631), the Florida Security of Communications Act (FSCA), and related federal and state electronic privacy statutes.

7. Third-Party Service Providers

The infrastructure supporting Web App Finder includes:

  • GitHub Pages: Static website hosting and open-source submission pipelines.
  • Supabase: Cloud database provider used to store community votes, public comments, and private safety reports.
  • GoatCounter: Cookieless, open aggregate website analytics.

8. Children's Privacy (COPPA & Minor Protection)

Web App Finder is designed for general audiences and is not directed at children under 13 years of age. We do not knowingly collect, solicit, or maintain personally identifiable information from children under 13 in compliance with the Children's Online Privacy Protection Act (COPPA).

If you are a parent or legal guardian and believe your child under 13 has submitted personal information or comments to our site, please contact us via our GitHub repository and we will promptly remove the data.

9. Your Rights & Data Choices (GDPR & CCPA)

Because we do not require account registration, passwords, or personal profiles, we do not hold personal profiles linking your identity to your activity.

Under applicable privacy laws (such as the EU GDPR and California CCPA):

  • You have the right to clear local data from your device at any time.
  • You can remove any comment and vote you posted by clicking "Withdraw vote" on the app's details page.
  • If you have any questions or data requests, you can contact the project maintainer via our GitHub repository.

10. Statutory "Do Not Sell or Share" Declaration (CCPA / CPRA & Texas TDPSA)

We Do Not Sell or Share Your Personal Information: In accordance with the California Consumer Privacy Act (CCPA), California Privacy Rights Act (CPRA), and the Texas Data Privacy and Security Act (TDPSA):

  • Web App Finder has never sold, rented, leased, or disclosed any personal information to third parties in exchange for monetary payment or other valuable consideration.
  • We do not "share" personal information for cross-context behavioral advertising or targeted marketing.
  • We do not collect sensitive personal information, biometric data, or precise geolocation coordinates.
  • Because we do not engage in the sale or sharing of consumer personal information, we do not provide an opt-out mechanism or "Do Not Sell My Info" link, as no selling or cross-context sharing occurs.

For our terms and liability disclaimers, please see our Terms of Service & Legal Disclaimers.