Privacy Policy.
The short version: we keep what running a membership actually requires, we do not sell any of it, and you can have all of it deleted by emailing us. Payments are handled by Creem, so we never see your card details. Last updated September 11, 2026.
What this site is
activebuilders.dev is the home of the Active Builders community. You create your member account here; the one-time membership payment is processed by Creem, our merchant of record, and the community itself lives in a private Discord server.
What we store about you
Your account. Your name, email address, a securely hashed password (we never see or store the plain text), when you signed up, your membership date, and, if you connect it, your Discord user id. If you sign in with Google we also receive and store your Google profile picture URL. All of this lives in our own database on our own server.
Sign-in records. Each active session stores your IP address and browser user-agent string. We use these to keep you signed in and to investigate abuse or suspicious logins. Sessions expire after 7 days, and an expired session record is deleted within the hour.
Connected accounts. If you sign in with Google or connect Discord, we store the access tokens those services issue us, so we can add you to the Discord server and, if you ask, fetch your Discord profile picture.
Your profile. If you fill one in: your bio, your website, your social profile links, and your uploaded photo. See section 06 for what becomes public.
Emails we send you. We keep a copy of every email we send to you, including its contents, so we can confirm what was sent and debug delivery problems. Password reset and verification links are stripped out of that copy before it is stored. Only site admins can read this log.
If you email us, we receive whatever you put in that email.
Sign-up notice. When an account is created we send ourselves a short notice with the name and email address entered, the IP address it came from, a rough location and network name for that address (looked up once with ipwho.is, from our server), and the browser used. It exists to tell real sign-ups from automated ones. It is deleted when the account is deleted, including when an unconfirmed account is removed automatically.
Cookies and analytics
A session cookie keeps you signed in. It is httpOnly, restricted to this site, and lasts 7 days. A second cookie remembers your light or dark theme preference for a year. Both are set by us, and there are no advertising or tracking cookies on this site.
For traffic stats we use Umami, which we host ourselves on our own server, so those numbers are not shared with an analytics company. It sets no cookies and records aggregate page views, referrers, rough country, and device or browser type. It does not record query strings, does not track you across sites, and does not build a profile of you.
The sign-up, log-in and password forms are protected by Google reCAPTCHA, which tells bots from people without a puzzle. On those pages Google's script runs in your browser, may set Google's own cookies, and receives your IP address and browser details under Google's privacy policy. It does not run anywhere else on the site.
Third parties
Pages load fonts from Adobe Fonts (Typekit) and icons from Font Awesome via their CDNs. Your browser requests those files directly, so those providers may receive your IP address and request details under their own privacy policies.
We use Sentry to catch application errors. It is configured not to send personal data: error reports carry stack traces and technical context, not your IP address, your cookies, the contents of your requests or your email address, and links that carry sign-in tokens are stripped before a report leaves the browser or the server.
If you use the autofill button in the project editor, the text of the website you named is sent to OpenAI so a description can be drafted from it. Nothing about you is sent, only the page you asked us to read, and only when you press the button.
If you ask us to pull in your Gravatar, we send a one-way hash of your email address to Gravatar (Automattic) to look it up. This happens from our server, not your browser, and only for the profile photo feature. If you never use it, nothing is sent.
Payments, Discord, and other platforms
Membership and sponsorship checkouts run on Creem, our merchant of record. Creem collects your billing details and processes the payment; we receive your email and order details (so we can unlock your membership) but never your card number.
If you connect your Discord account, we receive your Discord user id and use it to add you to the private server. Discord also tells us the email address on that account as part of connecting; we use it only to confirm the account is verified and do not store it. We keep the access token Discord issues, encrypted, so we can fetch your profile picture if you ask for it. Anything you share in Discord or on X is governed by those platforms. Please review the privacy policies of Creem, Discord, and X for how each handles your data.
We use these details to run the community, fulfill sponsorships, reply to you, and send the occasional important update. We do not sell your information.
Your public profile
The members directory at activebuilders.dev/members is public, and a selection of member photos also appears on our home page. You are not listed unless you turn it on yourself: the setting is off by default and lives under Your profile in the members area.
When you turn it on, your name and photo, bio, website, and social links become visible to anyone, including search engines, and are published in a machine-readable format that search engines and crawlers can index. Your email address is never shown. Turning the setting off removes you immediately, though search engines may take time to drop what they already cached.
Projects are published the same way and switched on one at a time. A project you publish gets its own public page carrying its name, description, images, links and your name as its author, and is listed at activebuilders.dev/projects. Projects you have not published are visible only to you. Unpublishing or deleting one takes its page down immediately. When you add a project with a web address, our server fetches that site once for its icon and once to photograph its homepage, unless you supplied your own; a published project that still has no screenshot gets one the same way. An icon served as an SVG is drawn into a picture by a browser running on our server, which loads nothing else while it does. Both are stored like images you upload and you can delete them at any time.
The first time you save a profile without a photo, we try once to find one from your connected Discord account, then from Gravatar. You can replace or remove that photo at any time. Photo files themselves are served from an unguessable URL and are not otherwise access-controlled, so treat anything you upload as public.
Keeping and deleting your data
We keep your account data for as long as your account exists. Sign-in sessions expire after 7 days and are deleted soon after. Beyond that we do not delete member accounts on a schedule, because a lifetime membership is meant to outlast one.
Two things sit outside the database. Our server keeps application logs, which record events by account id rather than by email address and are rotated by the system. And a nightly backup of the server exists to recover from a failure; it can hold a copy of your data for a period after you delete your account, and is never used for anything else.
There is one exception, and it works in your favour. If an account is created with your email address but the address is never confirmed, we delete that account automatically after 5 days. Bots sign real people up to sites they have never heard of, and we would rather not sit on an address nobody asked us to hold. A verified account is never removed this way, and neither is one that has paid for membership.
You can change your name, email, password, and profile yourself from the members area. To get a copy of your data, or to have it deleted, email support@activebuilders.dev and we will take care of it. We aim to action deletion requests within 30 days.
Deleting your account removes your account record, your sign-in sessions and their IP addresses, your connected-account tokens, your profile, your projects and their images, any personal access keys, and the sign-up notice we sent ourselves. Two things survive on purpose: our payment records at Creem, which we are required to keep for tax and accounting, and a stripped-down line in our email log recording that a message of a given type was sent on a given date, with the contents removed and your address replaced by a keyed fingerprint, so we do not accidentally email you again. That fingerprint cannot be turned back into your address without our server key. Content you posted in Discord or on X is managed on those platforms.
Children
Active Builders is not directed to anyone under 16. If you believe a child has provided personal data, contact us and we will help get it removed from the relevant platform.
Changes
We will update this page when our practices change. The date at the top reflects the latest version.
Contact
Questions about privacy go to support@activebuilders.dev.