Privacy
This describes what suspects.app actually stores. It is written against the database, not from a template.
We do not collect email or phone
There is no email field at signup, no phone field, and no third-party sign-in. Registration asks for a username and nothing else. We generate your password and a 40-character recovery key, store only their hashes, and show you the plaintext once as a file to download.
The consequence is deliberate and worth stating plainly: because we hold no way to contact you, we have no way to verify who you are. If you lose the recovery key, the account cannot be restored by us or by anyone. See the terms.
What an account record holds
- Your username.
- A hash of your generated password and a hash of your recovery key. Neither plaintext is retained anywhere after the page that shows it.
- The time and IP address of your most recent sign-in.
What we log as you use the site
- Sessions — a hashed session token, the IP and browser user-agent it was issued to, and its expiry. Signing out deletes the row.
- Recovery attempts — the username tried, the IP, whether it succeeded, and when. This is what makes the lockout on repeated failures work.
- Rate-limiting — a counter keyed to a hex-encoded form of your IP, so signups and sign-in attempts can be capped. Purged after 30 days.
- Content you create — posts, comments, and votes, tied to your account.
- Moderator actions — an audit log recording who did what to which item, with the acting IP.
IP addresses are stored in packed binary form. We keep them for moderation, abuse prevention, and to respond to law-enforcement requests.
The takedown form is the one exception
The takedown form has optional name and contact fields. If you type an email address or phone number there, we store it, because otherwise we cannot follow up on your report. Both fields are optional and you can file a report without them. We use that contact only to ask for clarification on the report you filed. Nothing about this is connected to accounts — filing a takedown does not create one, and having an account does not pre-fill it.
Retention and deletion
- Soft-deleted content stays out of public view; an audit record is retained for 90 days.
- Rate-limit counters are purged after 30 days.
- Sessions disappear at expiry, on sign-out, or on any password recovery.
To have an account and its content removed, sign in and file a request through the takedown form. Because we cannot verify identity by email, a deletion request for a specific account is only actionable from inside that signed-in account.
Third parties
We run no analytics, no advertising, and no tracking pixels. The only cookies are your session cookie and a CSRF token, both required for the site to function; your theme choice is kept in your own browser's local storage and is never sent to us. Web fonts are loaded from Google Fonts, which means your browser contacts that service when a page loads. Article thumbnails are fetched from the news sites we link to.
Subjects of coverage
This page covers people who use suspects.app. If you are named in content indexed here and believe it is inaccurate or shouldn't be listed, that is handled by the takedown process, not by this policy.