How Clowley Hub works — and what we don't promise.
Clowley Hub is a thin layer over GitHub: a directory and a download shortcut. The apps, the code, and the releases all belong to their authors. Before you install anything, please skim this page — it explains what we verify, what we don't, and the limits of our responsibility.
01 Where the data comes from
Every app you can install through Clowley Hub originates from a public repository on github.com. We index release metadata via GitHub's public APIs and surface what publishers have already made available there — names, descriptions, release notes, version tags, asset URLs, checksums.
We do not host the original source code, and we do not maintain mirrors of the binaries we link to. When you click "Install", you are downloading a file that lives on the publisher's release infrastructure, by way of the URL they registered with GitHub.
- Index data is refreshed automatically — typically every few minutes after a release event.
- Display names, taglines and category labels are pulled from the repository's
README.md, manifest and Hub-specific.clowley.ymlif present. - Statistics (stars, forks, watchers, last commit) reflect what GitHub reports at the time of the last sync.
02 What Clowley Hub does
Hub is a directory and a delivery shortcut. Concretely:
- Browses and filters releases across platforms (Windows, macOS, Linux, Android, iOS).
- Verifies the publisher's signed checksum on download, where one is provided, and flags mismatches.
- Surfaces a "verified publisher" badge for repositories that opted into Hub's verification handshake. The badge confirms identity, not code quality.
- Records platform-specific install commands for each release, so the one-liner in our UI matches the upstream tag.
03 What we don't do
We're transparent about the limits of our role:
- We do not audit, review, or test the source code of apps on Hub.
- We do not scan binaries for malware. The "verified publisher" badge is about identity, not safety.
- We do not endorse, certify, or vouch for any application's behaviour, license, or quality.
- We do not own any of the trademarks or assets that appear on Hub. App names and logos belong to their respective authors.
- We do not modify, re-sign, or repackage the binaries we link to — what you download is what the publisher uploaded.
04 Provided "as is"
By using Clowley Hub, you acknowledge that every app discovered, listed or installed through this site is provided "as is" and "as available", without warranty of any kind.
Clowley Storage, Inc. and its operators make no representations or warranties of any kind, express or implied, about the completeness, accuracy, reliability, suitability, availability, legality, safety or non-infringement of any application, repository, release, binary, dependency, link or other content surfaced through the Hub. Under no circumstances shall the operators be held responsible for damages — including but not limited to data loss, device damage, malware infection, intellectual property infringement, license violation or any other direct, indirect, incidental, consequential or punitive loss — arising from the download, installation or use of any app, regardless of whether such damage was foreseeable.
If a repository violates someone else's rights, distributes malware, or otherwise causes harm, responsibility lies with the publisher of that repository — not with Clowley Hub.
05 Verify before you install
Hub gives you what you need to make your own call. The minimum we recommend on every install:
- Read the README and the open issues. An app with no recent activity, no maintainers and no answers is a yellow flag.
- Check the license. AGPL, GPL, MIT, BSD — they aren't interchangeable for your use case.
- Compare the displayed
sha256on the install panel against the publisher's release notes on GitHub. - Cross-check the publisher handle. The "verified" badge means we confirmed identity. It does not vouch for code quality, license accuracy, or anything you build on top of the app.
- Run new binaries in a sandboxed environment when in doubt — especially for desktop tools without an established reputation.
Open-source code is auditable, not automatically audited. The trade-off for the variety on Hub is that you are the last line of review for the things you install.
07 Takedown & reporting
We are not a court, but we will act quickly on legitimate reports. If an app on Hub:
- Distributes malware or malicious payloads,
- Infringes someone else's copyright, trademark, or patent,
- Impersonates another project or publisher,
- Violates our content policy (e.g. illegal content, harassment tooling),
please write to [email protected] with the repository URL, the specific release tag, and a short description of the issue. We will respond, investigate, and de-list — or send the report upstream to GitHub — within five business days. While we do not host the binaries themselves, we can and do remove entries from the directory.
If you are the publisher of an app that was unfairly de-listed, the same address handles appeals.