Privacy
228.dev uses catalog search activity to improve search quality and decide which elements and pages to build. Search text is redacted before storage and linked to a monthly rotating pseudonym.
Search insights
We store the redacted search, selected filters, inferred catalog family, result count, returned item identifiers, response time, and MCP client name. Redaction removes common credentials, email addresses, phone numbers, URLs, UUIDs, and long identifier-like values. Redacted search events expire after 30 days. Aggregate counts that contain no search text may be retained to measure long-term catalog demand.
Catalog requests
A catalog request is submitted only after you confirm its capability, use case, native platforms, and optional notes. Contact permission is a separate choice and starts turned off. When you enable it, your signed-in account may be associated with the request so 228.dev can follow up.
Source delivery
Source claims record the selected catalog artifact, project, native platform set, and credit usage. Delivery returns only files from the approved runtime requested for that item. Preview HTML and CSS remain within the preview service.
Processors and access
Supabase provides authentication and database services. Vercel runs the 228.dev site and MCP endpoint. Catalog analytics and requests are available only to authorised 228.dev operators.
Deletion and questions
You can request deletion of contact-linked catalog requests or ask a privacy question by emailing hello@228.dev. Monthly pseudonyms are designed to prevent long-term linking of search activity to an account.