The Code · Privacy
Privacy, in plain language.
We collect the information needed to run a reader account: your email address, password, name, comments, likes, and saved posts. Your password is handled by Supabase Authentication; we do not see or store it in readable form.
Why we use it
We use this information to create and secure your account, show your profile, publish your comments, and remember what you have liked or saved. We do not sell your data or share it with advertisers.
Services that help run the site
Supabase provides account authentication and database hosting. Vercel Analytics records cookieless page views so we can understand how the site is used. Cloudflare Turnstile helps us block automated abuse on account forms. When email delivery is active, Resend will send account emails such as confirmations and password resets.
Delete your data
You can delete your account from account deletion in your profile. After a successful deletion, your account, profile, comments, likes, and saved posts are removed from the live database, including legacy quarantine copies linked to you by their original account-owner field. This cannot be undone through the site. Curated essays and other people’s data are kept; if you authored a curated essay, its account link is removed.
What may remain after deletion
Deletion does not immediately erase existing backups or service-provider logs. Backups can contain older account data until they are removed; we do not currently guarantee a fixed backup-deletion period. Historical records whose owner cannot be established need separate review. We cannot promise to remove copies other people have already made of public comments.
For abuse prevention, we keep keyed hashes derived from email addresses and IP addresses, rather than the original values, in login and signup rate-limit records. These are pseudonymous, not guaranteed anonymous. They are not linked by account ID and are not erased by account deletion. Login records stop counting after 15 minutes and signup records after one hour; expired records are removed in batches during later authentication attempts and may remain longer if no cleanup runs.
A publication administrator’s email address may also remain in a separate admin-access allowlist after their account is deleted. Removing that access configuration requires a separate review. It is not a list of reader accounts.
Questions
If something here is unclear, please contact us before creating an account or sharing information on the site.