Iraq Builds

Privacy Policy

Version 0.2 (draft) · Last updated August 31, 2026 · Effective at Public Beta / public launch (not yet authorized)

This is the current draft Privacy Policy for Iraq Builds. It is intended to apply when Public Beta / public launch is authorized, and may still change before then. Iraq Builds only describes data it actually collects.

Account & session information

Username, email, and password hash for authentication and account recovery. When you log in, Iraq Builds also stores a session record — creation and last-active timestamps, an expiry, and a bounded, truncated browser identifier — so you can review and end your own active sessions from Account Settings. This is not a raw IP address or a device fingerprint.

Email verification & password recovery

Iraq Builds uses your account email address to verify that you control it, to let you recover access if you forget your password, and — where applicable — for important account-security messages. Verification and recovery codes are short-lived, single-use, and are not stored in plaintext in Iraq Builds' database. Resend, Iraq Builds' transactional email delivery provider, processes the destination address and the message content needed to deliver these emails. Your account email remains private — it is never shown publicly unless you separately choose to add a public contact address through a product or builder-profile feature. Verifying an email only proves control of that mailbox; it does not verify your real-world identity. If you change your account email, Iraq Builds does not store the proposed new address in plaintext in the pending change record before you confirm it — only a protected keyed digest is stored, used to match your confirmation. Resend necessarily processes the new destination address and the message content required to deliver the verification code and a related security notice; the security notices sent to your old address never disclose the new address, and no email address is stored in Iraq Builds' administrative audit records for this flow. Once confirmed, the new address becomes your account's private email address.

Builder & product information

Public professional profile details and product listing content you submit for publication. Product links lead to destinations outside Iraq Builds; those destinations have their own privacy practices, which this policy does not cover.

Analytics

Iraq Builds records first-party analytics events you generate as a visitor or Builder: product page views; outbound clicks to a listed website, Google Play, the App Store, a PWA/open-product link, GitHub, or an external APK/download link; Contact-action clicks; and Share-action clicks (the target and platform, such as Copy Link or WhatsApp). Builders see these totals — for Today, the last 7 days, the last 30 days, and all time — along with simple activity trends, on their own dashboard. An outbound click is only ever recorded as a click; Iraq Builds never labels it a download, install, purchase, completed signup, or successful contact.

Administrative audit records

Bounded internal records of product-review and trust-report decisions (approve, request changes, reject, resolve, dismiss) tied to the reviewing administrator account. Iraq Builds does not yet implement a general, platform-wide bot-verification or rate-limiting layer — instead, specific endpoints carry their own purpose-specific anti-abuse controls. Account registration, the forgot-password request, and the public Contact/Report form each use Cloudflare Turnstile to verify submissions come from a real browser before they are processed; the Contact/Report form also has its own narrow, anonymous-submission cookie throttle described below.

Contact & reports

Reports and contact submissions. Iraq Builds currently targets removal of reports that have been resolved or dismissed 12 months after they are closed. That 12-month target is not yet automatically enforced, so a closed report may remain stored for longer than 12 months, including when no legal hold applies. A documented legal hold may require longer retention. The 12-month period is therefore a retention target, not a guaranteed deletion deadline. Ordinary closed reports are not intended to be retained indefinitely. When you use the Contact/Report form, Iraq Builds stores your message, the category and target you selected, the page you submitted from, and — only if you choose to provide one — a reply email address. Ordinary reports about a product, builder profile, or official link do not require an account or contact information; impersonation, ownership, copyright/IP, and privacy reports require a reply email so Iraq Builds can follow up. An anonymous, randomly generated browser cookie limits how many submissions one browser can send per hour; it carries no personal information, and no IP address or device fingerprint is stored. Internal resolution notes are never shown publicly or to the reported builder.

Registration access campaigns

Campaign or invitation attribution for controlled builder registration, where used: which access code a redemption is associated with, and the account that redeemed it. For an invitation code specifically configured with one, the email address it was bound to is also retained; not every code has an email bound to it. Registration Access Codes themselves are never stored in plaintext.

Account deletion

If you permanently delete your account (available from Account Settings, when you don't currently own a Builder or hold an administrator role), Iraq Builds erases your original username and email — both become available for someone else to register — and destroys your password and any active sign-in credential material, so the deleted account can never be used to log in again. Active sessions and any pending verification, password-reset, or email-change codes tied to the account are invalidated. Iraq Builds keeps the account's internal identifier as a historical reference so that audit records, moderation history, registration attribution, product-revision history, and prior ownership-transfer records that refer to it remain internally consistent; retaining that identifier does not mean this history is anonymous, only that the original username, email, and password are gone.

Private data export

From Account Settings, you can download a copy of your own account and Builder data as a JSON file at any time. The export includes your account information, the profile and product data for every Builder you currently own, and your product links. It does not include your password hash, session or verification/recovery/email-change tokens, registration-code material, report or moderation content, administrative audit records, rate-limiting data, or raw analytics events. For any other privacy question, or to exercise these choices, use the Contact/Report route or Account Settings.

Infrastructure & hosting

Iraq Builds runs on Cloudflare's application platform: Cloudflare Workers hosts the site itself, Cloudflare D1 stores the relational data described in this policy, and Cloudflare R2 stores approved product and profile media. Cloudflare Turnstile checks that submissions to account registration, the forgot-password request, and the public Contact/Report form come from a real browser, as described above. Iraq Builds' own application code does not store your raw IP address or a device fingerprint; running any web service on shared infrastructure necessarily involves ordinary network-level information passing through that infrastructure, which is why this policy describes what Iraq Builds itself stores and uses, not what its infrastructure providers process to deliver the service.