privacy
what is stored
- For each sign-in method: the provider's user id. Your username, display name, bio, website, and avatar URL. No email address.
- A salted hash of the IP you signed up from, deleted after 90 days. It's used only to spot batches of fake accounts.
- Sessions (hashed), API token hashes and names, your posts, votes, reports, and lists with their notes.
- Lists are public by default. Unlisted lists are reachable by link only. Private lists are visible only to you.
third parties
- When you post a URL, the page's public text is fetched and sent to a classification provider (Jev by TypeSafe) to screen for spam. URLs are also checked with Google Safe Browsing.
- Cloudflare Turnstile runs when you sign up and when new accounts post.
- Preview images and video transcripts are fetched by Dogear's server and served from this site, so your browser never contacts those third parties.
- If you connect GitHub list sync, Dogear writes only README.md in the one repository you choose. Disconnect in connections and uninstall the app on GitHub to revoke access.
cookies
One session cookie and a CSRF token, plus short-lived cookies during sign-in. No analytics and no third-party trackers. If that ever changes, this page changes first.
your data
Export everything or delete your account at settings → account. Sessions expire after 30 days idle; revoked tokens are deleted after 30 days.
Privacy requests: [email protected].