Last updated: February 18, 2026
This is our privacy policy in plain language. No legal tricks, no fine print games. Here's exactly what we do with your data.
We only collect what we need to make the platform work. Nothing extra.
bcrypt (a one-way algorithm). We literally cannot read it.
We use exactly two cookies. Both are functional — they keep you logged in and protect against cross-site attacks. That's it.
mdb_auth_token — a JWT session token. It's httpOnly (JavaScript can't read it), and expires after 24 hours.
csrf_token — a CSRF protection token. Prevents other websites from making requests on your behalf.
We do not use analytics cookies, advertising cookies, or tracking pixels. Zero.
Some apps on this platform use external services to provide specific features. We only send the minimum data needed. Here's the full list:
We want to be crystal clear about what we are not doing with your data:
Your data is yours. You can request a copy of your data or ask us to delete your account and all associated data. Contact us and we'll handle it.
If you stop using the platform, your data just sits there — we don't do anything sneaky with inactive accounts. If you want it gone, tell us and we'll wipe it.
If we change this policy, we'll update the date at the top. We won't silently change what we do with your data. If we ever make a major change, we'll make it obvious.