What Lobstify does with what you give it.
Lobstify is a queue that shows projects in order of how little they have been shown, and publishes the ledger that proves it. This page describes what that costs you in data, and what you agree to by publishing. It describes the software as it actually behaves; where a claim depends on code, the file is named.
What is stored about you
If you only read
No account, no profile, and no analytics or third-party trackers on any page. Two things are still recorded:
- A device fingerprint. A SHA-256 digest of your IP address and browser user-agent, truncated to 16 bytes. The address itself is never written down — only the digest (
db/rate-limit.ts). It exists to enforce the rate limits below and to stop a refresh loop inflating a project's public view count. - One row per project, per kind, per day, per device when you open a project or click through to it. Deduplicated by construction, so reloading a page changes nothing. These figures are public on each project page, and the fair queue never reads them.
If you sign in
- A one-way key derived from your email address with SHA-256 (
lib/identity.ts). This is what owns your projects. It cannot be reversed into your address. - Your email address, stored once, in the accounts collection only, because signing in with a password has no other way to find your account. It is never sent to another reader's browser and never shown on a page.
- Your display name, which you choose and can change.
- A password derivation, if you set one: PBKDF2-SHA256 with a per-account random salt (
lib/passwords.ts). Never the password. - Which providers have confirmed your address, if you used GitHub or Google.
What you publish
Projects, product updates, feedback and replies are public by intent, under the display name you chose. Votes are stored as a digest of the project and your device key, so a count exists without a record of who voted for what.
Cookies
Two, both strictly necessary, both first-party. There is no advertising, measurement or profiling cookie, which is why you are not asked to consent to any.
lobstify_session— proves who you are. Signed by the server,HttpOnly,SameSite=Lax,Secureoutside local development, 30 days.lobstify_oauth— ties one sign-in attempt to your browser so somebody else's callback cannot complete in your name. 10 minutes, deleted as soon as the attempt ends.
Your saved projects and dismissed hints live in your browser's own storage and are never sent to the server.
Who else sees it
- Vercel serves the site and processes requests.
- MongoDB Atlas stores everything described above.
- GitHub or Google, only if you choose to sign in with them, and only to confirm one verified email address. Nothing is sent back to them afterwards.
- Brevo delivers the emails that tell you somebody replied, and only then. It receives your address, the subject and the message. If you turn those emails off on your profile, or if this deployment has no mail configured, it receives nothing at all.
Nothing is sold, and nothing is shared for advertising. There is nobody to share it with: the site has no advertisers and no paid placement, which is also the reason the queue cannot be bought.
How long it is kept
- Projects, feedback and updates:as long as they are published. Withdrawing a project hides it from every listing but deliberately does not delete it, so the words other people wrote on it survive and yesterday's published fairness figures do not become retrospectively false.
- Rate-limit counters and reach rows: deleted once they can no longer affect anything (
db/moderation.ts). - Your inbox: the newest 200 notifications; older ones are dropped as new ones arrive.
- Answer credit: expires by leaving a 7-day window rather than by being deleted.
Your requests
You can change your display name and your password from your profile, and withdraw any project you published from your projects.
Two things the interface cannot do, for a structural reason rather than a missing button. Your email address is hashed into the key that owns your projects, so changing it would separate you from your work. And an account that vanished would leave published listings nobody can correct or withdraw. For deletion, or for a copy of what is held about you, write to contact@peekrapp.com.
Publishing here
By submitting a project or writing feedback, you agree that:
- it is yours to publish, or you have the right to publish it;
- it stays public under your display name, and withdrawing it hides it rather than erasing what others wrote in response;
- you will not use Lobstify to publish unlawful content, impersonate somebody, or manipulate placement — including by submitting the same project repeatedly or voting from multiple devices;
- feedback is for the maker's benefit. Abuse, spam and promotion disguised as feedback are removed.
Automated checks refuse link farms, promotional phrasing, shouting and duplicates before anything is stored (lib/moderation.ts), and per-device limits apply: 5 submissions and 12 pieces of feedback per hour. Reports are read by a human; nothing is taken down automatically.
What is not promised
Lobstify is offered as it is, without a warranty, and it can change or stop. The fairness claims are narrower than they may sound, and the audit page exists so you do not have to take them on faith: placement is derived from under-exposure, freshness, feedback need and rest, and vote counts are absent from that calculation. Being surfaced fairly is not a promise of attention.
What “verified” means
Verified means a provider — GitHub or Google — confirmed this maker's email address. It is not a review, a ranking or an endorsement, and it changes nothing about where the project sits in the queue. A project published from a password-only account carries no badge and is treated exactly the same by the fair order.
The three ways of signing in are not equal in this one respect, and the badge is the only place it shows. A password proves somebody knows a password; only GitHub, Google, or a hosting platform that authenticated the request confirms that the address belongs to whoever typed it. The state is recorded on the project when it is published, so a listing does not silently become verified afterwards.
Partnerships
partnership@peekrapp.com reaches whoever runs Lobstify.
This is not advertising. Placement in the queue is not for sale, and no arrangement changes it: the order comes from under-exposure, freshness, feedback need and rest, the calculation is published on the audit page, and there is no code path by which money enters it. If that ever changes, it will change on this page first.
Contact
- Your data — deletion, a copy of what is held about you, or anything about this page: contact@peekrapp.com. Say which you want; the reply will state exactly what was removed.
- Something wrong on the site — abuse, a listing that should not be here, or a page that does not work: support@peekrapp.com.
Written by the people who wrote the software, not by a lawyer, and it describes behaviour rather than reciting a template. If Lobstify grows past a side project, have it reviewed by somebody qualified — this page is accurate, which is not the same as sufficient.