Accounts soon

Plain sentences

Privacy

Written from the code rather than from a template. Every claim here is true of this repository as it stands, and the imperfect parts say so.

Privacy at a glance

What data this service holds, why, whether it identifies you, who else handles it, and how long it is kept.
WhatWhyTied to you?Who elseKept
Reading pagesNothing is storedNoVercel request logs, as any host keepsVercel's log retention
Page viewsSeeing which entries get readNo — anonymisedGoogle Analytics, only if switched on (it is not, today)Google's default
Light or dark themeRemembering the one you pickedNo — stays in your browserNobodyUntil you clear site data
A message you sendReplying to youYesResend, which delivers the emailUntil you ask for it to be deleted
Account email and sign-inSigning you inYesNeon Auth (Stack Auth); Google or GitHub if you sign in with themUntil you delete the account
Your registerPublishing itYesNeon, which stores itUntil you delete it
PaymentCharging onceYesStripe — your card never reaches this siteA purchase record, for accounts
Failed console sign-insLocking out guessingIP address, encryptedNobodyThirty days

What this site stores about you

If you only read it: nothing. There are no advertising or tracking cookies and no cross-site profile, and reading this page leaves nothing behind that identifies you. If you make an account to keep a register of your own, the service holds your email address and whatever you put in the register — the label above says exactly where.

Analytics

If Google Analytics is configured, it records anonymised page views with IP anonymisation switched on, and ad storage, ad personalisation and ad user data all set to denied before the first event fires. It is used to see which entries people read. It is not used to build an audience, and nothing is shared with an advertising network.

If you send a message

Your name, address and what you wrote reach me by email so that I can reply. They are not added to a mailing list, not passed to anyone, and not used for anything other than answering you. Ask me to delete the thread and I will.

Where the data behind this site lives

The register itself is kept in a Postgres database on a personal machine that has no public network path — not a tunnel, not an open port. The published site is a static snapshot generated from it. That means there is no live database for anyone to reach from the internet, including me.

The one thing that is encrypted, and why

The private console records failed sign-in attempts so that it can lock out repeated guessing. Those records include IP addresses, which are personal data, so the address column is encrypted at rest and the lookup runs against a keyed fingerprint rather than the address itself. Attempt records are deleted after thirty days.

Cookies

The public pages set no cookies at all, which is why there is no consent banner — there is nothing to consent to. Signing in to an account sets a session cookie so that you stay signed in; the private console sets its own, marked HttpOnly, Secure and SameSite=Strict. Pressing the light/dark switch stores your choice in your own browser, not in a cookie, and only because you asked it to remember.

Third parties

For someone only reading: Vercel hosts the site and sees request logs as any host does, and Google Analytics runs only if it is configured. Fonts are self-hosted from this domain, so no font request identifies you to anyone. For account holders, four more: Neon Auth handles sign-in, Neon stores registers, Stripe takes payment, and Resend delivers email. None of them is sent anything beyond what the label above lists, and none of it is sold.

Having something removed

Email hello@display.archi and say what you want gone. Every message gets a reply within two working days. There is no form to fill in and no verification hoop.

This covers display.archi both as a personal register and as a service that keeps registers for other people. Accounts are not open yet; the parts about them describe the system as it is built, so this page is already true on the day they open. If what the service collects changes, this page changes with it — a policy stretched to cover something it was not written for is how these documents start lying.