Skip to content
assetlib

Assetlib privacy notice

Privacy, plainly.

Assetlib is an early service run by a small team. Each surface collects as little as it can, and this page says exactly what that is, where it is stored, and how to ask about it.

Last updated October 8, 2026. Applies to the website at www.assetlib.dev, the console at assetlib-console.vercel.app, the Roam and Daylight sample apps, the SDKs, and the audit command and agent plugin.

The website keeps nothing about you.

www.assetlib.dev has no account, no sign-up form, no product analytics, and no advertising trackers. Fonts are served from this site, not from a font network. We set no cookies on this domain.

Vercel hosts the site. Like any host, it may process request information such as your IP address, user agent, and the pages you request in its access logs. See the Vercel privacy policy.

The homepage embeds the Roam and Daylight sample apps in frames served from their own addresses. Loading the homepage loads those apps. What they store is described in section 03; nothing from them reaches this site.

Downloading the integration checklist or pilot brief is an ordinary file download. It submits nothing and creates nothing.

The console stores your GitHub identity and your artwork.

The console at assetlib-console.vercel.app is where workspaces, images, placements, and releases live. It is a bounded preview for non-confidential artwork.

What we collect when you sign in

  • From GitHub: your GitHub account identifier, profile name, avatar, and a verified email address. We request the read:user and user:email scopes only. We never request access to your repositories.
  • Session: a session cookie that is Secure, HttpOnly, and SameSite=Lax. Sessions expire after eight hours. The OAuth token GitHub issues is stored encrypted and used only to complete sign-in.
  • Request metadata: IP addresses are used for rate limiting on sign-in, uploads, onboarding, and delivery, in short-lived counters.

What we store when you use a workspace

  • Images you upload, including the exact original file (kept private to your workspace) and the prepared versions we generate from it. Preparation strips embedded metadata such as EXIF before anything is served.
  • Placements, draft bindings, release notes, release history, optional image descriptions, and the roles of workspace members.
  • Your workspace’s public SDK configuration: organization and app identifiers, a delivery URL, and a public verification key. It contains no credentials.

What becomes public

When you publish a release, its signed manifest and the prepared images it references become publicly retrievable by anyone with the URL, with credentialless cross-origin access, and may be cached by browsers and content delivery networks. That is how connected apps fetch them. Draft images, originals, and unpublished changes stay private to workspace members.

Where it is stored

The console runs on Vercel. Account, session, workspace, and image data are stored in a managed PostgreSQL database provided by Neon in the AWS US East 1 region. Both providers process the data on our behalf: see the Vercel privacy policy and the Neon privacy policy. We do not sell or share this data for advertising, and we collect no telemetry or usage analytics from the console.

The sample apps remember only what you paste into them.

Roam and Daylight are small open-source apps that run in your browser or on your device. They have no accounts and no analytics. If you paste a public SDK configuration into one, the app stores it locally so it can reconnect, and it caches the verified artwork it downloads. Clearing the app’s data, or your browser’s site data, removes both.

When a sample app checks for a release, it requests the signed manifest and images from the console’s public delivery routes. Those requests carry ordinary HTTP metadata and are subject to the hosting logs described above. Nothing else is sent.

The SDK sends no identifiers and no events.

When your app calls refresh, the SDK requests the signed manifest and any images it needs from the delivery URL in your configuration. It sends no device identifier, no user identifier, no analytics event, and no telemetry. There is no background polling: requests happen only when your code asks for them.

Delivery requests reach the console’s public routes and are logged like any other request to Vercel. The SDK caches verified artwork on the device inside your app’s own storage, within documented limits, and falls back to the image bundled in your app when delivery fails.

You decide what your app does with the artwork. Your own privacy notice covers your app and its users; this one covers ours.

The audit runs on your machine and reports to you.

The @assetlib/audit command reads image headers and, only if you ask, scans quoted filenames in a source folder you choose. It makes no network calls of its own. The first run fetches the package from the npm registry, which is governed by the npm privacy policy. It prints its report to your terminal and sends nothing to us.

The report can include your file names and source locations. Review it before sharing it anywhere.

The assetlib-audit plugin for Claude Code and Codex is a set of instructions for the agent you already use; it runs the same command. The agent, not Assetlib, handles what it reads and sends, under its own provider’s terms. We receive nothing from the plugin.

Release history is kept so apps can roll back.

  • Account and session data stay for as long as the account exists. Sessions expire after eight hours and expired rows are cleaned up.
  • Artwork and releases are retained while the preview runs. Archiving an image hides it from new use but does not delete it, because an installed app may still reference a release that includes it. Archive is reversible.
  • Hosting logs are kept according to Vercel’s retention, not ours.
  • At the end of the preview, or if the service is discontinued, we may delete workspaces and their data. We will say so on this site beforehand where practical.

There is no self-service account deletion or workspace export yet. Both are planned. Until then, requests are handled by hand as described below.

Ask, and we will act by hand.

You can ask us to show you the data we hold about you, correct it, delete your account and workspace, or export your workspace. Write to the contact below from the email address on your GitHub account so we can match the request. We will confirm what was done.

Deleting a workspace removes its draft and published data from our systems. It cannot recall images already cached by browsers, content delivery networks, or installed apps that fetched them while they were public.

You can revoke Assetlib’s access to your GitHub account at any time from your GitHub application settings. Revoking access ends future sign-ins; it does not by itself delete your workspace.

If you are in a jurisdiction that gives you additional rights over your personal data, such as the EU, the UK, or California, the contact below is how you exercise them. We do not sell personal data.

Changes are dated, and someone answers.

Assetlib is not directed to children under 16, and we do not knowingly collect their data. If you believe we have, contact us and we will remove it.

When this notice changes, the date at the top changes with it. Material changes to what the console collects will also be noted on the console’s sign-in page.

Questions and requests: tylerzhaodev@gmail.com. For a suspected security vulnerability, use GitHub private vulnerability reporting on the relevant AssetLib repository rather than email.

Assetlib is a working name. This notice describes the service as it exists on the date above.