CH Clowley Hub responsibility · v1.4 · 2026-05-25
Responsibility · data, limits & obligations

How Clowley Hub works — and what we don't promise.

Clowley Hub is a thin layer over GitHub: a directory and a download shortcut. The apps, the code, and the releases all belong to their authors. Before you install anything, please skim this page — it explains what we verify, what we don't, and the limits of our responsibility.

Effective May 25, 2026 · Replaces all prior versions · Reading time ~4 min

01 Where the data comes from

Every app you can install through Clowley Hub originates from a public repository on github.com. We index release metadata via GitHub's public APIs and surface what publishers have already made available there — names, descriptions, release notes, version tags, asset URLs, checksums.

We do not host the original source code, and we do not maintain mirrors of the binaries we link to. When you click "Install", you are downloading a file that lives on the publisher's release infrastructure, by way of the URL they registered with GitHub.

  • Index data is refreshed automatically — typically every few minutes after a release event.
  • Display names, taglines and category labels are pulled from the repository's README.md, manifest and Hub-specific .clowley.yml if present.
  • Statistics (stars, forks, watchers, last commit) reflect what GitHub reports at the time of the last sync.

02 What Clowley Hub does

Hub is a directory and a delivery shortcut. Concretely:

  • Browses and filters releases across platforms (Windows, macOS, Linux, Android, iOS).
  • Verifies the publisher's signed checksum on download, where one is provided, and flags mismatches.
  • Surfaces a "verified publisher" badge for repositories that opted into Hub's verification handshake. The badge confirms identity, not code quality.
  • Records platform-specific install commands for each release, so the one-liner in our UI matches the upstream tag.

03 What we don't do

We're transparent about the limits of our role:

  • We do not audit, review, or test the source code of apps on Hub.
  • We do not scan binaries for malware. The "verified publisher" badge is about identity, not safety.
  • We do not endorse, certify, or vouch for any application's behaviour, license, or quality.
  • We do not own any of the trademarks or assets that appear on Hub. App names and logos belong to their respective authors.
  • We do not modify, re-sign, or repackage the binaries we link to — what you download is what the publisher uploaded.

04 Provided "as is"

By using Clowley Hub, you acknowledge that every app discovered, listed or installed through this site is provided "as is" and "as available", without warranty of any kind.

Liability disclaimer

Clowley Storage, Inc. and its operators make no representations or warranties of any kind, express or implied, about the completeness, accuracy, reliability, suitability, availability, legality, safety or non-infringement of any application, repository, release, binary, dependency, link or other content surfaced through the Hub. Under no circumstances shall the operators be held responsible for damages — including but not limited to data loss, device damage, malware infection, intellectual property infringement, license violation or any other direct, indirect, incidental, consequential or punitive loss — arising from the download, installation or use of any app, regardless of whether such damage was foreseeable.

If a repository violates someone else's rights, distributes malware, or otherwise causes harm, responsibility lies with the publisher of that repository — not with Clowley Hub.

05 Verify before you install

Hub gives you what you need to make your own call. The minimum we recommend on every install:

  • Read the README and the open issues. An app with no recent activity, no maintainers and no answers is a yellow flag.
  • Check the license. AGPL, GPL, MIT, BSD — they aren't interchangeable for your use case.
  • Compare the displayed sha256 on the install panel against the publisher's release notes on GitHub.
  • Cross-check the publisher handle. The "verified" badge means we confirmed identity. It does not vouch for code quality, license accuracy, or anything you build on top of the app.
  • Run new binaries in a sandboxed environment when in doubt — especially for desktop tools without an established reputation.
Friendly reminder

Open-source code is auditable, not automatically audited. The trade-off for the variety on Hub is that you are the last line of review for the things you install.

06 Cookies & tracking

Clowley Hub sets a small number of cookies and uses localStorage to keep the site usable. None of them follow you across other sites; we do not embed third-party advertising trackers.

  • Strictly necessary — keep the catalog responsive, remember your filter selections within a session, and rate-limit abusive traffic. Always on; required for the site to work.
  • Preferences — remember your selected platform, last visited category, and sort order between sessions. You can turn these off any time.
  • Anonymous analytics — aggregated page counts so we can see which apps are reached and which pages are useful. No GitHub-derived identifiers, no profiles, no cross-site tracking. Off by default until you opt in.

You can review and change your choices at any time — click Cookie settings to bring the consent banner back. Your decision is stored under clowley.cookies.v1 (in localStorage, mirrored to a cookie of the same name) and can be cleared by deleting site data in your browser.

EU / UK visitors

The banner you saw on first visit captures consent in line with the ePrivacy Directive and the UK PECR. Strictly necessary cookies are set without consent because the site cannot function without them.

07 Takedown & reporting

We are not a court, but we will act quickly on legitimate reports. If an app on Hub:

  • Distributes malware or malicious payloads,
  • Infringes someone else's copyright, trademark, or patent,
  • Impersonates another project or publisher,
  • Violates our content policy (e.g. illegal content, harassment tooling),

please write to [email protected] with the repository URL, the specific release tag, and a short description of the issue. We will respond, investigate, and de-list — or send the report upstream to GitHub — within five business days. While we do not host the binaries themselves, we can and do remove entries from the directory.

If you are the publisher of an app that was unfairly de-listed, the same address handles appeals.