Privacy
What this archive keeps, what it deliberately does not, and how to remove what it has. Written from the database schema rather than from a template, so it is specific enough to be checked.
Last reviewed 14 August 2026
Reading needs no account, and records nothing
Every ruling, every topic, every search result on this site is readable with no account, and reading them creates no record of you. There is no advertising network, no third-party analytics, no tracking pixel and no cookie set for any purpose other than keeping you signed in if you choose to be.
If you never make an account, this site stores nothing about you at all.
Bookmarks made without an account live in your own browser’s storage and are never sent to us. Clearing your browser data removes them, and they do not follow you to another device — that is the whole of the trade, and the bookmarks page says so on its face.
What an account holds
An account exists to remember what you found. Everything in the table below is either something you typed or something the site cannot work without.
| Kept | What it is, and why |
|---|---|
| Your email address | The only thing that identifies the account. Used to sign you in, to confirm the address, and to reset a password. Never sold, never shared, and never used to send you anything you did not ask for. |
| Your password | Stored as a one-way hash, never as text. Nobody here can read it, including us. |
| Bookmarks and notes | Yours, private, and never shown to anyone else or published. There is no public commenting on this site by design. |
| Reading history | Which rulings you have opened, so the site can show you where you were. It can be switched off in Preferences, and switching it off stops it being written rather than merely hiding it. |
| Signed-in devices | One row per browser you are signed in on: the browser’s description, when it was last used, and a hash of the address it came from — never the address itself. You can see the list and end any of them from your account. |
| Your preferences | Theme, text size, timezone, date format, and the switches above. |
Searches are counted, and not attributed
The site keeps an aggregate record of what is searched for: the search text, how many results it found, and which filters were applied. This is the only evidence there is for which questions the archive answers badly, and it is where improvements to search come from.
Those rows carry no identity. No account, no session, no address — not as a setting that could be turned on later, but by construction: the code that writes them has no access to any of it. People ask this archive about their marriages, their debts and their illnesses, and knowing what a community asks about does not require a record of who asked what.
If you would rather your searches were not counted even in that form, there is a switch for it in Preferences. Search history you can see and re-run is a separate thing, kept for you and deleted with your account.
Addresses are hashed, everywhere they are used at all
Your IP address is used to rate-limit sign-in and registration attempts, which is what stops somebody guessing passwords against every account on the site. It is stored as a one-way hash and never in the clear — a hashed key supports an exact lookup and nothing else. It cannot be browsed, joined to an account, or turned back into an address.
The same is true of the record of administrative actions, which exists so that changes to the archive are accountable.
When something breaks, the fault is recorded — not the person
If a page fails, the site records what broke: the error, the address of the page it happened on with any query string removed, and the kind of request it was. Without that, a fault that only happens to other people is a fault nobody can fix.
No cookies, no session, no account and no IP address are stored with it — not hashed, absent. The request is right there when an error is caught, which is exactly why this is worth stating: the code that writes these rows takes the page address and nothing else off it. The query string is dropped because it can carry what you typed into the search box.
One row is kept per distinct fault rather than per occurrence, so the record says that something broke and how often — never who was reading when it did.
How long things are kept
- Your account and everything in it — until you delete it. There is no expiry and no inactivity purge.
- Signed-in devices — until the session expires or you end it.
- The aggregate search log — capped at 400 days, then pruned.
- Rate-limit counters — hours, then discarded.
- Recorded faults — 30 days once dealt with, 180 days otherwise.
Deleting your account
Deletion is a deletion. Your row is removed and eleven tables that reference it go with it — sessions, tokens, bookmarks, notes, reading history, search history and the rest. It is not a flag on a row that stays behind, because a record kept under a “deleted” status is still a record holding your email address, and that is not what asking to be deleted means. It frees the address, so you can come back later if you want to.
Two things deliberately survive, with the link to you severed rather than stored: a problem report you sent us, and — for staff accounts — the log of corrections made to the archive. Those rows are about the archive rather than about you, and after deletion nothing connects them to a person.
The control is at the foot of your account. It costs your password, and a second-factor code if you have one, for the same reason signing in does: a borrowed browser must not be able to destroy your reading.
Who else is involved
The site runs on Vercel, which hosts it and necessarily processes the requests that reach it. Email — address confirmation, password resets — is sent through Resend. Both are service providers acting on our instructions; neither is given your reading, your bookmarks or your notes.
The rulings themselves come from Askimam.org and are republished with permission. Following that link leaves this site, and what happens there is governed by their terms rather than ours.
Asking us something
If you want to know what is held about you, or want it removed and would rather not do it yourself, the contact form reaches us with your account already attached, so there is nothing to prove and no exchange of emails establishing who you are.