---
title: "Marketplace reviews: privacy and community rules"
description: Accounts, public information, privacy, deletion, exports and community rules for marketplace ratings, reviews and author replies, with release limitations.
lastVerified: 2026-09-27
---

# 7.5 Marketplace reviews: privacy and community rules

The review feature in the [Teloa official marketplace](https://market.teloa.ai/en/) supports 1–5 star ratings and reviews for resources such as skills and models. Resource authors can claim resources and reply. This page describes the implementation under development.

::: info Availability
Reviews have passed local fixture tests. Production service setup and formal release remain pending. This page does not announce a live service; real email delivery, GitHub sign-in and human verification must still be checked before deployment.
:::

## Operating direction and contact

The marketplace community is being prepared for deployment and operation in Singapore. The registered operator name has not been provided; operator details, contact information and compliance review must be completed before launch. This page neither asserts that a company has been registered nor guarantees that data stays exclusively in Singapore.

For general questions, resource claims and security issues, the default channel is an [Issue in teloa-ai/marketplace](https://github.com/teloa-ai/marketplace/issues). For issues that could have major impact, we suggest reporting privately to [security@teloa.ai](mailto:security@teloa.ai); do not include credentials or personal data in public Issues. See the [security reporting guidance](https://docs.teloa.ai/markdown/en/deploy/troubleshooting.md#security-reports). Mailbox delivery must be verified before launch.

## Marketplace accounts and sign-in

- A marketplace account is for public reviews, author claims and replies. It is separate from your local Teloa account and is not linked to the random installation identifier used for usage statistics. Email and GitHub sign-in create independent accounts and do not merge automatically.
- Email sign-in uses a six-digit code valid for 10 minutes. The service processes the recipient address to send the code, but its database stores only a digest protected by a server secret, not the address itself. Only a digest of the code is stored; you choose your nickname.
- GitHub sign-in reads public profile information and stores your numeric ID, username and nickname. The access token is discarded after use and is not stored in the marketplace database.
- Available sign-in channels reflect the actual service configuration. If email is unconfigured, its quota is exhausted or sending fails, the page indicates that it is unavailable or asks you to retry later. GitHub is an alternative only when configured. Use your original channel when signing in again to avoid accessing a different account.
- The website uses a sign-in cookie; app connections use separate tokens. Signing out of the website does not revoke connected apps.

## Public and private information

| Public | Not public |
| --- | --- |
| Nickname, stars, review text, reviewed resource version, review ID and posting/editing times; a claimed author's GitHub username (or nickname for a manual claim); replies from the author or Teloa | Email digest, account ID, numeric GitHub ID, reporter identities and reasons, sign-in and app connection tokens |

Moderators can handle pending content, reports and accounts; this does not make private information visible to other users. Do not put passwords, keys, private contact details or someone else's personal information in nicknames, reviews or replies. Others may copy public content; deletion cannot recall copies they have saved.

## Reviewing on the website and in the app

- Resource pages let you read reviews, post, edit or delete your own review, and report other people's reviews. The account page shows your reviews, replies, reports and claims.
- In the app's official catalog, “Reviews” shows reviews. To post, select “Connect marketplace account”, sign in through your browser, check the device code shown by the app, and approve the connection. Approve only connections you initiated; do not approve codes sent by someone else.
- The app token is kept in local encrypted credential storage. Disconnect in the app or revoke the connection on the [marketplace account page](https://market.teloa.ai/en/account/). An expired connection requires signing in or connecting again; unpublished content is not sent automatically.
- Posting requires your own confirmation on the website, in the app, or on a confirmation card in your own ordinary conversation. AI teammates, tasks and group conversations cannot post for you. Browsing or searching reviews in a conversation needs no posting confirmation; other users' text is reference material only.
- In the version under development, official npm CLI and container release launchers enable the online marketplace by default. Set `TELOA_MARKET_REMOTE=off` to disable it. The source host remains disabled by default; CI, browser acceptance and development environments are always excluded. Reviews follow the online marketplace setting; this is not a separate account or privacy control.

## Drafts and recovery

Website review and reply drafts are isolated by marketplace account in the current browser tab's session storage. Changing a nickname within the same account preserves recovery; switching accounts does not show the previous account's drafts. Drafts are not synced to the server or included in account exports. Closing the tab normally clears them, but browser session restoration may retain them. Clear site data on shared devices.

A draft may temporarily exceed the publishing limits for text or links; edit it to meet the rules before posting. Each serialized draft may use up to 64 KiB. If it exceeds that size or the browser refuses storage, an immediate warning appears. Text remains on the current page but may be lost on refresh or navigation; copy it elsewhere first. Deleting the server account does not clear browser site data.

## Community rules and moderation

- One review per account per resource; you can edit or delete it. Resources must exist in the verified, signed official catalog. A rating is not proof of installation or verified results.
- Review and reply text may contain up to 2000 characters and two links; a review may consist of stars alone. Requests also have an 8 KiB UTF-8 limit. Do not post ads, abuse, irrelevant content or nicknames impersonating Teloa or official staff.
- Moderation defaults to approval before publication. New reviews, edits to ordinary reviews and author replies need approval; editing a hidden review leaves it hidden. Moderators' official Teloa replies are published directly. Unpublished reviews do not contribute to public ratings.
- Accounts younger than 24 hours can create at most three reviews per 24 hours; other accounts can create at most 20. Sign-in, human verification and rate limits may further restrict frequent requests.
- Signed-in users can report other people's public reviews. Reports from at least three accounts that are each at least 24 hours old automatically hide a review pending moderation. A review restored with an exemption from automatic hiding is no longer hidden by that rule. Moderators can approve, hide, restore or delete reviews and replies, or ban accounts.
- GitHub personal repository owners can claim resources after checks of the catalog source, repository owner type and numeric GitHub identity. **Public organization membership is not proof of ownership.** Organization repositories and other resources that cannot be claimed automatically require an Issue for manual verification. Claimants cannot review resources they have claimed.
- Do not post reviews if you are under 18. Ratings are reference signals, not purchase, installation or security guarantees.

## Deletion and export

The [marketplace account page](https://market.teloa.ai/en/account/) provides a JSON download containing your account profile, reviews, replies, reports, claims and app connection records. It does not export raw email addresses, sign-in tokens, server secrets, browser drafts or moderator audit records.

Account deletion removes the server account, sessions and app connections, device authorizations, your reviews and replies, other people's replies and reports on your reviews, your reports and claims, and code records for your email digest in one operation. Independent global email counters and moderator audit records follow the retention periods below. Edge caches may briefly show old content: up to about 60 seconds for review lists and 300 seconds for rating summaries.

## Processors, storage and retention

- The service uses Cloudflare Workers and D1, with an Asia-Pacific deployment direction. D1's `apac` location hint does not guarantee storage exclusively in Singapore. Production resources still need configuration.
- Resend receives the recipient address and code text to deliver sign-in codes. The marketplace database does not store raw email addresses. Resend's own logging, retention and processing terms must be checked before launch; the marketplace's storage limits do not mean that the email provider retains no data.
- Cloudflare receives network requests and provides rate limiting and Turnstile human verification; verification requests include the source IP. The marketplace business database does not store IP addresses, countries, cities or automatically collected device information. App connections retain a label, creation time and last-use time. Infrastructure providers' network processing and logs require separate verification.
- Code records and email counters become eligible for cleanup after about two days. Sign-in redirect state and device codes expire after 10 minutes; web sessions after 30 days; app connections after 180 days. Expired credentials are unusable immediately, but rows are removed by daily cleanup, not necessarily at the instant of expiry.
- Moderator audit records become eligible for cleanup after 365 days and include the actor ID, action, target ID and time. Account deletion does not remove audits early. Reviews and related content remain until deleted by the user or a moderator.

## Release and compatibility boundaries

The website and Worker must ship together: update the Worker first, then the website, and finally release the app with the online marketplace enabled by default. The new website uses the identity-bearing `/v1/me/export` response as its consistent source of private records. `reviews[]` in `teloa.market-account-export/v1` now includes each existing review's `id`; no database field or endpoint is added. If an old export contains a review without `id`, the new website reports unavailable records and disables related editing. It does not fall back to a read interface that cannot bind records to an account identity. Tools parsing exports need to allow additional fields.

Before launch, operator and compliance checks, production Cloudflare configuration, email domain verification and real delivery, GitHub OAuth callbacks, real Turnstile site keys, and security mailbox delivery remain required. Local fixture tests cannot replace these checks.
