DeepSeek Harness Plugin Hub

PRIVACY NOTICE

How we handle your information

How the Plugin Hub processes information when you browse the catalog, use the CLI, sign in, or submit a report.

What we collect

Browsing the plugin catalog does not require an account. On a first visit we set a first-party cookie named dsh-hub-attribution (90 days) so we can remember the landing path and, when present, campaign parameters or click IDs such as gclid, wbraid, gbraid, and oppref. If you sign in, we store your WorkOS account details (email, name, and avatar) to identify you and attribute plugins you publish. If you submit an abuse report, we process the report content and an optional contact email. To prevent abuse, we also process Turnstile verification results and hashed rate-limit identifiers.

CLI telemetry

After showing a first-run notice, the open-source dsh-hub CLI reports successful and failed install and Preset lifecycle operations unless you turn telemetry off. The notice run sends no event. Reports contain the public package or Preset identifier and version, operation and outcome, a stable error category, duration, operating system, CPU architecture, and CLI version. They contain no Hub account, machine identifier, local path, configuration value, environment value, or secret. The request payload and aggregate database contain no IP-address field. Our hosting and security providers still process source IP addresses to deliver and protect HTTP requests. The API derives an hour-rotating HMAC rate-limit key from the source IP and keeps only the current and previous hourly windows; those keys cannot be linked across hours.

Measurement

When Google Ads, Google Analytics 4, or ChatGPT Ads measurement is enabled for this site, we load those products' tags and may send conversion events (copying an install command, or completing sign-in) together with the first-touch click IDs. That is how we tell which ads led to those actions. We do not run an email list and we do not sell personal information.

Purpose

We use this information to operate the plugin directory, improve CLI reliability, prioritise maintenance, attribute published plugins to their owners, respond to abuse reports, measure ads when those products are turned on, and keep the service secure.

Service providers

Cloudflare provides hosting and Turnstile security verification. WorkOS provides sign-in. The backend API and database run on Google Cloud. Data may be processed in these systems as required to operate the service.

Retention and deletion

CLI events are immediately folded into daily aggregates and retained for 365 days. The hourly internal schedule and every telemetry ingestion delete older aggregates and expired CLI rate-limit keys; ingestion stops if that cleanup is unavailable. Aggregates have no account or stable device identifier, so they cannot be selected by user account for deletion. We keep account and report information only as long as needed to operate the service. You may request deletion of identifiable information at hello@dshpluginhub.ai.

Last updated: August 31, 2026. This is an independent, unofficial community project and is not affiliated with, authorized by, or endorsed by DeepSeek.

Back to home
DeepSeek Harness Plugin Hub

Publish and manage complete Harness Profiles. Discover Plugins for your next setup.

Explore

PluginsPresetsDocsNews

Community

Publish a pluginContactReport an issue

Resources

Plugin Hub on GitHubDeepSeek HarnessSystem statusPrivacy notice
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

Independent and unofficial. Not affiliated with, authorized by, or endorsed by DeepSeek.

Privacy Notice — DeepSeek Harness Plugin Hub