Effective Date: October 6, 2026

Privacy Policy

TLDR: The security and privacy of your data is our highest priority. We collect only what we need to run your account and packages, we never sell your data or share it for anyone else’s purposes, and we use it only to provide the Service to you. Our website also uses a Google tag to measure our own ads and site usage, and Sentry to find errors. You can delete your account at any time.


This Privacy Policy explains how pckgs.io (“we”, “our”, or “us”) collects, uses, shares, and protects your information when you use our website and cloud storage services for hosting and distributing software packages — including Unity, Dart, and npm packages, with additional ecosystems added over time (the “Service”). We are committed to transparency and safeguarding your privacy.


Our Commitment to Your Privacy

Protecting the security and confidentiality of your data is our highest priority. Specifically:

  • We never sell your data. We do not sell, rent, or trade your personal data or the contents of your packages, to anyone, for any reason.
  • We do not share your data for anyone else’s purposes. We share data only with the service providers listed under “Service Providers and Data Sharing”, solely so they can operate the Service for you, and they may not use it for their own purposes. The only other exceptions are a legal obligation or protecting the safety and security of our users and the Service.
  • We use your data only to provide the Service. We use account data to run your account, and packages to store and deliver them to the people you authorize. We do not use either for advertising, profiling, data mining, or to train artificial intelligence or machine learning models.
  • We do not look at your private packages. Our systems process package files automatically to deliver them: when you publish a package, we automatically read its metadata and documentation files (such as README, LICENSE, and CHANGELOG) so they can be shown on the package page. For private packages, these pages are visible only to the people you authorize; for public packages, they are visible to everyone. Our team does not open private package contents except where you ask us to for support, where necessary to investigate abuse or a security incident, or where the law requires it.

Information We Collect

We collect the information needed to provide and manage the Service:

  • Email address (required). Used to identify your account and to contact you about it.
  • Name (optional). Your first and last name, as provided by you or by your sign-in method.
  • Profile image (optional). Only an image you upload yourself. We never import your profile picture from Google or any other sign-in provider.
  • Account and organization data. Your organizations, memberships, invitations, access tokens, and the packages and files you upload.
  • Technical data. Standard request data such as IP address, browser type and pages visited, which reaches us through our infrastructure provider, our error monitoring, and the analytics described below.

Payments are handled by our payment provider (see “Service Providers and Data Sharing”); we do not collect or store payment card details ourselves.


Information We Receive From Google

You can sign in to pckgs.io with your Google account. This section describes what Google user data the Service accesses, how we use it, and how we protect it.

What we access. We request only the basic sign-in scopes openid, https://www.googleapis.com/auth/userinfo.email, and https://www.googleapis.com/auth/userinfo.profile. Through them we receive an ID token from Google containing:

  • Your email address and whether Google has verified it
  • Your name (given name and family name)
  • A unique Google account identifier

We do not request or access your Gmail, Google Drive, Calendar, Contacts, or any other Google service or data. The basic profile scope also makes Google include your profile picture address in the sign-in response, but we do not read, store, or display it.

How we use it. We use this information only to authenticate you, to create and manage your pckgs.io account, and to display your name on the Service. We do not use it for any other purpose.

How we store it. Your email address and name are stored in our database as part of your account. The Google ID token is passed to Google Identity Platform, the authentication service we use, which creates and maintains your sign-in identity. We do not request offline access from Google, so no Google refresh token is issued to us, and we do not store any Google access token.

How we share it. We do not sell, rent, or transfer Google user data to anyone other than the service providers listed under “Service Providers and Data Sharing”, and only so they can operate the Service for us. We do not use it for advertising, analytics, profiling, credit or lending decisions, or to train artificial intelligence or machine learning models, and we never sell it to data brokers or information resellers.

Google API Services User Data Policy. pckgs.io’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Revoking access. You can remove pckgs.io’s access to your Google account at any time at myaccount.google.com/permissions. You can also delete your pckgs.io account and the data we hold, as described under “Data Retention and Deletion”.


Cookies and Similar Technologies

Essential cookies. We use cookies to keep you signed in. They store your access token (which carries your user ID, email address and name) and your refresh token. They are marked HttpOnly and Secure, so scripts running in your browser cannot read them, and they are strictly necessary for the Service to work.

Consent cookie. We store your cookie choice (“Accept all” or “Essential only”) in a first-party cookie named consent for 180 days, so we do not ask you again on every visit.

Advertising and analytics (Google Tag). On our website we use a Google tag (Google Ads / Google Analytics) for two purposes only: to measure how effective the advertisements we run are, and to collect analytics about how visitors use the website. This tag sets cookies and sends data such as pages visited, referring source, device and browser information, and IP address to Google. We do not pass your account information, such as your email address or name, to this tag, and we do not use Google user data received through sign-in for advertising or analytics. Google processes this data under Google’s Privacy Policy; see also how Google uses information from sites or apps that use its services. The tag only loads if you choose “Accept all” in the cookie banner; if you choose “Essential only”, it is never loaded and nothing is sent to Google. You can change your choice at any time with the “Cookie Preferences” link in the site footer, and withdrawing consent removes the Google cookies. You can also manage how Google uses this data at adssettings.google.com.


How We Use Your Data

We use your personal data for these purposes:

  • To create and manage your user account and to authenticate you.
  • To store and deliver your packages via our cloud infrastructure.
  • To operate, maintain, secure and troubleshoot the Service, including detecting and fixing errors.
  • To measure the effectiveness of our advertising and understand how the Service is used, using technical data such as pages visited, referring source, and device and browser information.
  • To communicate with you about your account, such as sign-in emails, invitations, and support requests.

We do not use your data for any other purpose, as set out in “Our Commitment to Your Privacy” above.


Storage and Security

Your account data is stored in our database. Package files and profile images are stored in Cloudflare R2 object storage. Our website and API are served behind Cloudflare, which acts as a reverse proxy and content delivery network, so requests to the Service pass through Cloudflare’s network. All traffic is encrypted in transit using HTTPS, and files stored in Cloudflare R2 are encrypted at rest by Cloudflare.

We implement and maintain security measures to protect your data against unauthorized access, disclosure, alteration, or destruction, including encryption in transit, access controls on private packages and organizations, short-lived access tokens, and HttpOnly, Secure session cookies. No method of transmission or storage is completely secure, but we work to protect your information.

If a security incident affects your personal data, we will notify the affected users, and the relevant authorities where required, without undue delay.


Service Providers and Data Sharing

We share data only with the service providers below, only to the extent necessary for them to help us operate the Service, and they may not use it for their own purposes. They may process data in countries other than your own, under their own privacy terms and data protection commitments.

  • Cloudflare: network proxy, content delivery, and R2 object storage for files and images.
  • Google Identity Platform: authentication and sign-in, for Google sign-in and email sign-in links. We do not offer password-based sign-in.
  • Google (Google Ads / Google Analytics): advertising measurement and website analytics, as described under “Cookies and Similar Technologies”.
  • Polar: payment processing and subscription billing for paid plans. When you start a checkout we send Polar only your email address, plus internal identifiers (your user ID, and your organization’s ID and slug) so the subscription can be linked back to your organization. We do not send your name. The billing details you enter at checkout, such as payment details and billing address, are collected by Polar directly and are governed by Polar’s own privacy policy. While a subscription is active, we also send Polar usage events, which contain only Polar’s customer identifier and the amount of storage or transfer used (in KB).
  • Sentry: error and performance monitoring. In production, error reports and performance traces may include technical request data and your user ID and email address. We do not send your name to Sentry.

We may also disclose information if required by law or to protect the rights, safety, or security of pckgs.io, our users, or the public. If we are involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction, and we will notify you of any change in how it is handled.

Packages and organization information that you choose to make public are visible to others by design.


Your Rights

You have fundamental rights regarding your personal data. We are committed to helping you exercise these rights:

  • Right to Access: You can request a copy of the personal data we hold about you.
  • Right to Correction: You can ask us to correct any inaccurate or incomplete personal data we have.
  • Right to Deletion: You can delete your account yourself (see below), or ask us to delete your personal data, subject to any legal obligations that require us to retain it. Records of payments and invoices held by our payment provider may be retained as required by law.

Depending on where you live, you may have additional rights under applicable data protection law, and we will honor them. To exercise any of these rights, please contact us here or at support@pckgs.io.


Data Retention and Deletion

We keep your personal data only for as long as your account exists and as necessary to provide the Service and comply with our legal obligations.

You can delete your account at any time from your Account Settings. To delete an account you must first delete or transfer any organizations you own. When you request deletion:

  1. Your account is locked and scheduled for deletion. For 30 days you can sign in and restore it.
  2. After the 30 days, your account is permanently deleted. This removes your user record (email address and name), your memberships, invitations and access tokens, your uploaded profile image, and your sign-in identity in Google Identity Platform.

For more details, see how to delete your account. Records held by service providers, such as error reports in Sentry, are retained according to those providers’ own retention settings.


Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, our service providers, or applicable laws. Any revisions will be posted on this page, and the “Effective Date” at the top of the policy will be updated accordingly. If we make a material change, in particular to how we handle your data or Google user data, we will notify you, for example by email or a notice on the Service, before it takes effect. We encourage you to review this policy regularly.


Contact Us

If you have any questions, concerns, or requests about this Privacy Policy or our data practices, you can contact us here or at support@pckgs.io.