Privacy
This page explains what mrviper111.dev (this website) collects, why, and what happens to it. In short: only what's needed to run the site, keep it secure, and understand how it's used.
What I keep
- Your chosen username and email
- Your password, which is stored hashed so I never see the real one
- Anything you add yourself, like an avatar or about me
- Logs of account activity, such as sign-ins, password changes, and clearance changes
- A fingerprint of the browser you sign in with. It's a hash, not your actual browser details, and it only exists so the site can tell when a sign-in comes from somewhere new
- Failed sign-in attempts, so the account can lock itself after too many wrong passwords
What I do with it
Only what's needed to run the site: sign you in, give you access to what you're allowed to use, keep things secure, and send the occasional account email such as a password reset.
I don't build a profile of you, and I don't look through accounts out of curiosity. The activity log exists so that if something goes wrong on an account, there's a record of what actually happened.
Keeping it secure
Passwords are hashed before they're stored, so there's nothing in the database that can be read back as your password. Not by me, and not by anyone who somehow got hold of a copy.
After five failed sign-ins the account locks for fifteen minutes, which makes guessing a password impractical. If a sign-in comes from a device that hasn't been used on your account before, you'll get an email about it. If you ever think someone else is in your account, Settings has a button that ends every other session and leaves only the browser you're currently using.
Cookies and analytics
The site sets a cookie to keep you signed in and another to remember whether you chose light or dark mode. Neither one follows you anywhere else.
Umami handles basic traffic numbers, things like which pages get visited and how often. It's self-hosted, so those numbers stay on my server rather than going to an analytics company. There's no advertising and no cross-site tracking, and there won't be.
Who else touches it
Account email, such as password resets and new device alerts, is delivered through Resend. They handle sending the message and can see the address it goes to.
The site runs on a server I rent, so the hosting provider has access to the machine in the same way any host does.
That's the entire list. No advertising networks, no data brokers, nobody paying me for any of it.
What you control
Your avatar, your about me, and your password can all be changed or cleared from Settings at any time. So can your sessions, if you left yourself signed in on a machine you no longer have.
If you want your account and everything attached to it deleted, email me and it's done. There's no form and no waiting period. For a site this size I'd rather you just ask me directly.
How long I keep it
Your account and the things attached to it stay for as long as the account does. Sign-in history and failed attempt records are kept for a limited period and cleared after that, since they stop being useful for security fairly quickly.
Everything else
I don't sell your data and I don't share it for marketing. This is a personal site for a handful of people, not a business with a growth target.
If you have a question about any of this, email me at [email protected]. If any of it changes, I'll update the date at the top.