Privacy

Tablif reads what software products say on their own pages and quotes it. This page says what we record about you while you use the site, why, where it goes, and how to make us delete it. It describes what the code does today, not what we intend to do later.

Who is responsible

Tablif, reachable at emrctak@gmail.com. One person runs it. That address is the one to write to for anything on this page, and it reaches a human rather than a queue.

If you only visit

You do not need an account to read the site, and we do not ask for one. We still keep a log of page views so we can tell which pages get read. It is written by a script in your browser, so it records people rather than crawlers.

Data recorded for visitors without an account
WhatWhyWhere it goesHow long
Pages you open, and clicks on links that leave the siteTo see which pages are actually read, and which of our outbound links get used.Our own database, on our own server.Kept indefinitely today. See the note below.
Your IP address, in fullIt arrives with every request. We store it alongside the page record.Our own database. Not shared.Kept indefinitely today. See the note below.
Browser user agent, and the page that referred youTo separate bots from people, and to see where visitors arrive from.Our own database.Kept indefinitely today. See the note below.
A random visitor id in a cookie named tvSo a series of page views can be read as one visit instead of unrelated hits.Our own database. The cookie is httpOnly, so page scripts cannot read it.Cookie expires after 1 year.

If you make an account

Data recorded for account holders
WhatWhyWhere it goesHow long
Email addressIt is your login, and it is how an account is recovered.Our own database.Until you ask us to delete the account.
Password, hashed with bcryptTo sign you in. The original password is never stored and we cannot read it.Our own database.Until you ask us to delete the account.
Anything you fill in yourself: display name, bio, website, avatarBecause you chose to put it on your profile.Our own database. A profile is public.Until you remove it or delete the account.
What you post: submissions, comments, follows, watchlistsIt is the content of the site.Our own database. Most of it is public by design.Until you remove it or delete the account.
Which browsers have signed into your accountTo connect a visit to an account after sign-in, and to spot abuse.Our own database.Until you ask us to delete the account.

You can sign in with Google instead of a password. If you do, Google tells us your email address and your name and picture, and we store those. We never see your Google password. Google's own handling of that sign-in is covered by Google's privacy policy, not this one.

Who else gets your data

Two companies, and no one else. Google, for Analytics and for the Google sign-in button. And Teknosos, the Turkish hosting company we rent the server from.

That server is physically in Turkey, which is outside the EEA. If you are in the EU, the EEA or the UK, this means your data is held in a country without an EU adequacy decision. We are saying so plainly rather than leaving it out: it is the kind of detail a privacy policy exists to disclose.

We do not sell data, we do not share it with advertisers, and there is no ad network, no marketing pixel and no third party CRM on this site. This is not only a promise: the site sends a Content Security Policy that blocks the browser from contacting any host other than ours and Google's. Adding a tracker would mean changing that header, in public, in the page source.

Analytics, and where we ask first

Google Analytics is the one third party that sets a cookie in your browser. If you are in the EU, the EEA or the UK, a banner appears and nothing is measured until you accept. Elsewhere it starts on, which is how most sites in this category work. Either way you can turn it off for good with the Cookies link at the bottom of every page, and rejecting always overrides your location. Every cookie is listed here.

Our own page log described above is separate from this. It is first party, it never leaves our server, and it runs whether or not you accept the Google cookie.

How long we keep it

Account data stays until you delete the account. The page log is deleted automatically after 90 days: every night we remove visit records older than that, including the IP addresses, and the record of which browsers signed into which account goes with them. Nothing in that log is older than 90 days.

One caveat we would rather state than hide: the database is backed up nightly and those backups are kept for 14 days. So a deleted row can survive in a backup for up to two weeks after it leaves the live database. If you ask us to delete your data we delete it from the live database immediately, and the backups age out on their own.

What you can ask us to do

Write to emrctak@gmail.com and ask for a copy of what we hold on you, a correction, or deletion. You can ask us to stop logging your visits. If you are in the EU, the EEA or the UK these are rights under the GDPR; if you are in Turkey they are rights under KVKK. We answer within 30 days. You do not need to explain why, and asking costs nothing.

To delete your own account data yourself, the fastest route is to remove what you posted and then write to us for the rest. There is no self-serve delete button yet, and we would rather say that than imply one exists.

Children

The site is a directory of business software. It is not aimed at children and we do not knowingly keep data from anyone under 16.

When this changes

If we start collecting something new, this page changes on the same day as the code, not afterwards. Last measured against the running code on 13 August 2026.

Cookies · How we read products · About