Privacy Policy

Last updated 2026-09-29

Who we are

FoxPlug turns the work you ship into updates, draft posts, changelogs and pages. This page explains, in plain English, what foxplug.com and the FoxPlug app collect, where it goes and what you can do about it. It describes what our code does today.

Cookies and tracking on foxplug.com

When you first visit foxplug.com you see a banner with two choices: Accept All and Essential Only. Closing it with the X is the same as Essential Only. Your choice is saved in your browser (localStorage, key foxplug_cookie_consent) and applies to every page after that, including the app.

  • Google Ads tag (Google) — measures whether our Google ads work. The script loads from Google on foxplug.com with every consent signal set to "denied". Until you press Accept All it sets no cookies and Google receives only consent-denied, cookieless signals. After Accept All it may set advertising cookies such as _gcl_au, and Google may set its own cookies. We send Google the page address with only ad-click and utm parameters kept (private link codes in the address are replaced), never your email.
  • Microsoft Clarity (Microsoft) — page analytics on our marketing pages. It loads only after you press Accept All. It sets its own cookie (such as _clck), and Microsoft sets its own cookies too.
  • PostHog (PostHog, Inc., US) — product analytics on foxplug.com and in the app (which pages are read, which buttons are pressed). It loads only after you press Accept All. Session recording is switched off in our code, so we do not record or replay your session, and we do not tell PostHog who you are. It keeps its own cookie (named ph_ followed by our project key).
  • Essential Only means no advertising cookies and no optional analytics: the Google tag stays in consent-denied mode, and Clarity and PostHog do not load. If you later choose Essential Only in another tab, PostHog stops collecting.
  • Global Privacy Control and Do Not Track are honoured. If your browser sends either signal, the Google tag, Clarity and PostHog do not load at all and no banner is shown. The same applies when one of our pages is shown inside another site's frame.
  • To change your choice later, clear this site's data in your browser (or remove the foxplug_cookie_consent entry). The banner will appear again.

Our own first-party visit record

Whatever your banner choice, foxplug.com keeps one simple record per browser session in our own database (not an analytics company): the page you landed on (path only), the site that sent you (its address, but never our own or a sign-in page), any utm_source and utm_medium in the link, and a random session id. It also notes which link into the app you clicked, which way you started signing up or in (email, email link, LinkedIn or Google) and, if the sign-up failed, the error message shown (never your email or password), and whether you came from an ad (paid, organic, direct or other). The Google ad click id (such as gclid) is added to this record only if you pressed Accept All. No IP address and no email are stored with it. This record is also kept when your browser sends Global Privacy Control or Do Not Track; it then never includes an ad click id. Your browser keeps the first landing (localStorage, key lcnc_ft) so that, if you sign up, your account records which channel brought you.

Cloudflare serves foxplug.com and shows us request-level traffic from its own logs; no Cloudflare script runs in your browser. Some pages load open-source code from public code servers (cdn.tailwindcss.com and unpkg.com), which, like any server you load a file from, see your IP address.

Trying FoxPlug without an account

  • "Show me my update": you paste a public GitHub repo or changelog address. We read it through GitHub's public API (or the public page) and write an update and draft posts. The result is kept with a one-way hash of your IP address (for rate limits) and a private link that works for 7 days. After 7 days a daily cleanup removes the result, the link codes and the IP hash; only counts remain.
  • "Email me this result": pressing it sends one email, through Resend, with the private link. We do not store your email address: only a salted one-way hash of it (to stop abuse) and the time you pressed the button, and those rows are deleted after 7 days. You are not added to any list and we do not email you about it again.
  • Launch kit from your site address: we read the public pages of the address you enter to write a headline, captions and visuals. A launch video, if made, is rendered on our video servers.

If you create an account

  • Sign-in: email and password, Google sign-in, or LinkedIn sign-in, handled by Supabase Auth. LinkedIn sign-in gives us your name, profile photo and email from LinkedIn, and nothing else; it does not let FoxPlug post. We store your email and your projects, drafts, milestones, pages and settings in our Supabase database.
  • Payments: handled by Stripe. We receive your plan and subscription status; we never see or store your full card number.
  • Emails to you: FoxPlug does not send you digests, alerts or reminders unless you switch that kind of email on (each is off by default). Sign-in emails such as password resets come from Supabase Auth.
  • "Watch" features check public sources about the project you set up: your own site's public pages (for new pages), competitor pages you add, and, once you switch them on, public mentions, team pages and funding pages. What they find is shown inside the app.

GitHub and other connected services

GitHub. You connect GitHub by approving FoxPlug on GitHub's own screen. FoxPlug then reads your repositories' names and details, commit messages (with author, date and link), releases and their notes, and merged pull request titles and descriptions, from your most recently active repositories. It adds one push webhook to a repository so new pushes reach FoxPlug. It never reads or stores your source code files and never changes your code. GitHub's screen asks for repository access because GitHub needs that permission to read commits on private repositories and to add the webhook; FoxPlug uses it only for those reads and the webhook. The access token is kept in an encrypted secret store (Supabase Vault), not in a plain table. You can remove FoxPlug's access anytime in your GitHub settings under Applications.

Posting to LinkedIn. LinkedIn asks your permission to let FoxPlug publish on your profile only when you press "Connect LinkedIn to post" on a draft. The access LinkedIn then gives (your LinkedIn token) reaches your browser once, as you come back from LinkedIn. The app sends it straight to our server, where it is kept in an encrypted secret store (Supabase Vault) that the app cannot read, and then replaces its own sign-in record so your browser does not keep the token. It is used for one thing: publishing a post you have previewed, and only at the moment you press "Post now". FoxPlug never posts to LinkedIn on its own or on a schedule. LinkedIn access lasts about 60 days; after that the app asks you to reconnect. "Disconnect LinkedIn posting" deletes our copy at once, and you can also remove FoxPlug in your LinkedIn settings.

Other services you choose to connect (for example X, LinkedIn, Bluesky, Mastodon, YouTube, Product Hunt, your newsletter tool, Notion, Trello, Vercel, Stripe or a funding page): we use the access you grant only for the features you use, such as reading your activity to find milestones or sending a post you approved. Nothing is posted anywhere until you approve it and press send. You can disconnect any service at any time.

Your changelog subscribers: if people subscribe to your changelog, the confirmation email goes out through your own email provider, not from FoxPlug.

Service providers we use

  • Cloudflare hosts and serves foxplug.com.
  • Supabase hosts our database, sign-in, secret store and server functions.
  • Anthropic (Claude) writes updates, drafts and pages from your project's information. OpenAI produces voice narration for videos.
  • Railway runs our video rendering servers.
  • Stripe handles payments. Resend sends the few emails FoxPlug itself sends.
  • Serper (search results), Brandfetch and unavatar help us find a company's public logo and public mentions.
  • Google (Ads tag), Microsoft (Clarity) and PostHog, as described above.
  • The help chat ("Foxy") on foxplug.com is GetFoxChat, our sister product, served from Vercel; what you type there is handled as its privacy page describes. Some research and press features run on MentionFox, another sister product.

We do not sell personal data.

Keeping and deleting data

We keep your account data while your account is in use. The only automatic time limits are the ones stated on this page (the 7-day try-it result and its email rows). To ask for a copy of your data, a correction, or deletion, email privacy@foxplug.com.

Contact

Questions about privacy? Email privacy@foxplug.com.