policy/ privacy

What we hold, and what we do with it

We hold real personal data — email addresses, session tokens, RSVP timestamps, and the IP addresses in a server's log. This page says what each one is for, how long it stays, who else touches it, and how you get it back or get rid of it. Nothing here is sold. Nothing here is shared with anyone who would rather have it.

the short version

what we hold, row by row

This is the real schema, column by column. It is not a summary of a schema — it is the list, and a test in the build fails if the database grows a column that can hold someone's data and this list has not changed with it.

User— Your account. One row is one person.

columnwhat it iswhy we hold itbasiskept
emailthe address you signed up withto sign you in, and to answer you when you write to uscontractthe service you joineduntil you delete your account, plus 30 days in backups
handleyour public name on the site, for example /u/yourhandleso you have a public page without giving us your real namecontractthe service you joineduntil you delete your account
namea display name, only if you typed oneso people recognise youcontractthe service you joineduntil you delete your account
passwordHashnot exporteda scrypt hash of your password with a per-user saltso we can check a password without storing it. Your password itself is never stored and never loggedA hash is not readable, and a second copy of it would be a second copy of your credential. We tell you it exists instead of handing it over.contractthe service you joineduntil you delete your account
githubIdyour GitHub numeric id, only if you sign in with GitHubso one GitHub identity is one person across our sitescontractthe service you joineduntil you delete your account
githubLoginyour GitHub login, only if you connect itto show it on your profilecontractthe service you joineduntil you delete your account
googleIdyour Google id, only if you sign in with Googleso a Google identity joins your account instead of making a second onecontractthe service you joineduntil you delete your account
avatara picture URL, only if you set oneso your profile is recognisablecontractthe service you joineduntil you delete your account
bioyour own words, up to 600 charactersit is your profilecontractthe service you joineduntil you delete your account
websitea link you put on your profileit is your profilecontractthe service you joineduntil you delete your account
locationwhere you are, in your own wordsyou typed it. We never infer it from an IP addressconsentyou asked for ituntil you delete your account
pronounsyour pronouns, if you set themyou set them, for other peopleconsentyou asked for ituntil you delete your account

Session— Your sign-ins. One row is one device you are signed in on.

columnwhat it iswhy we hold itbasiskept
tokennot exportedthe random string in your session cookieit is the session itself, and it is httpOnly so no script on the page can read itWe will not put a live credential in a download. We show you when each session was made and when it expires instead.contractthe service you joined30 days, then it stops working and the row is deleted
userIdwhich account the session belongs toit is how we know who is signed incontractthe service you joinedwith the session
expiresAtwhen the session stops workingso an old session cannot be used forevercontractthe service you joinedwith the session
createdAtwhen you signed in on that deviceso you can see and revoke a sign-in you do not recognisecontractthe service you joinedwith the session

Rsvp— You saying you are coming to a session.

columnwhat it iswhy we hold itbasiskept
userIdthat you are comingso the count on a card is a real count and you can change your mindcontractthe service you joineduntil you delete your account
eventIdwhich sessionso the room knows who to expectcontractthe service you joineduntil you delete your account
goingyes or noa yes and a no are both the recordcontractthe service you joineduntil you delete your account
createdAtthe exact time you said itin an RSVP the timestamp is the datacontractthe service you joineduntil you delete your account

Project— Something you built and listed publicly.

columnwhat it iswhy we hold itbasiskept
authorIdthat you wrote itso the listing is attributable and you can edit itcontractthe service you joineduntil you delete your account
namethe name of the projectit is the listingconsentyou asked for ituntil you unlist it
urlwhere it livesso people can go and look at itconsentyou asked for ituntil you unlist it
repothe repository, if you listed oneso people can read the sourceconsentyou asked for ituntil you unlist it

what we do on what basis

purposebasiswhat we do
Signing in, RSVPs, the roomcontractDo it. It is the service you joined.
Reading the coursescontractDo it. The free ground stays free.
Anything sold or shared—Never. There is no version of this where we do.
Email about sessionsconsentThere is no mailing list and no opt-in box on this site yet, so there is nothing to consent to and nothing to withdraw. When there is one it will be a separate, unticked checkbox that is not the sign-in button, and it will be written here the day it ships - not after.

who else touches it

These are the services that process data because you used them. A provider that merely carries a request is named too, because pretending otherwise is how people get surprised.

how long

Your account, your RSVPs
Until you delete it. There is no expiry we sneak in.
Session rows
30 days. The cookie stops working at the same moment.
Server logs with your IP
As long as a server log is kept, and nothing is built from them.
Backups
A deleted account stays in a backup until that backup ages out. We cannot promise it is gone from the tape the instant you press the button, and we are not going to pretend otherwise.
Email about sessions
There is no such list yet, so nothing is kept. If it is built, it is opt-in, and this page changes the same day it does.

your two doors

Both are one click, both need you to be signed in, and neither of them can be used on anyone else — the routes read your session and take no id from the page. You can also ask us by email and a person will do it for you.

signed-in only · no id is ever taken from this page

what we cannot reach

Delete your account and these stay. We would rather list them than have you find out in two years.

and what is not here

cookies

agf_sessionessential · no consent needed

Your sign-in. It is an httpOnly cookie: the page cannot read it, and no script on the page can read it.

None. No analytics, no advertising, no third-party pixels, no trackers. If that ever changes it needs your consent first, and the notice at the top of every page will say so before it happens.

    One cookie. We set exactly one, agf_session, and it is your sign-in — without it you are not signed in. No analytics, no advertising, no trackers. What we hold, in full.