We hold real personal data — email addresses, session tokens, RSVP timestamps, and the IP addresses in a server's log. This page says what each one is for, how long it stays, who else touches it, and how you get it back or get rid of it. Nothing here is sold. Nothing here is shared with anyone who would rather have it.
agf_session, your sign-in. It is essential, so it does not need your consent, and it is httpOnly so no script on the page can read it.This is the real schema, column by column. It is not a summary of a schema — it is the list, and a test in the build fails if the database grows a column that can hold someone's data and this list has not changed with it.
| column | what it is | why we hold it | basis | kept |
|---|---|---|---|---|
| the address you signed up with | to sign you in, and to answer you when you write to us | contractthe service you joined | until you delete your account, plus 30 days in backups | |
| handle | your public name on the site, for example /u/yourhandle | so you have a public page without giving us your real name | contractthe service you joined | until you delete your account |
| name | a display name, only if you typed one | so people recognise you | contractthe service you joined | until you delete your account |
| passwordHashnot exported | a scrypt hash of your password with a per-user salt | so we can check a password without storing it. Your password itself is never stored and never loggedA hash is not readable, and a second copy of it would be a second copy of your credential. We tell you it exists instead of handing it over. | contractthe service you joined | until you delete your account |
| githubId | your GitHub numeric id, only if you sign in with GitHub | so one GitHub identity is one person across our sites | contractthe service you joined | until you delete your account |
| githubLogin | your GitHub login, only if you connect it | to show it on your profile | contractthe service you joined | until you delete your account |
| googleId | your Google id, only if you sign in with Google | so a Google identity joins your account instead of making a second one | contractthe service you joined | until you delete your account |
| avatar | a picture URL, only if you set one | so your profile is recognisable | contractthe service you joined | until you delete your account |
| bio | your own words, up to 600 characters | it is your profile | contractthe service you joined | until you delete your account |
| website | a link you put on your profile | it is your profile | contractthe service you joined | until you delete your account |
| location | where you are, in your own words | you typed it. We never infer it from an IP address | consentyou asked for it | until you delete your account |
| pronouns | your pronouns, if you set them | you set them, for other people | consentyou asked for it | until you delete your account |
| column | what it is | why we hold it | basis | kept |
|---|---|---|---|---|
| tokennot exported | the random string in your session cookie | it is the session itself, and it is httpOnly so no script on the page can read itWe will not put a live credential in a download. We show you when each session was made and when it expires instead. | contractthe service you joined | 30 days, then it stops working and the row is deleted |
| userId | which account the session belongs to | it is how we know who is signed in | contractthe service you joined | with the session |
| expiresAt | when the session stops working | so an old session cannot be used forever | contractthe service you joined | with the session |
| createdAt | when you signed in on that device | so you can see and revoke a sign-in you do not recognise | contractthe service you joined | with the session |
| column | what it is | why we hold it | basis | kept |
|---|---|---|---|---|
| userId | that you are coming | so the count on a card is a real count and you can change your mind | contractthe service you joined | until you delete your account |
| eventId | which session | so the room knows who to expect | contractthe service you joined | until you delete your account |
| going | yes or no | a yes and a no are both the record | contractthe service you joined | until you delete your account |
| createdAt | the exact time you said it | in an RSVP the timestamp is the data | contractthe service you joined | until you delete your account |
| column | what it is | why we hold it | basis | kept |
|---|---|---|---|---|
| authorId | that you wrote it | so the listing is attributable and you can edit it | contractthe service you joined | until you delete your account |
| name | the name of the project | it is the listing | consentyou asked for it | until you unlist it |
| url | where it lives | so people can go and look at it | consentyou asked for it | until you unlist it |
| repo | the repository, if you listed one | so people can read the source | consentyou asked for it | until you unlist it |
| purpose | basis | what we do |
|---|---|---|
| Signing in, RSVPs, the room | contract | Do it. It is the service you joined. |
| Reading the courses | contract | Do it. The free ground stays free. |
| Anything sold or shared | — | Never. There is no version of this where we do. |
| Email about sessions | consent | There is no mailing list and no opt-in box on this site yet, so there is nothing to consent to and nothing to withdraw. When there is one it will be a separate, unticked checkbox that is not the sign-in button, and it will be written here the day it ships - not after. |
These are the services that process data because you used them. A provider that merely carries a request is named too, because pretending otherwise is how people get surprised.
your login and id, only if you choose GitHub sign-in
we store your GitHub id, not your GitHub password, and we never post to your account
whatever you post in the Discord, under Discord's own policy
the Discord is a separate service with its own data. Deleting your account here does not delete what you wrote there.
the request, including your IP, as every reverse proxy does
it is the tunnel in front of the site. This is the one place an IP is unavoidable.
your name, email and order, only if you buy the $49 rung
we cannot delete your order there for you. It is your receipt and your card, and Gumroad holds the card details. Write to us and we will help you find the button.
nothing yet
the forum is not live. When it is, it will be a separate store with its own policy, and signing up there is a separate act.
Both are one click, both need you to be signed in, and neither of them can be used on anyone else — the routes read your session and take no id from the page. You can also ask us by email and a person will do it for you.
Delete your account and these stay. We would rather list them than have you find out in two years.
the server writes them to protect itself from abuse. They are not in the account database, they are not attached to your account, and nothing else reads them. We keep them as long as a server log is kept, and we build nothing on top of them.
LearnAI holds course content only. It has no accounts and no user table.
agf_sessionessential · no consent neededYour sign-in. It is an httpOnly cookie: the page cannot read it, and no script on the page can read it.
None. No analytics, no advertising, no third-party pixels, no trackers. If that ever changes it needs your consent first, and the notice at the top of every page will say so before it happens.
One cookie. We set exactly one, agf_session, and it is your sign-in — without it you are not signed in. No analytics, no advertising, no trackers. What we hold, in full.