Coming very soon

While you wait, you can use our extension.

Last updated 13 August 2026

Privacy Policy

Repcurate is a lookup tool for product listings and quality-control photos. It is built to work without knowing much about you, and this page describes exactly what it does know.

Who is responsible

Repcurate is operated by an individual, not a company. For anything in this policy - including access, correction or deletion requests - write to [email protected]. Requests are answered within 30 days.

What we collect

Three things, and nothing else.

  • Account data, if you create an account: your email address and a hash of your password. Never the password itself. If you sign in with Google, Discord or Reddit we receive the identifier and email that provider returns. Reddit does not release an email address, so accounts created that way are given a synthetic internal placeholder instead - it is not a real mailbox and we cannot reach you at it.
  • Server logs: standard request logs kept for security and debugging, including IP address and user agent, retained for a short period and not used to build a profile.
  • Product analytics, only if you turn them on. See below.

We do not ask for your name, address, phone number or payment details. Repcurate processes no payments.

What we deliberately do not collect

The URLs you paste never reach our servers as URLs. Pasted links are parsed in your own browser; only the platform name and the numeric item ID travel onward, as part of the page address you are then taken to.

There is no free-text search on Repcurate, so there is no search history. Analytics events are barred by design from carrying pasted URLs, item IDs, shop IDs, seller names or any text you typed.

Cookies

The website sets one cookie, and only after you sign in:

  • __Secure-better-auth.session_token - your sign-in session. Scoped to .repcurate.com so it works across the site and the API, HttpOnly (unreadable by scripts), Secure, SameSite=Lax. It contains a short-lived signed session record, cached for up to 60 seconds to avoid a database read on every request. It is strictly necessary: without it, signing in cannot work.

There are no advertising cookies, no tracking pixels and no third-party cookies. Our analytics does not use cookies at all. Full detail on Cookie Settings.

Analytics - off unless you say otherwise

We use PostHog, hosted in the European Union, to count how the product is used. It is opt-in: until you agree, the analytics code is never even downloaded to your browser. You can verify that in your browser's network tab.

When enabled, it is configured as narrowly as the tool allows:

  • No session recording or screen replay. Ever.
  • No autocapture - nothing is recorded because you happened to click it. Only the specific events listed below.
  • No user profiles. Events are anonymous and are not attached to your account, even when you are signed in.
  • Requests go to repcurate.com/ingest and are forwarded by our own server. Your browser never contacts PostHog directly, so PostHog does not see your IP address from the website.
  • State is kept in your browser's local storage, not in cookies, so it is never attached to network requests.

The complete list of events: page view (the route pattern, such as /item/[platform]/[itemId], never the filled-in address), URL pasted, URL resolved, URL rejected, item viewed, photo shoot opened, photo viewed, store viewed, install clicked, sign-up started, sign-in started, account viewed, and consent granted or revoked. Their properties are counts and fixed categories - how many photos, which platform, which button - never identifiers or text.

Turn it off any time on Cookie Settings or your account page. Turning it off also erases the analytics identifiers from your browser.

Photos load directly from third-party servers

This is the one place where another company sees you, and it happens whatever your analytics choice is.

QC photos are not copied onto our servers. They are shown from the forwarding agents' and marketplaces' own image servers - for example cbu01.alicdn.com, gw.alicdn.com, oss.acbuy.com, usimage.cssbuy.com and libcdn1.hahbuy.com. Most of these are operated in China.

When such an image loads, that operator's server necessarily sees your IP address and browser user agent, as it would for any image on the open web. We send no-referrer with every one of these requests, so they are not told which Repcurate page you were on. We do not control these operators and they are not acting on our behalf. If this matters to you, a content blocker or a VPN prevents it; the rest of the site works without the photos.

Where your data is held

Accounts and application data live on a server in the European Union. Analytics, when enabled, is stored by PostHog in the European Union. The image-server requests described above go wherever that image is hosted, which is generally outside the EU - that transfer is a direct consequence of displaying the photo and is the reason it is spelled out here rather than buried.

How long we keep it

  • Account data: until you delete your account, then removed.
  • Server logs: a short operational window, then discarded.
  • Analytics events: retained by PostHog under its standard retention, anonymous throughout.

Your rights

If you are in the EU or UK, the GDPR gives you the right to access, correct, export or erase your personal data, to object to processing, and to complain to your national supervisory authority. Our legal bases are: performance of a contract for account data, legitimate interests for security logs, and your consent for analytics - which you may withdraw at any time without giving a reason.

Exercise any of these by emailing [email protected].

The browser extension

The Repcurate browser extension is a separate piece of software with its own privacy controls and its own telemetry setting, found in the extension's options. Choices made on this website do not change the extension's setting, and the extension never records the pages you visit on marketplaces or forums.

On Reddit, when you open a post that the extension recognises as a reseller advertisement, it sends a non-identifying report: that post's public Reddit id and nothing else - not your identity, not an install id, not the subreddit, not what else you browse. Our server checks the post itself before hiding it for other users, and does not store your IP address with the report. Reports are sent in batches a minute or two later, never as you view them. This is on by default; you can turn it off in the extension's options under Privacy.

Google Sheets scanning - opt-in, per sheet

This only happens if you click "Scan this spreadsheet" on a Google Sheets page. Nothing is read automatically, ever.

If you click it, the extension asks Google for read-only, temporary permission to that one sheet via your own Google account (OAuth) - never write access, never access to any other file in your Google account. We read the sheet's cell links only, never other cell content, formatting, comments, or the sheet's title. Only the marketplace product links found - already-public URLs, the same kind you could paste into the extension yourself - are sent to our server, to run the same legitimacy check used elsewhere in the extension. The raw sheet content and the Google access token never leave your browser.

You can revoke this access at any time from myaccount.google.com/permissions. Chrome only - this feature has no Firefox equivalent.

Children

Repcurate is not directed at children under 16 and we do not knowingly hold their data.

Changes

If this policy changes materially, the date at the top changes with it and - where the change affects analytics - you will be asked for your choice again. Continuing to use the site after a change means you accept the updated policy.