Privacy

last updated 2026-08-09 · consent wording version 2026-08-v1

This is the whole policy. It is short because the site does little: it ranks tools by votes, and it emails a weekly rundown to people who asked for one.

Download or delete your data  ·  Unsubscribe from the weekly rundown

Who is responsible

Actually Good Tools is operated by DevOpser LLC. For the data described here, DevOpser LLC is the controller.

DevOpser LLC
PO Box 1674
Issaquah, WA 98027
United States
privacy@devopser.io

What we collect, and why

If you vote

A counted vote holds the tool, an optional note you wrote, and one identifier: your account id if you were signed in, or the SHA-256 hash of your email address if you confirmed by code. Your address is not stored in readable form next to a counted vote. Votes cast before email verification existed carry an older, random pseudonym instead; those stay valid.

While a vote is waiting for its code we hold rather more, briefly: the tool, your note, your email address, a hash of the 6-digit code (never the code itself), your IP address and your browser’s user-agent string. That row is deleted within 24 hours whether you confirm or not.

If you tick the newsletter box

Your email address, the exact consent wording that was on screen, its version number, the time you ticked the box, the IP address and user-agent at that moment, and a single-use confirmation token. We then send you a confirmation link, and we record the time you opened it. That last one is what makes it a confirmed (double) opt-in — it is our proof you asked, not just our word for it.

Where that link arrives depends on where you ticked the box. Tick it while confirming a vote and the link comes in an email of its own, kept apart from the email carrying your 6-digit vote code. Tick it on the submission form and the link sits at the end of your submission receipt, in a section of its own — one email instead of two, and the receipt says plainly that you are not subscribed until you open it.

Until you open that link you are not on the mailing list: nothing is sent to you, and your address is not passed to the CRM that sends the rundown. Ignore it and the record is deleted automatically after 30 days.

When you do open it, we send you the rundown as it stands that day as your first issue, so a Tuesday sign-up is not six days of silence. That one is sent directly by us over Amazon SES rather than through the CRM, and it carries the same one-click unsubscribe and postal address as every other issue. After it, you are on the ordinary Monday cadence.

If you make an account

Your email address, a hash of your password (or your Google sign-in identifier if you used Google), and your multi-factor settings if you turned them on. Tools you submit are stored with your account against them.

Consent records

Every time consent is granted, withdrawn, or data is erased, we append a row to a log that is never edited and never deleted on withdrawal: the address, what happened, what it was for, the wording and version, the time, the IP address and user-agent. Keeping it is the only way to show later that we had permission at the time.

Ordinary server logs

Our hosting produces standard web-server logs — IP address, the request, the time — used to run and secure the site and nothing else.

Lawful bases

Under Article 6 of the GDPR:

Confirming a vote never subscribes you to anything. The two are deliberately kept apart, because Art.7(4) does not allow consent to be bundled into something you came here to do.

Cookies

There are two, both strictly necessary, and neither is used for tracking:

Both exist only to deliver something you asked for: staying signed in, and one person getting one vote. Neither feeds advertising, analytics or profiling, and no third party can read either. Strictly necessary cookies do not require consent, so this site has no cookie banner and nothing for you to consent to.

Clearing agt_voter simply means you verify by email again. It never earns you a second vote on the same tool — the uniqueness check is on the email hash, not the cookie.

How long we keep it

Who else touches it

That is the complete list.

Where the data lives

Everything is hosted in the United States. If you are in the UK or the EEA, your data is transferred there. AWS’s data processing addendum incorporates the European Commission’s Standard Contractual Clauses; the CRM is not a third party at all — it is run by DevOpser LLC on the same infrastructure, under this same policy.

Links out to other sites

Some links to the tools we list are affiliate links: if you sign up after following one, the company pays us a commission. Those links are labelled affiliate link on the page, and the link text is always the tool’s real domain, so you can see the destination before you click. They earn us money; they buy no placement, and the ranking is votes only — the about page sets that out in full.

What this means for your data: an affiliate link is an ordinary link to the company’s own site, carrying a code that tells them we sent you. Following one sends nothing about you to anyone — we do not add an identifier, we do not log the click, and nothing is loaded from the affiliate network while you are on this site. Once you arrive on the other company’s site you are on their site, under their privacy policy, and they will typically set a cookie of their own to remember the referral. Not clicking means none of that happens.

What we never do

Your rights, and how to use them

If the GDPR applies to you, you have the right to access your data, to have it rectified, to have it erased, to restrict or object to our processing of it, to portability — a copy in a machine-readable format — and to withdraw consent at any time. Withdrawing consent does not undo anything we lawfully did before you withdrew it.

Those pages ask you for an emailed code first. That is not an obstacle — acting on an address nobody has proved they control would let anyone download or delete a stranger’s data.

Complaints

If you think we have handled your data badly, tell us first at privacy@devopser.io — it is usually the fastest way to fix it.

You also have the right to complain to a supervisory authority. In the EEA that is the data-protection authority where you live, where you work, or where the problem happened. In the UK it is the Information Commissioner’s Office.

Changes to this page

If what we do with data changes, this page changes and the date at the top changes with it. The consent wording carries its own version number, and we store the exact text you were shown at the moment you ticked the box — so a later rewording can never be applied backwards to you.