What is stored

We store your email address, an internal user ID and the creation date. If you turn on two-factor authentication, we also hold your authenticator secret (kept by our authentication provider) and hashed recovery codes.

Passwords

Your password is sent over HTTPS to our login gateway, which passes it to Supabase Auth. It is stored there only as a salted hash, and the gateway does not keep it.

Cookies

A few HttpOnly cookies keep you signed in. There are no analytics, advertising or tracking cookies.

Third parties

Supabase (accounts and database) and Cloudflare (hosting, the login gateway and Turnstile bot checks). They may log IP addresses and request times. No other third-party code is loaded.

Suggestions

Suggestions are encrypted in your browser to a key only I hold. Supabase can see that one was sent and when, not what it says.

Your data

You can delete your account from the account page, or ask a question on the contact page. Last updated October 2026.