Independent directory, limited data collection
Everything Is A Plugin (EIAP) is an independent community directory, not an official DeepSeek service. Browsing is public; an account is required only to submit a plugin. The site has no payments or advertising and uses Google Analytics and Plausible to understand traffic.
Scope and current status
This policy covers everythingisaplugin.dev. This policy describes the current MVP implementation, not the separate practices of a listed plugin, GitHub, npm, Cloudflare, Google, or another linked service.
EIAP is a discovery layer. It stores directory metadata and links to original sources, but it does not host or distribute plugin packages.
Information we collect
Browsing does not require an account. EIAP uses Google Analytics and Plausible to measure visits and understand how the directory is used. Google Analytics may set a first-party _ga cookie and process information such as session activity, approximate location, and browser or device details. The Plausible-based tracker is designed to provide aggregate measurement without cookies.
If you sign in with GitHub or Google, EIAP receives a provider account identifier, display name, profile image URL, provider username where available, and email address and verification status where the provider supplies them. EIAP does not request access to private repositories, repository write access, or Google Drive. Provider access tokens are used only during the sign-in callback and are not stored.
When you submit a plugin, EIAP stores your account identifier, the public repository URL, an optional contact email, submission status, and public GitHub metadata such as owner, name, description, and star count.
Messages sent to an EIAP contact address are forwarded by Cloudflare Email Routing to the operator’s existing mailbox. Cloudflare and the destination mailbox provider may process the sender address, message headers, message content, and delivery metadata so the message can be delivered and answered.
Cloudflare may process ordinary technical request data needed to deliver and protect the site, such as IP address, request URL, device or browser information, timing, and security signals. That infrastructure-level processing is governed by Cloudflare’s own policies.
How information is used
EIAP uses analytics information to understand aggregate traffic, identify useful pages, diagnose problems, and improve the directory. Account and submission information is used only to authenticate users and to operate, review, secure, and improve the directory.
- Validate that a submitted GitHub repository is public and reachable.
- Create and moderate a plugin-directory record.
- Detect duplicate, abusive, misleading, or malicious submissions.
- Use an optional email only when follow-up about that submission is necessary.
Storage, retention, and security
Account, OAuth identity, hashed session, and submission records are stored in Cloudflare D1. Session cookies expire after 30 days and can be revoked by signing out. OAuth identity records and moderation records are retained while needed to operate and protect the directory; you may request correction or deletion using the contact channel below. Public repository metadata may remain in the catalog while a listing is active.
EIAP uses reasonable technical and organizational safeguards, but no internet service or storage system can guarantee absolute security. Do not include passwords, API keys, private repository details, or other sensitive information in a submission.
Sharing and sale
EIAP does not sell or rent submission data. Information may be processed by infrastructure providers as required to run the service, disclosed when legally required, or used to investigate security and abuse.
Public repository information is public by nature and may appear on the directory page, in search engines, and in cached copies. An optional submission email is not intended for public display.
GitHub, npm, Cloudflare, and external links
EIAP uses GitHub and Google for optional OAuth sign-in, links to GitHub repositories and npm package pages, uses Cloudflare infrastructure, and loads analytics services from Google and a Plausible-based endpoint at data.page-views.com. When you visit or use those services, their terms and privacy practices apply independently. EIAP does not control their collection, retention, or security practices.
Your choices and requests
You may browse the public directory without signing in. You may choose GitHub or Google when an account is needed, omit the optional submission email, sign out to revoke the current session, and request correction or deletion through the contact address below. You can limit analytics by blocking third-party scripts or cookies in your browser and may use Google’s Analytics opt-out controls where available.
For privacy questions or requests to correct or remove directory information, email the address below. Please include only the information needed to identify and handle the request.
Policy changes
This policy may change when the directory adds features, vendors, or a formal operator contact. Material changes will be posted on this page with a revised effective date. Continued use after an update is subject to the revised policy to the extent permitted by law.