Privacy Policy

Last updated: 6 August 2026

AlternativeTo is committed to protecting your privacy. This policy explains what personal data we collect when you use alternativeto.net, why we collect it, who we share it with, how long we keep it, and what rights you have over it. We have tried to write it in plain language rather than legalese.

If you only read one thing: we need an email address and a username to give you an account, we use cookies and third-party services for advertising and analytics, and if you choose to support us financially your card details go straight to Stripe and never touch our servers. You can ask us to delete your data at any time by emailing hello@alternativeto.net.

alternativeto.net is operated by 27 Kilobyte AB, Box 45142, 104 30 Stockholm, Sweden. We are the data controller for the personal data described in this policy.

For any privacy question, request or complaint, contact us at hello@alternativeto.net. We answer privacy requests as quickly as we can, and always within one month.

We have not appointed a Data Protection Officer, as we are not required to do so.

  • Account data. To have an account you must give us an email address and a username. Everything else on your profile is optional.
  • Public content. Anything you post — comments, reviews, likes, lists, submitted apps — is public by design and tied to your profile.
  • Payments. The one paid feature is a fee to get a submitted app reviewed sooner. Payment is handled by Stripe; we never see or store your card number.
  • Advertising. The free site is funded by ads. In the EEA and the UK we ask for your consent before any ad personalisation happens.
  • We do not sell your personal data for money. Ad-related cookies may still count as "sharing" or "selling" under some US state laws — see US privacy rights below.
  • Deletion. Email us and we will delete your account and personal data.

Account and login data. Your email address, your username, and — if you sign in with a password — a hashed version of that password. If you sign in with Google, Microsoft, GitHub or Apple instead, we receive your email address, name and profile picture from that provider. We never receive your password for those services.

Profile data (all optional). Real name, bio, country of residence, website URL, profile picture, and links to services such as LinkedIn, Reddit, GitHub, YouTube and Instagram. You choose whether to provide any of this, and you can change or remove it at any time in your account settings.

Content you contribute. Comments, reviews, opinions, "likes", app and alternative submissions, lists, tags, uploaded icons and screenshots, and anything else you submit. This content is public and is shown together with your username and profile picture.

Messages you send us. If you email us or use a contact or report form, we keep that correspondence so we can handle your request.

Usage data. IP address, browser and device type, operating system, referring page, pages visited, time spent, and the path you took through the site. Some of this we collect ourselves for security and abuse prevention; some is collected by the third-party services listed below.

Cookies and similar trackers. Used to sign you in, remember your preferences, measure traffic and serve ads. The full list, with purposes and durations, is in our Cookie Policy.

Server logs. Our servers and infrastructure providers record requests to the site, including IP address and timestamp, for operation, security and troubleshooting.

Payment data from Stripe — see the next section.

Anti-bot signals from hCaptcha when you sign up or submit certain forms.

AlternativeTo is free to use. The one thing you can pay for is a one-time fee to have an app you submitted reviewed sooner. Payments are processed by Stripe Payments Europe, Ltd. and its affiliates ("Stripe").

We never see your card details. Checkout happens on Stripe's own hosted pages. Your card number, expiry date and security code go directly to Stripe and are never transmitted to, or stored on, AlternativeTo's servers.

What we send to Stripe. Your email address, an internal AlternativeTo user identifier, and the identifier of the app submission you are paying for, so the payment can be matched to your account and to the right submission.

What we receive back and store. Confirmation that the payment succeeded, the Stripe checkout session and payment identifiers, and the amount and currency. We use this to move your submission into the priority queue and to show you that the payment went through.

What Stripe does with your data. Stripe acts as an independent controller for parts of this processing — including fraud prevention, complying with financial and anti-money-laundering law, and tax. Stripe may collect your name, billing address, card details, transaction history, and device and usage data in accordance with its own Privacy Policy.

Retention. We keep records of transactions for seven years from the end of the financial year they belong to, as required by the Swedish Bookkeeping Act, even if you delete your account. After that they are deleted or anonymised.

Legal basis. Processing the payment is necessary to perform our contract with you. Retaining the accounting records is necessary to comply with a legal obligation. Fraud prevention rests on our and Stripe's legitimate interests.

Place of processing. Ireland and the United States.

To provide your account and the service — creating and authenticating your account, showing your profile, publishing the content you submit, and letting you manage your settings. Legal basis: performance of a contract with you.

To process payments — taking payment for a priority review, moving your submission into the priority queue, and issuing receipts. Legal basis: performance of a contract; legal obligation for the accounting records.

To send you service email — verification links, password resets, security notices, receipts, and messages about a submission of yours. These are not marketing, and you cannot opt out of them while you have an account. Legal basis: performance of a contract.

To send occasional product email — rare messages about new features. We keep these to a minimum, and every one has an unsubscribe link. Legal basis: consent, or our legitimate interest in telling existing users about changes to a service they use.

To keep the site working and safe — preventing spam, abuse, scraping and fraudulent voting; investigating breaches of our rules; monitoring errors and performance. Legal basis: our legitimate interest in a functioning, non-abusive service.

To measure and improve the site — understanding which pages are used, diagnosing problems, testing changes. Legal basis: consent where cookies require it; otherwise our legitimate interest in improving our service.

To show advertising — including personalised advertising where you have consented. Legal basis: consent for personalised advertising and ad cookies; legitimate interest for non-personalised ads.

To comply with the law and defend our rights — responding to lawful requests from authorities, and establishing or defending legal claims. Legal basis: legal obligation; legitimate interest.

Where we rely on legitimate interests, we have weighed our interest against your rights, and you can object at any time — see Your rights below.

AlternativeTo is free to use and funded by advertising. We use Google AdSense and Google Ad Manager to serve ads, together with Google's Funding Choices consent tool and Google Consent Mode.

If you are in the EEA or the UK, ad storage, ad personalisation and ad user data are switched off by default and are only enabled if you give consent through the consent banner. Outside those regions they are enabled by default, and you can opt out at any time through the consent tool or through your Google ad settings.

You can also limit ad tracking through:

To understand how Google uses data from sites that use its services, see Google's partner policy.

We only share personal data with providers that need it to run the service. They act as our processors unless noted otherwise, and are bound by contract to use the data only on our instructions.

  • Stripe (Stripe Payments Europe, Ltd. / Stripe, Inc.) — payment processing; independent controller for parts of the processing. Ireland and United States. Privacy Policy
  • Google, Microsoft, GitHub and Apple — optional social sign-in. If you use one, that provider tells us your email address, name and picture, and learns that you signed in to AlternativeTo. Governed by each provider's own privacy policy.
  • Auth0 (Okta, Inc.) — used only to verify passwords for older accounts that have not yet been migrated to our current login system. Once your account is migrated, Auth0 is no longer involved. United States. Privacy Policy
  • Microsoft Azure (Microsoft Corporation) — hosting, databases and backend infrastructure. European Union and United States. Privacy Policy
  • Cloudflare (Cloudflare, Inc.) — content delivery, DDoS protection and traffic filtering. All traffic between your browser and AlternativeTo passes through Cloudflare. United States. Privacy Policy
  • Algolia (Algolia SAS) — powers site search. Search queries and technical metadata are processed by Algolia. France and United States. Privacy Policy
  • Mailgun (Sinch) — delivers transactional email such as verification links, password resets and account notices. Processes your email address and the content of those messages. United States and European Union. Privacy Policy
  • Google Analytics (Google Ireland Limited) — traffic measurement, with IP anonymisation enabled. Ireland. Privacy PolicyOpt out
  • Google Tag Manager (Google Ireland Limited) — manages the tags used on the site. Ireland. Privacy Policy
  • Google AdSense and Google Ad Manager (Google Ireland Limited) — advertising, including the DoubleClick cookie. Ireland. Privacy Policy
  • Google Funding Choices (Google Ireland Limited) — records and stores your consent choices. Ireland. Privacy Policy
  • Sentry (Functional Software, Inc.) — application error monitoring for our backend services. Error reports may include an IP address and details of the request that failed. United States. Privacy Policy
  • TrackJS (TrackJS LLC) — JavaScript error monitoring in the browser. United States. Privacy Policy
  • hCaptcha (Intuition Machines, Inc.) — protects sign-up and submission forms from automated abuse. hCaptcha analyses signals such as your IP address, how long you have been on the page, and your mouse movements, to decide whether you are a human. In "invisible mode" this happens in the background without showing you a challenge. We rely on our legitimate interest in protecting the site from automated abuse and spam (Art. 6(1)(f) GDPR). Intuition Machines acts as a processor under the GDPR and as a service provider under the CCPA. United States. Privacy PolicyTerms
  • OpenAI (OpenAI, L.L.C.) — used by our editorial team to help draft and summarise app descriptions and other editorial content. Publicly visible content may be sent to OpenAI for this purpose. Account data, email addresses and payment data are not. United States. Privacy Policy

We may also disclose personal data to professional advisers, or to public authorities and courts where we are legally required to, or where it is necessary to establish or defend a legal claim. If AlternativeTo is ever sold or merged, personal data may be transferred as part of that transaction; we will tell you first.

We are based in Sweden, and several of the providers above are based in, or process data in, the United States and other countries outside the EEA. Where data leaves the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses, on an adequacy decision where one exists (for example the EU–US Data Privacy Framework for certified providers), and on additional safeguards where appropriate.

You can ask us for details of the safeguards that apply to a specific transfer by emailing hello@alternativeto.net.

  • Account and profile data — until you delete your account or remove the information. Deleting your account removes your profile and personal details.
  • Content you posted publicly — comments, reviews and submissions may remain on the site after account deletion, but are disassociated from your identity, unless you ask us to remove them specifically.
  • Login records — data tied to your chosen login method is kept until you delete your account.
  • Payment and accounting records — seven years, as required by Swedish bookkeeping law, regardless of account deletion.
  • Server logs and security data — for a limited period, normally no more than 90 days, and longer only where needed to investigate a specific abuse or security incident.
  • Support correspondence — up to two years after the matter is closed.
  • Cookies — for the durations set out in the Cookie Policy.

Once a retention period expires the data is deleted or anonymised. Rights of access, erasure, rectification and portability cannot be exercised over data that has already been deleted.

Content you post is public

AlternativeTo is a public, community-built site. Your username, profile picture, bio, links, and everything you contribute are visible to anyone on the internet, and may be indexed by search engines, copied, or cached by third parties beyond our control.

Please do not post anything you would not want to be public and permanent. If you post personal data about someone else, you are responsible for having a lawful basis to do so, and we may remove it on request.

We take appropriate technical and organisational measures to protect your data: encryption in transit (HTTPS everywhere), hashed passwords, access controls limiting who on our side can reach personal data, isolated production environments, and monitoring for unauthorised access. Payment card data is handled entirely by Stripe, which is PCI DSS Level 1 certified.

No system is perfectly secure. If a breach ever affects your personal data and creates a risk to your rights, we will notify you and the Swedish Authority for Privacy Protection as required by law.

AlternativeTo is not directed at children. You must be at least 16 years old to create an account, or the minimum age of digital consent in your country if that is lower. If we learn that we hold personal data from a child below that age, we will delete it. Contact hello@alternativeto.net if you believe this has happened.

If you are in the EEA or the UK — and, in practice, we extend most of these to everyone — you have the right to:

  • Access your data and get a copy of it.
  • Rectify data that is wrong or incomplete. Most of it you can fix yourself in your account settings.
  • Erase your data ("right to be forgotten").
  • Restrict processing in certain circumstances, so that we only store the data.
  • Object to processing based on legitimate interests, on grounds relating to your situation. You can object to direct marketing at any time, with no reason needed.
  • Withdraw consent at any time, where processing is based on consent. This does not affect processing that already happened.
  • Portability — receive your data in a structured, commonly used, machine-readable format, and have it sent to another controller where technically feasible.
  • Lodge a complaint with your data protection authority. Ours is the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten (IMY).

How to exercise them: email hello@alternativeto.net. We may need to verify your identity, usually by confirming that you control the account's email address. Exercising your rights is free of charge, and we will respond within one month.

If you live in California, Colorado, Connecticut, Virginia or another US state with a comprehensive privacy law, you have rights to know, access, correct, delete and port your personal information, and to opt out of targeted advertising and of the "sale" or "sharing" of your personal information. You also have the right not to be discriminated against for exercising them.

We do not sell your personal information for money. However, the advertising cookies described above may qualify as a "sale" or "sharing" under California law. You can opt out through the consent tool on the site, through the opt-out links above, or by emailing us.

Sensitive personal information. We do not collect or use sensitive personal information for the purpose of inferring characteristics about you.

Authorised agents. You may use an authorised agent to submit a request; we will ask for proof of authorisation.

We do not respond to browser "Do Not Track" signals, as there is no common standard for how they should be interpreted. To control tracking on AlternativeTo, use the consent tool or the opt-out links above.

The third-party services listed above handle such signals according to their own policies.

We may update this policy from time to time. When we do, we will change the "Last updated" date at the top and, where the changes are significant, notify you on the site or by email. If a change affects processing that is based on your consent, we will ask for your consent again.

Personal data — any information that identifies you, or that could identify you when combined with other information.

Usage data — information collected automatically when you use the site: IP address, request times and methods, response sizes and status codes, country of origin, browser and operating system, time spent on each page, and the path taken through the site.

Controller — the party that decides why and how personal data is processed. For AlternativeTo, that is us.

Processor — a party that processes personal data on the controller's behalf and on its instructions, such as our hosting or email provider.

Cookie — a small piece of data stored in your browser.

Tracker — any technology that allows users to be tracked, including cookies, unique identifiers, web beacons, embedded scripts, e-tags and fingerprinting.

EEA — the European Economic Area: the EU member states plus Iceland, Liechtenstein and Norway.

This policy is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR), the UK GDPR, and applicable US state privacy laws. It relates solely to alternativeto.net unless stated otherwise.