Privacy, in plain English.
Pre-launch draft — written plainly and in good faith, awaiting legal review before launch. If anything here reads wrong, tell us.
Last updated 18 July 2026
The short version
We built this site to need as little of your data as possible, because the subject deserves discretion. No advertising trackers, no social-media pixels, no fingerprinting, no selling or sharing of data with anyone.
What we collect today
- Standard server logs. IP address, page requested, browser user-agent — kept briefly for security and debugging, then rotated away. We don't build profiles from them.
- Your age confirmation. The 18+ splash stores a yes in your browser's session storage. It never leaves your device and disappears when you close the tab.
- Nothing else. The quiz and fit finder run on the URL in your address bar — we don't store your answers. Close the tab and they're gone unless you kept the link.
Cookies & analytics
No third-party cookies. When we add analytics it will be a self-hosted, cookieless counter (page views and outbound clicks in aggregate) — never a third-party ad or analytics network. This page will be updated before that ships.
Accounts
- Pseudonymous by design. An account is a username, an email for login and the alerts you opt into, and a password stored properly hashed (argon2id). No real-name fields exist anywhere on the site. You can also add a passkey and skip passwords entirely.
- Age. Creating an account requires confirming you're 18 or older. Full third-party age verification arrives with media features; until then it's an attestation.
- Sessions. Login sets one first-party, http-only cookie holding a random session token — no third parties, no tracking. We keep a coarse record of your active sessions (browser type, a one-way hash of your IP — never the raw address) so you can see and end them.
- Discreet by default. Emails use plain, boring subject lines. Nothing on an envelope, statement or notification announces what this site is about.
Your data — export and deletion
From your settings you can do both yourself, no email to us required:
- Export. Download everything we hold for your account as a single JSON file — profile, your private shelf, reviews, corrections, measurements, helpful votes and contribution points.
- Delete. We anonymise in place. Your username becomes
deleted-user-…, your email, password and any passkeys are purged, and your private shelf and sessions are erased. The community contributions you chose to share — measurements, corrections, reviews — are kept but detached from you, so the verified specs other people rely on stay honest. Once anonymised, that content no longer identifies you, which GDPR permits. Deletion can't be undone.
Your rights
Wherever you are, we treat GDPR as the floor: access, correction, deletion, and export of anything we hold about you — most of it self-serve above, and the rest on request, for free. Ask and it happens.
Questions
Anything unclear, or anything you think we've got wrong — contact us. Privacy questions get answered by a human.