Privacy
The people who use this site depend on not being identified. So the honest version of this page is short: we collect very little, and the things we deliberately do not collect are listed by name.
Last updated 15.09.2026 · United States · English is the binding version
This page contains placeholders. It must be completed before the service is advertised publicly. Anything written as [LIKE_THIS] is not yet filled in.
What we store
This list is the whole of it. It is not a summary — it is taken from the database schema itself.
Stored
- Your email address
- Your handle, and a folded form of it used to block lookalikes
- Your display name and your one line about what you sell
- Your links, and the labels and notes you gave them
- The names of things you offer
- Your own statements about yourself
- Which of the fifty card styles you picked
- Created and updated timestamps
- A session row: token, your id, and an expiry — nothing else
Never stored
- No IP address
- No user agent, no device id, no fingerprint
- No last-seen time and no login history
- No analytics table, no event log
- No password, anywhere — there is no password column at all
- No avatar file, and no image upload of any kind
- No prices, no orders, no payment data
- No messages, because there is no messaging
The avatar on your card is a drawn letter, not a photograph. There is no photograph to store and none to leak. A face photo is the single most dangerous file we could accept from the people who use this site, so the field does not exist.
No tracking, and no advertising
There are no analytics, no advertising, no tracking pixels and no third-party cookies. We do not sell, rent, or share personal information, and we never have.
There is one cookie: the session cookie that keeps you signed in, for up to thirty days. If you do not sign in, nothing is set. Your browser also remembers whether you chose the dark or light theme, under the neutral key theme — it stays on your device, never reaches us, and does not name this site.
Signing in
There are no passwords. You type your address and we email you a link. The link is short-lived, and it is stored only as a hash — a copy of our database does not yield a working login link. Using it once consumes it.
The liveness check, and the one place a photograph is involved
This needs saying precisely, because the rest of this page says we take no images. There is an optional check where the site asks you to photograph an everyday object, a hand gesture, and four digits written on a note — a combination invented at that moment, with sixty seconds to answer.
That photograph is sent, and it is never stored. It goes from your browser to our server, straight out to a vision model, and the variable goes out of scope. It is not written to disk, to file storage, or to any table. The model is asked three yes-or-no questions about the objects in the picture, and is explicitly told not to describe the person, not to guess their age, and not to comment on anything else.
The working rows for the check hold only what was asked and whether it passed. When the three steps are done, those rows are deleted and one sentence survives: that you answered three tasks we made up on the spot. No face, no ID document, and nothing that stays the same between two checks — deliberately, since permanent identifiers are the thing we warn sellers about.
Who else touches the data
- Vercel — hosting. Serves the site and runs the code.
- Neon — the database, on AWS in us-east-2 (Ohio).
- Resend — sends the sign-in emails. It sees the address a link is sent to.
- Vercel AI Gateway, and through it an OpenAI-family vision model — receives a liveness photograph at the moment it is checked, and only then. If you never do the check, nothing is ever sent there.
- Google Fonts — your browser fetches the typefaces directly from Google. That is the only third-party request any page here makes, and it happens whether or not you have an account.
Deleting everything
Open your page settings and type your own handle to confirm. That removes your row and, with it, your links, your offers, your statements, any checks, and your sessions. Pending sign-in links for your address are deleted too, so one already sitting in an inbox stops working.
There is no deleted_at field on this site. A tombstone is not deletion, so there is not one. What remains afterwards are ordinary operational traces outside our database — backups held by our hosts on their own cycles, and copies other people or search engines may have made of a public page while it was up. We cannot reach into those.
If you are in California
Under the CCPA as amended by the CPRA you may ask what personal information we hold about you, ask for a copy, ask us to correct it, and ask us to delete it. The delete button does all of this immediately and without asking anyone.
We do not sell personal information and we do not share it for cross-context behavioural advertising. There is no "Do Not Sell My Personal Information" process to run because there is no such transfer to opt out of. We will not treat you differently for exercising any of these rights. To make a request in writing, use [OPERATOR_EMAIL]; we may need to confirm you control the email address on the account, which is the only identifier we have.
Children
This service is for adults. It is not directed to children, and we do not knowingly collect information from anyone under 13, or permit anyone under 18 to hold a page. If you believe a child has given us information, write to [OPERATOR_EMAIL] and we will delete it.
Where the data lives
The database is in the United States. If you write to us from elsewhere, your information is processed in the United States.
Who we are
[OPERATOR_NAME], [OPERATOR_ADDRESS]. Privacy questions: [OPERATOR_EMAIL].