Privacy

Privacy Policy

Last updated

This page explains what Pradakshina collects, why it collects it, how long it keeps it, and what you can ask us to do about it. It covers the account service on this site.

What we collect

Only what an account needs to work:

  • Your name and email address. Required to create an account. The email address is also how you sign in and how we send verification and recovery codes.
  • Your password, as a hash. We never store the password you type. It is put through a one-way hash (bcrypt), so nobody here can read it, and we cannot tell you what it is if you forget it.
  • Optional profile details. Phone number, date of birth, postal address and a profile photo, if you choose to add them. You can change or clear them at any time from your account pages.
  • Verification codes. Stored hashed, against the address they were sent to, with a count of failed attempts.
  • Session and security data. A session record with your IP address while you are signed in, and a short-lived record of failed sign-in and code requests so we can rate-limit abuse. The rate-limit records identify a client by a hash of the IP address, not the address itself.

We do not collect payment details, we do not buy data about you from anyone, and we do not run advertising or tracking profiles.

Why we collect it

  • To create and operate your account, and to sign you in.
  • To confirm you control the email address on the account, at signup and whenever it changes.
  • To let you recover access if you forget your password.
  • To keep the service secure — rate-limiting, ending sessions after a password change, and telling you when your address is used.
  • To answer you if you get in touch.

Email we send you

All of it is transactional. There is no marketing list to unsubscribe from. We email you to send a verification or recovery code, to tell your old address that the email on your account was changed, and to tell you if somebody tried to register using your address.

That last one is deliberate: registration gives the same answer whether or not an address already has an account, so a stranger cannot use the signup form to find out where you have accounts. You get told instead.

Cookies

Two, both strictly necessary, neither used for tracking:

  • Session cookie. Identifies your signed-in session. It expires after two hours of inactivity, and is marked HttpOnly and SameSite=Strict so other sites cannot read or send it.
  • CSRF cookie. Protects forms against being submitted from another site on your behalf.

Because neither is used for analytics or advertising, there is no cookie banner asking you to accept them — you cannot use an account without them.

Who else sees your data

  • Our email provider, which delivers the codes and notices described above and therefore handles your email address.
  • Google Fonts, which serves the typeface used on this site. Loading a font means your browser contacts Google and reveals your IP address and the page you are on.
  • Our hosting provider, which stores the database and the uploaded profile photos.

We do not sell your data or share it for anyone else's marketing. We disclose it only where the law requires it.

How long we keep it

  • Unconfirmed signups — deleted ten minutes after you start, if you never confirm.
  • Verification and recovery codes — ten minutes, or immediately once used or exhausted.
  • Sessions — two hours of inactivity, and ended immediately when you sign out or change your password.
  • Rate-limit records — minutes, long enough to enforce the limit.
  • Your account and profile — for as long as the account exists. Deleting an account removes its profile record and its photo.

Security

Passwords are hashed, never stored or logged in readable form. Verification codes are hashed too, capped at five attempts and expired after ten minutes. Sessions are held server-side, are re-issued when you sign in, and are invalidated everywhere else when your password changes. Changing the email address on an account requires your current password, and the old address is told about it.

No service can promise perfect security, and this one does not. If you believe an account has been accessed by somebody else, change the password immediately and contact us.

Your choices

  • See and correct your data — your name, photo and contact details are editable from your account pages.
  • Change your email address — from the same place, after confirming your password and the new address.
  • Ask for a copy, or for deletion — contact us and we will act on it.

Depending on where you live you may have further rights over your data, including objecting to how it is used and complaining to a data protection authority. Contact us and we will tell you how that applies to you.

Children

This service is not aimed at children, and accounts are not knowingly created for them. If you believe a child has an account here, contact us and we will remove it.

Changes to this policy

If this policy changes materially, the date at the top of the page changes with it. Please check back occasionally.

Contact

Questions about this policy, or a request about your data — our contact details are here, or write to hello@pradakshina.in.