PRIVACY
What this site stores
This is a plain description of what this site stores and why. It is written to be checkable against the code rather than to be comprehensive in a legal sense.
This describes the current behaviour of the site accurately. It is not yet a reviewed privacy policy, and one is required before the site is publicly reachable.
What we store
An account holds the following, and nothing else:
- Email address
- Required. It identifies the account and receives verification and password-reset links.
- Name
- Optional, and shown only to you. Never required, never published.
- Password hash
- Argon2id. The password itself is never stored and cannot be recovered from the hash.
- Session identifiers
- A SHA-256 hash of the session token, its expiry, and when it was created. The token itself exists only in your browser cookie.
- Google account id
- Only if you sign in with Google: the account identifier Google issues, so the same Google account maps to the same Atheror account. Stored only after Google confirms the address is verified.
- Early-access application
- Only if you send one: your answers to the five questions on the early-access form, and when you sent or changed them. Read by the two people who run Atheror to decide who gets in first. Deleted with the account.
- Email tokens
- A hash of each verification or reset link, and its expiry. Deleted when used or when a newer one is issued.
Cookies
One cookie, set when you sign in: an httpOnly session token that expires after 30 days. It exists so the site knows you are signed in. There is no analytics, no advertising and no third-party tracking on this site.
During a Google sign-in, three further cookies exist for ten minutes and are deleted the moment the sign-in finishes. They hold the anti-forgery values that make the handshake safe.
Google sign-in
If you choose it, Google tells us your email address, whether Google has verified it, and your display name. We store the first two and the account identifier. Nothing is sent back to Google beyond completing the sign-in itself. You can add a password later and disconnect Google entirely.
Verification and password-reset links are sent through an email provider. No marketing mail is sent, because there is no marketing list.
Deleting everything
The security page in your account deletes the account without asking anyone. It removes the account row and, with it, every session, every connected sign-in method and every outstanding link. There is no archive and no recovery.