Privacy
Short version: one cookie keeps you logged in, we don’t track you, and we don’t sell or share your data. Everything you upload is public — see below.
Cookies
We set exactly one cookie, session, when you log in. It’s httpOnly, sent only over HTTPS in production, and expires after 7 days. Its only job is keeping you signed in — there are no analytics, advertising, or third-party tracking cookies.
What we store
Creating an account stores your username, email address, and a bcrypt hash of your password — never the password itself. Your email is never shown to other users. We don’t use it to send marketing, and we don’t share it with anyone.
Third parties
We don’t run analytics and we don’t share your account data with third parties. Every asset on this site, including fonts, is served from this domain — your browser never contacts anyone else just from loading a page.
Uploaded documents are public
This is a public, content-addressed vault — not private storage. Anything you upload is stored on IPFS, pinned, and indexed in the open vault database. It can be fetched by anyone who has or discovers its address, and may end up replicated on other nodes outside our control, including ones we can’t reach to remove content from.
Only upload documents you’re genuinely fine having public, and make sure doing so is lawful for you — including any rules in your jurisdiction about sharing other people’s personal data or copyrighted material. That responsibility is yours.
Removing something
We can stop hosting our own copy of a document on request, but because the vault is designed to be freely copied and replicated, we can’t guarantee removal from copies we don’t control. Treat anything uploaded here as permanent and public.
Questions
This project is open source — you can read exactly how it works, or raise a question, on GitHub.
self-hosted · open source · no account required · privacy