What I collect, and why.
Last updated 13 August 2026The waitlist
If you join the waitlist, I store your email address and, if you picked one, the role you selected. That is the entire record. The email is used to send you one confirmation message and to contact you when early access opens. Nothing else.
Who processes it
Waitlist entries are stored with Supabase and email is delivered by Resend. The site is hosted on Vercel. Site usage is measured with PostHog and Vercel, as described below. Your info is never sold, shared, or passed to anyone else.
Analytics
I measure how the site is used, so I can make it better. Which pages get visited, where visitors arrived from, roughly where they are, what they click, and how far down a page they read. I also record anonymous session replays, which are silent playbacks of how a page was used, so I can see where the site needs improvement.
None of that starts until you accept the cookie banner. Say no and nothing is stored or sent, and the only thing kept on your device is a note that you said no, so you are not asked again.
Everything typed into a form is hidden from replays, including your email address on the waitlist. Nothing recorded identifies you, and nothing here follows you to other sites. Page addresses are logged without their query string, so a link somebody sent you cannot leak through it. Fonts are served from this domain, so loading a page tells nobody else you were here.
Getting removed
Reply to any email from me, or write to josh@sourceapp.io, and I will delete your waitlist record. No form. It goes when you ask.
The desktop app
Source is local-first. It runs on your machine and works in your own repository. This policy covers the website only. The app will ship with its own, describing exactly what leaves your computer, if anything.