1. Introduction
Welcome to IconSearch ("we", "our", or "us"). IconSearch is an open-source icon discovery engine and developer productivity platform. This Privacy Policy explains how we collect, use, store, and protect information when you visit iconsearch.info or connect using any of our 18 developer extensions and plugins. By using the Platform, you agree to the practices described in this policy.
2. Information We Collect
We adhere to strict data minimization principles. The types of data we collect include:
• Account Data: When you sign up or log in via Supabase Authentication (Email/Password or Google OAuth), we store your email address, unique user ID, avatar URL, and authentication timestamps.
• Entitlement & Founder Access Claims: When you claim Founder access or product entitlements, we store your user ID, product key (e.g. vscode-extension, figma-plugin), claim status, and timestamp.
• Device Authorization Data (RFC 8628): When you approve an extension or plugin connection, we generate an 8-character user code and store ONLY a cryptographic SHA-256 hash of the session token combined with a server-side pepper (DEVICE_TOKEN_PEPPER). We never store raw session tokens on our servers.
• Cloud Sync Data: If you choose to save custom icon packs or style presets to your account, we store your custom pack names, icon lists, and styling parameters (size, stroke weight, color) in our Supabase database.
• Rate Limiting & Security Logs: To prevent abuse, API flooding, and automated scraping, we temporarily retain client IP addresses in sliding-window memory caches (120 requests/min rate limit).
• Usage Analytics: We use Google Analytics 4 to collect aggregated, anonymized metrics (pageviews, session durations, broad geographical country/city data) to optimize platform performance. All IP addresses are anonymized.
3. Authentication & Security Architecture
Authentication is managed securely through Supabase Auth. Device Authorization for IDE extensions, browser extensions, and design tools follows the RFC 8628 protocol. Session tokens issued to extensions can be individually revoked by users at any time via /api/device/revoke or by signing out. Database access is protected with strict Row Level Security (RLS) policies ensuring users can only access and modify their own packs, presets, and entitlements.
4. Cookies & Local Browser Storage
We use first-party HTTP cookies and LocalStorage to:
• Maintain your active Supabase user session. • Persist local UI settings (such as dark mode preferences, active customizer settings, and local cart items).
Third-party cookies may be set by Google Analytics for traffic analysis and Google AdSense for displaying contextual advertisements. You can disable third-party cookies in your browser settings or opt out of Google Analytics via tools.google.com/dlpage/gaoptout.
5. Google AdSense & Advertising
IconSearch displays contextual advertisements through Google AdSense to support server costs. AdSense may use cookies to serve relevant ads based on non-personally identifiable browsing patterns. You can manage personalized ad preferences through Google Ads Settings (adssettings.google.com) or opt out through optout.networkadvertising.org.
6. How We Use Your Data
We process personal information strictly for legitimate operational purposes:
• Authenticating your identity and managing account sessions. • Allocating and verifying lifetime Founder Access entitlements across our 18 product integrations. • Authorizing connected extensions, plugins, and MCP servers. • Synchronizing cloud-saved icon packs and customizer presets upon request. • Protecting our infrastructure from IP abuse and high-frequency scraping.
We do NOT sell, rent, trade, or monetize your personal data to third parties.
7. Third-Party Links & Open Source Assets
IconSearch links to third-party resources including GitHub repositories, npm registries, Figma community assets, and documentation. We are not responsible for the privacy practices or content of external sites. Indexed SVG icons remain governed by their respective open-source licenses (MIT, Apache 2.0, ISC, CC0, etc.).
8. Data Retention and Deletion Rights
We retain account and cloud sync data for as long as your account remains active. You have the right to request full export or permanent deletion of your account, cloud icon packs, presets, and device authorizations. To request account deletion, email us at iconsearchinfo@gmail.com. All associated database records will be permanently purged within 7 business days.
9. Regional Rights (CCPA & GDPR)
• California Residents (CCPA): You have the right to request disclosure of personal data collected, request deletion, and opt out of any data sales (IconSearch does not sell personal data).
• EEA / UK Residents (GDPR): You have the right to access, rectify, port, or erase your personal data, and to restrict or object to processing based on legitimate interests. You may lodge a complaint with your local Data Protection Authority.
10. Children's Privacy
IconSearch is a professional technical platform intended for developers and designers. We do not knowingly collect or solicit personal information from children under 13. If we discover personal data from a child under 13, we will delete it immediately.
11. Policy Updates
We may update this Privacy Policy periodically to reflect infrastructure or legal updates. Material updates will be indicated by revising the "Last updated" date at the top of this page.
12. Contact Us
For privacy inquiries, data deletion requests, or security reports:
📧 Email: iconsearchinfo@gmail.com 🌐 Contact Form: https://iconsearch.info/contact 📍 Operating from: United States