PRIVACY
Privacy policy.
Short version: we do not run analytics, we do not use third-party trackers, we do not sell anything to anyone, and we never store your raw IP address. Last updated August 2, 2026.
What we collect
- What you submit. The media file itself, plus the title, project, description, tags, creator credit and source URL you type. Everything in a submission is intended for publication — do not put anything private in those fields.
- A hashed fingerprint of your IP address. Used to rate-limit submissions and logins and to attribute moderation actions. It is an HMAC-SHA-256 digest with a server-side secret — we do not store, log or display the raw address, and the hash cannot be reversed back to it.
- Staff account data. Username, display name, an optional email address for password recovery, and a scrypt hash of the password. Applies only to vault moderators, not to visitors or submitters.
- API key metadata. If you are an integrator: the label, contact and site URL you gave us, plus usage counts. We store only a SHA-256 hash of the key.
What we do not collect
- No analytics, pixels, ad networks, session recording or fingerprinting.
- No third-party scripts at all — the site's strict Content-Security-Policy forbids loading code from any other origin, and the fonts are self-hosted for exactly that reason.
- No accounts, no email addresses and no wallet connection for visitors or submitters. You can browse, download and submit without identifying yourself.
- No raw IP addresses, and no cross-site tracking of any kind.
Cookies
Three, all strictly functional. None are used for tracking or advertising.
- CSRF token — a short-lived random value that proves a form submission came from this site. Set for anyone using a form.
- Staff session — a signed identity token, set only after a moderator logs in, cleared on logout.
- One-time API key handoff — lives for two minutes on the admin area only, so a newly created key can be shown once.
How long we keep it
- Approved media stays until it is removed by a moderator or by a valid takedown request.
- Rejected submissions keep a record of the decision for moderation accountability; a hard delete removes both the database row and the stored file, irreversibly.
- Moderation and staff audit logs are append-only and retained for accountability. They record who did what, when, and a hashed IP — never raw addresses.
- Password reset tokens expire after 30 minutes and are pruned automatically.
- Rate-limit records are transient and expire on their own.
Who else sees it
Approved media is public by design and served over a public, CORS-open API — anyone, including third-party sites using our developer API, can display it. Assume anything approved is permanently public and may be copied. Pending and rejected media is private and returns a 404 to everyone except signed-in moderators.
We use a hosting provider and a CDN to serve the site; they process requests on our behalf. We do not share data with advertisers or data brokers, because we do not collect anything they would want.
Your choices
To have something you submitted taken down, or to ask what we hold about a staff account, use the contact route on the content policy page. Because submissions are anonymous, we may be unable to verify who submitted a given item — tell us what it is and where, and we will act on the content itself.
Children
The vault is not directed at children under 13 and we do not knowingly collect their information. If you believe a child has submitted something, report it and we will remove it.
Changes
If this policy changes materially we will update the date at the top. Continued use after a change means you accept it.