Security is a core part of how this service is built and operated. This page summarises the measures we apply. We deliberately do not publish internal details that could assist attackers, but we want our users to know the principles we follow.
All pages, forms and interfaces of this website are served exclusively over TLS encrypted connections. Unencrypted requests are redirected to the encrypted version. Modern security headers restrict how content can be embedded and executed.
Passwords are stored only as strong one way hashes and are never kept or transmitted in readable form. Login and signup endpoints apply rate limiting and temporary lockouts against automated guessing. Email verification protects against account impersonation, and account deletion is available to every user directly in their profile.
Our servers are operated under a least privilege model, are kept updated and sit behind firewalls and an edge security layer that filters malicious traffic, hostile bots and denial of service attempts before it reaches our systems. Administrative access is restricted, key based and logged.
The service is monitored around the clock for availability, anomalies and abuse patterns, with automated alerting to the operations team. Security relevant events are logged and reviewed.
We collect only the data we actually need to run the service. Public browsing requires no account and no tracking consent, technical logs are short lived, and backup copies are overwritten on a rolling schedule.
Our measures implement the requirements of Art. 32 GDPR on the security of processing. Data processing agreements are in place with all processors, and in the event of a personal data breach affecting your rights we will notify the competent supervisory authority and affected users within the legally required deadlines. Details on data handling are in our Privacy Policy.
If you believe you have found a security vulnerability in this website, we ask you to report it to us confidentially before any public disclosure. Do not exploit a vulnerability beyond what is necessary to demonstrate it, do not access or modify data of other users and give us reasonable time to fix the issue. We will not take legal action against researchers who act in good faith within these rules. Reports can be sent to .
Last updated: 7 August 2026.