Account data & privacy
Visitor account information · Updated 17 September 2026
What is stored
We store your email as an unverified login identifier, a salted password hash, a hashed recovery code, optional profile details, saved documents and searches. Optional download history is off by default. We do not publish this information to other visitors.
Sessions and security
A necessary, secure HTTP-only cookie keeps you signed in for up to seven days. Session tokens are stored as hashes. Short-lived counters based on hashed IP addresses and email addresses limit abusive sign-in attempts. Expired counters are eligible for cleanup after one day. Account pages do not include the public-page behavior tracking script.
Recovery and email
No verification or password-reset emails are currently sent. Save the recovery code shown at registration. It grants password-reset access together with your email, and is replaced after use. We cannot safely restore access if both the password and recovery code are lost.
Your controls
In account settings you can export your data, change your password, replace the recovery code, sign out devices, turn history on or off, clear history, or permanently delete the account. Downloads keep only the latest 100 requests; previews and ZIP batches are excluded. Deleting an account removes its data from the live database; infrastructure recovery backups may retain copies according to their configured retention. Public SDS files remain unchanged.