Privacy policy
Last updated 25 September 2026.
What the badge does on your site
This is the part that matters most, so it goes first. The script you paste on your own site (badge.js):
- sets no cookies and writes nothing to localStorage or any other storage;
- does not fingerprint, profile or identify your visitors;
- contacts no analytics service and no ad network, and no third party at all unless you have linked one of your apps to BroFindAI, described below;
- makes one request to render (a cached GET for your own public profile) and sends no information about the visitor with it;
- renders inside a shadow root and cannot read your page's content.
There is one more kind of request, for your analytics. The badge sends a short message to us when it is shown on a page (once per page load), when a visitor opens its panel (once per page load), and when a visitor clicks a link in it. Each message says which of those happened, which link for a click, and the hostname of the page. That is the whole message: no path, no query string, no referrer, no identifier, and nothing read from or stored on the visitor's device.
When a message arrives, Cloudflare, which runs our servers, tells us the country the request came from, as a two-letter code. We keep that code and nothing else about the request; our code never reads the IP address it was worked out from.
We add each message to counters. What is stored is integers: how many views, opens and clicks, per day, per site, per country and per link. There is no visitor record to look at, join or hand over, even if someone asked us to. It is what fills in Analytics on your dashboard, and it is yours alone. Nobody else can read your numbers. If you would rather a site sent nothing at all, add data-taksh-insights="off" to its script tag and the badge never sends any of it.
BroFindAI vote counts. If, and only if, you have marked one of your apps as listed on BroFindAI, the badge shows that app's live vote count. To do that it reads a public JSON file from brofindai.com, once a visitor opens the panel. It is a read, not a report: no cookies are sent or set, and nothing about your visitor goes with it. Only the vote number is used: no text BroFindAI sends can end up on your page. If BroFindAI is slow, blocked or down, the count simply doesn't appear and the rest of the badge is unaffected.
Link no apps and the badge contacts nobody but us, exactly as it always has. To rule it out on a particular site regardless, add data-taksh-votes="off" to the script tag.
Our servers see what any web server sees when a file is requested: an IP address and a user agent, in Cloudflare's standard request logs. We do not build profiles from them and do not join them to accounts.
What we store about you
If you sign in, we store your Google account's email, display name and profile photo URL, plus whatever you put in your maker hub: username, bio, project links and badge settings. All of that except the email is public by design: it is what the badge and your hub display.
When you buy, our payment processor (Razorpay) handles the card. We never see or store card details: only a payment ID, an amount and the fact that your badge is now published.
Analytics on this site
On maketaksh.com only (never through the badge on your site) we use Google Analytics, Microsoft Clarity and PostHog to understand which parts of this page people read and where they get stuck. Clarity records anonymised session replays of this site. PostHog only creates a person profile once you sign in; if you never do, its data stays anonymous. All three set cookies in your browser while you are here.
If you arrive with a ?ref= on the URL (BroFindAI's badge links here with one) we record that one word as an event so we can tell which links are worth having, and then remove it from the address bar. The event is the word and nothing else: no identifier, no page contents, nothing about you.
The homepage shows badges from sites that list Make Taksh: BroFindAI, Product Hunt, VibeRank, Sell With boost and Smol Rank. The BroFindAI badge loads a script and a font from BroFindAI, reads the current vote count, and if you click it, tells BroFindAI which badge was clicked. None of those requests carry cookies, and it stores nothing in your browser. The other four are plain images loaded from those sites, so like any web request they see your IP address and browser.
This site also serves Google AdSense on its content pages, and runs Google Ads campaigns whose tag records that a visit arrived from one of those ads and whether it ended in a purchase. Both use cookies for ad delivery and measurement. You can opt out of personalised ads at adssettings.google.com.
Who else processes it
Google Firebase (authentication and database), Cloudflare (hosting and edge caching), Razorpay (payments), and the analytics providers above (Google, Microsoft and PostHog; PostHog on US infrastructure). We do not sell data to anyone, and there is nobody to sell it to.
Deleting everything
Email [email protected] from your account address and ask. Your profile, hub and account are deleted, and badges already installed on your sites simply stop rendering. They fail silently rather than breaking the page.
Changes
If this policy changes materially, the date at the top changes and anyone with an account gets an email. We won't quietly start collecting something new through the badge.