DSH Plugins
PRIVACY POLICY

Privacy and advertising disclosures.

Last updated: August 19, 2026

Information processed by the site

dshplugin.dev can process standard request information such as IP address, browser type, requested URL, timestamp and security logs through its hosting provider. The site does not require visitors to create accounts.

Plugin submissions

The submission form stores the public GitHub repository URL, an optional contact email address, an optional review note, the editorial status and an audit history in the site's Cloudflare D1 database. The contact email is used only when a reviewer needs clarification. Form contents, repository URLs and email addresses are not sent to Google Analytics or PostHog.

Cloudflare Turnstile processes browser, device and request signals to protect the submission form from automated abuse. The resulting verification token is checked by the site and is not stored with the submission. Learn more in the Cloudflare Privacy Policy.

Campaign attribution

After a visitor allows optional analytics, a visit that includes UTM parameters or Google click identifiers can store those values in browser session storage for the current tab. They are used to attribute the final publisher click and do not include names, email addresses or other intentionally collected personally identifiable information. Choosing essential-only storage removes this campaign attribution.

Google analytics and advertising

Google Analytics 4, using measurement ID G-4WD85D6708, is loaded only after a visitor allows optional analytics. If the site later uses Google Tag Manager, the managed Google tag will replace the direct integration to prevent duplicate measurement. Before that choice, analytics storage, advertising storage, advertising user data, advertising personalization and personalization storage are denied. The site does not intentionally send Google information that directly identifies a visitor.

Consented analytics can measure page views, install-command copies, sharing actions and the final publisher visit. Google signals and ad-personalization signals are disabled in the direct GA4 configuration.

The built-in privacy control grants analytics storage only. It does not grant advertising storage, advertising personalization or advertising user-data consent.

Visitors can manage or opt out of personalized advertising through Google Ads Settings and can learn about additional industry opt-out choices at AboutAds.

PostHog product analytics

PostHog US Cloud is loaded only after a visitor allows optional analytics. It receives page views and the named interaction events described above. Automatic element capture, heatmaps, Web Vitals, dead-click and rage-click detection, session replay, automatic exception collection and automatic page-leave events are disabled.

PostHog can process browser and device metadata with an anonymous identifier to aggregate site usage. The project is configured to discard raw client IP addresses, although PostHog may derive approximate location or bot-detection metadata before discarding the IP. dshplugin.dev does not intentionally send PostHog names, email addresses, form contents, free-form text or account identifiers. Choosing essential-only storage opts the browser out and removes persisted PostHog analytics identifiers. Learn more in the PostHog privacy notice.

Consent in the EEA, UK and Switzerland

Before Google advertising is enabled for visitors in the EEA, United Kingdom or Switzerland, dshplugin.dev will use a Google-certified Consent Management Platform integrated with the IAB Transparency and Consent Framework where required. The current analytics choice is not a certified advertising CMP and must not be treated as advertising consent.

External publishers

The final “Get this plugin” action opens a publisher-controlled website. That destination has its own privacy policy and data practices. dshplugin.dev forwards only whitelisted campaign attribution parameters through its controlled redirect.

Retention and choices

The analytics choice is stored in the browser until it is changed through “Privacy choices.” Campaign attribution stored in session storage normally ends when the tab closes. Submission records are retained as needed to complete editorial review, prevent duplicate requests and maintain the directory's audit history. Hosting and security logs may be retained by the infrastructure provider for operational and abuse-prevention purposes. Contact us to ask a privacy question or request correction or deletion of submitted information.