§ 1.Information Collected
When the User creates an account on the Service, the Company collects the following categories of information: (a) the User’s email address, (b) the User’s chosen display name, and (c) a salted cryptographic hash of the User’s chosen password. The Company shall not store the User’s password in plaintext and shall not possess the technical means to recover it on the User’s behalf; the User is accordingly encouraged to record the chosen password through means not dependent on the Service.
In the course of the User’s use of the Service, the Company additionally collects operational metadata, including without limitation: (i) login attempts and account-creation activity, including successful and unsuccessful outcomes, (ii) Internet Protocol addresses and the proxy routing headers supplied to the Service, (iii) browser-supplied request information such as user agent, language, referrer path, platform hints, fetch context, requested host and protocol, content negotiation headers, data-saving preference, Do Not Track preference, and Global Privacy Control signal, (iv) the approximate country from which the request originated where the Service’s network provider supplies it, and (v) the timestamps at which the foregoing events occurred. Referrer query strings are discarded so invite codes and similar credentials are not retained. The Company uses this data for the purposes set forth in Section 5 and for the legitimate interest of detecting, preventing, and investigating abuse. The Company does not use canvas fingerprinting, browser probing, or third-party enrichment services for this security log.
Strictly speaking, the foregoing is a description of categories, not a list of items. The User’s confidence in the Service is best supported by a category-level understanding; a line-item understanding would, in our experience, occasion more questions than it resolves.