Privacy
Last updated: 11 August 2026
HowManyUsers counts users. It does not collect them. This page says exactly what we store and what we refuse to store — and every line of it matches what the code actually does.
Your users' data
We never want your users' names, emails, phone numbers or addresses. The identifier you send us is hashed with a server-side secret and your project id before it touches our database: it can't be reversed, and the same person in two different startups produces two unrelated identifiers. If you send an email as a user id — it happens — what we store still isn't that email.
What we do store about them
A pseudonymous identifier, the date the account was created in your product, the date we first saw it, and optionally a two-letter country code and a coarse device category. Nothing else, ever.
Your data as a founder
Your name, email and profile picture, from Google. Your projects, their metrics and their API keys — hashed, never in plain text. We use your email to sign you in and, if you ask for it, to notify you. Your name and your profile picture appear on your startup's public profile, so people know who's behind it. One switch in Settings turns it off, and it disappears from the profile immediately.
Cookies
We use a handful of first-party cookies to keep you signed in, remember your language choice and credit a badge or a shared link for the traffic it sends us — plus Google Analytics, a third-party service, to understand how the site gets used. None of it builds an advertising profile of you. The full list, with names and how long each one lasts, is on our cookie policy.
Analytics
We use Google Analytics to see, in aggregate, which pages get used and roughly where traffic comes from. It sets its own cookies and can see your IP address and browser details before Google processes them — that data goes to Google, not just to us, and is covered by Google's own privacy policy as well as this one. We don't show a cookie-consent banner before it loads today; the cookie policy explains how to block it in your browser if you'd rather it didn't run.
IP addresses
We never store them in the clear. Where we need them — abuse protection, audit trail — we store a hash. It's enough to see that twenty attempts came from the same place, and not enough to know where.
What is public
A new project is published by default, with its metrics visible — that's what a scoreboard is for. Everything is a switch: turn off any metric, or the whole profile, from Settings, and it disappears from your profile, your badges and the rankings immediately. What you turn off is never shown, not even in an image or a badge.
Who else touches your data
Google, for sign-in and for analytics (above). Cloudflare, which runs the domain's DNS and, if you write to a @howmanyusers.wtf address, forwards that email to our inbox. It is NOT in front of the site: when you open a page, your browser talks straight to our server and Cloudflare never sees that visit. Stripe, if you pay for anything — they handle your card, we never see the number. Resend, to send the emails the product sends, like a milestone or a reminder that nothing's connected yet. None of them get more than what that specific job needs.
How long we keep things
Event and user data lives for as long as your project exists — deleting the project deletes it, immediately, not on a schedule. Server logs kept for abuse protection hold a hash, not the address itself, and age out on their own after a limited time. Cookies expire on the schedule in our cookie policy; the longest-lived one lasts a year.
Deleting your data
Deleting a project deletes its events, its counted users, its keys and its public profile. It's a real deletion, not a hidden flag. The only thing that survives is the public address, which is never reused, so an old link can't end up pointing at someone else's startup.
Your rights
You can see and export your project's data from your dashboard, and delete a project or your whole account yourself, at any time, without asking us first. If you want something we haven't put a button on yet — a full export, a correction, a plain answer about what we hold — write to us and we'll do it by hand.
Not for children
HowManyUsers is a tool for people running a product, not a service aimed at children, and we don't knowingly collect data from anyone under 16.
Changes to this policy
If what we collect or how we use it changes, this page changes with it before the change takes effect. A privacy policy that doesn't match the code is worse than not having one.
Contact
Questions about your data: hi@howmanyusers.wtf, or @firbedatomas on X.