Directory Policy
Privacy Policy
What nTropi processes for accounts, catalog contributions, ownership claims, browser tools, and analytics.
Last updated: August 31, 2026.
Member Accounts
When member registration is enabled, nTropi stores your name, email, password credential in hashed form, email-verification state, account status, sessions, and security timestamps. Verification and password recovery links are time-limited. Public signup remains disabled on the production site until the Release 2 gate, but the same controls are available in local and preview environments for testing.
Submissions and Ownership Evidence
Drafts, listing recommendations, owner updates, alternative rationales, private draft images, moderation decisions, and audit history are kept to operate the contribution workflow. Ownership evidence can include a domain email relationship, DNS or website token result, repository evidence, or free-form supporting information. Claim evidence is not published and is restricted to the claimant and authorized internal reviewers. Transactional emails never include that evidence.
A published listing may identify that information was community submitted, but nTropi does not publish a member email address or private evidence. Any future public member attribution will be shown clearly before it is introduced.
Reviews, Responses, and Reports
nTropi stores review text, four criterion scores, their normalized average, author and listing identifiers, status, and timestamps. Public pages show only visible reviews with the member's display name. Owner responses are stored with their author, status, and timestamps and are public only while visible. Hidden and removed content remains retained for moderation integrity but is excluded from public HTML, loader data, structured data, aggregates, and rankings.
Content reports store a controlled reason, optional details, reporter, target, status, assignment, decision metadata, and timestamps. A reporter can see their own report and outcome. Report details, internal moderation notes, and other reporters' information are restricted to authorized moderators and are never included in public pages or email.
Browser Tools and Local Storage
Most developer tools run in your browser. A tool may store preferences or working state in local storage on your device. Unless a tool clearly says otherwise, that working content is not uploaded to nTropi.
Hosting and Security Logs
Cloudflare processes ordinary request metadata needed to deliver and secure the site, which can include an IP address, request time, browser information, requested route, and response status. nTropi does not add user IDs, fingerprints, or raw full referrers to catalog analytics.
Abuse Prevention
Authentication and contribution requests use rate limits and Cloudflare Turnstile. nTropi stores fixed-window counters keyed by an authenticated user or a secret-keyed hash of a normalized network address; raw network addresses are not stored in those counters or member session records. CAPTCHA tokens are validated server-side and recorded only as one-way hashes long enough to prevent reuse. Cloudflare may process network data to provide hosting, email, and CAPTCHA services under its own policies.
Analytics
Umami receives page views. When configured, Google Tag Manager and Google Analytics also receive page views and limited catalog interactions: result clicks, outbound-link types, filter use, query length, result count, and whether a search returned no results. Raw catalog search text is not sent. Query length and counts are bounded, and no user identifier is attached by nTropi. Google may process device or cookie information according to its own configuration and policies.
Editorial Operations
Automated link checks run as an editorial operation, never during a visitor request. They store the checked URL, timestamp, response class, final URL, and failure reason so editors can review stale or broken sources. They do not record visitor activity.
External Sites
Listing and source links lead to independent websites. Those operators receive the normal information sent by your browser and apply their own privacy policies. nTropi does not control their collection practices.
Suspension, Deletion, and Retention
Accounts may be suspended to protect the service. You can request correction or deletion through the contact below. Some moderation, ownership, review, report, moderation, audit, abuse-prevention, and published-catalog records may be retained where needed for integrity, security, legal obligations, or to explain prior editorial decisions. Revoking ownership removes active privileges without erasing the historical decision.
Contact
Privacy questions and correction requests can be sent to privacy@ntropi.app.