Libraries.dev

Privacy Policy

Last updated September 2026

This policy explains what data Libraries.dev collects when you use the site, create an account, or subscribe to Pro — why we collect it, who processes it on our behalf, and the rights you have over it. We collect as little as the product needs to work, and we never sell your data.

Who we are

Libraries.dev is operated by Jakub Antalik ("we", "us"). For anything in this policy — including data requests — contact jakubja@gmail.com. For visitors in the EU/EEA and UK, we act as the data controller for the personal data described below.

What we collect

Most of the site — browsing the libraries, trying the playgrounds, installing the free packages from npm — needs no account and collects no personal data. The data below applies once you sign in or subscribe.

  • Your email address — the anchor for your account and passwordless sign-in. You give it to us when you subscribe or sign in.
  • Billing details — handled by Stripe. We store your Stripe customer and subscription identifiers and your plan status; we never see or store your card number — it is entered directly on Stripe's hosted checkout.
  • Team membership — if you own or join a team, we store the team name, its members, roles, and pending invitations (invited email addresses).
  • Sign-in & access records — short-lived login tokens, active sessions, and an audit log of protected downloads and auth events. IP addresses in that log are stored only as a salted hash, never in the clear.
  • Studio agent requests — when you use the Agent tab in the Studio, the text you type, the current parameter values, and the recent turns of that conversation are sent to our AI provider to produce the answer. We also keep an anonymised copy of the text to improve the agent — see the next section for exactly what that means, and how to turn it off.

How we use it, and our legal basis

Under the GDPR, we rely on the following bases:

  • To provide the service you asked for (contract) — authenticate you, unlock and deliver the Studio and Pro content, manage your team, and process your subscription.
  • To send transactional email (contract) — magic sign-in links, team invitations, and payment receipts. These are not marketing; we don't send marketing email without your consent.
  • To keep the service secure (legitimate interest) — rate-limiting, abuse and fraud prevention, and the access audit log.
  • To meet legal obligations — e.g. retaining billing records for tax and accounting.
  • To improve the Studio agent (legitimate interest) — we keep one record per agent request containing the library, the outcome (applied, declined, rebuilt, error), a few counts, and the text of your request with personal details removed (email addresses, links, phone numbers, long numbers, @handles and key-like strings are replaced with placeholders) and cut to 300 characters. The record carries no user identifier, session, or IP address, so it cannot be linked to you or to your other requests. The agent's replies, your conversation history and any code it generates are not kept. You can turn this off at any time under Studio agent analytics on your account page, and we also honour the Global Privacy Control and Do Not Track browser signals — when off, the text is not stored at all.

Who processes your data

We use a small set of trusted providers ("processors") to run the service. They only process your data on our instructions, for the purposes below.

ProviderPurposeData
StripePayments & subscriptionsEmail, card details (entered directly with Stripe), billing & plan status
ResendTransactional emailEmail address, message content (sign-in / invite links)
CloudflareHosting, database & file storageAccount & team data, sessions, hashed access logs, Pro content delivery, standard web-server request logs, anonymised Studio agent records
AnthropicStudio agent (AI model)The text of your agent requests, the current parameter values and recent turns of that conversation — sent only when you use the Agent tab. Under Anthropic's commercial API terms this data is not used to train its models.

Each provider maintains its own privacy and security terms (Stripe, Resend, Cloudflare, Anthropic). We do not sell or rent your personal data, and we don't share it with advertisers.

Cookies

We use a single essential cookie — the session cookie — to keep you signed in. It is HttpOnly, Secure, and set only after you sign in; it carries no tracking data and expires when your session ends. We use no advertising, analytics, or third-party tracking cookies — so there is no cookie consent banner to click through.

How long we keep it

  • Account & team data — for as long as your account exists.
  • Sessions & login tokens — short-lived; login links expire in minutes, sessions in weeks.
  • Access & audit logs — kept only as long as needed for security, then pruned.
  • Anonymised Studio agent records — three months, then deleted automatically. Because they carry no identifier, they cannot be retrieved or deleted per person; turning the setting off stops new ones.
  • Billing records — retained as required by tax and accounting law, even after you cancel.

International transfers

We host in Cloudflare's EU region where possible, and our email region is the EU (Ireland). Some processors (e.g. Stripe) may process data outside the EEA; where they do, they rely on appropriate safeguards such as the EU Standard Contractual Clauses.

Your rights

If you're in the EU/EEA or UK, you can ask us to:

  • Access the personal data we hold about you, or receive a copy (portability).
  • Correct data that's wrong or out of date.
  • Delete your account and personal data (subject to billing records we must keep by law).
  • Object to or restrict certain processing.

Email jakubja@gmail.com and we'll action it. You can delete most account data yourself from your account. You also have the right to complain to your local data protection authority.

Children

Libraries.dev is a developer tool and isn't directed at children. We don't knowingly collect data from anyone under 16.

Changes to this policy

If we make material changes, we'll update the date above and, where appropriate, notify you by email. Continued use after a change means you accept the updated policy.