// Privacy
Privacy
The short version: no ads, no trackers, and we never sell your data. Here is exactly what we collect, why, and the rights you have over it.
No ads, no tracking
There are no advertisements and no third-party tracking pixels or analytics. The one-time fee is the entire business model.
What we collect
To run your account we store what you give us (your handle, display name, email, and a hashed password) and what you create (posts, co-signs, follows, candles, and whispers). To show presence and the witching hour we record when you were last active and your browser time zone. For security and abuse-prevention we briefly process technical data such as your IP address.
Cookies we set
Only first-party, functional cookies: a session cookie to keep you signed in, an optional "remember me" cookie, and a small "local hour" cookie so the night knows your local time. No advertising or cross-site tracking cookies. You can clear them in your browser any time; some features will then ask you to sign in again.
Why we are allowed to process it
Under the GDPR our legal bases are: performing our contract with you (running the service you signed up for), your consent (for optional extras such as the email digest or browser push), and our legitimate interests (keeping the service secure and free of abuse).
Your rights
You can access, correct, export, restrict, or delete your personal data, and object to or withdraw consent for optional processing. Much of this is self-service: edit your profile, toggle the digest and push, or delete your account (which scrubs your identifying fields and removes your posts). For anything else, contact us. In the EEA or UK you may also lodge a complaint with your data-protection authority.
If you are in California
You have the right to know what we collect, to delete it, and to correct it, and the right not to be treated differently for exercising those rights. We do not sell or "share" personal information as the CCPA/CPRA defines it.
Whispers: encrypted at rest
Private whispers are encrypted on our servers (AES-256-GCM) and sent over TLS. Ephemeral whispers are truly deleted the moment they are read. Be clear-eyed, though: this is encryption at rest, not end-to-end. Our servers hold the key and could in principle decrypt stored messages, so this is not a guarantee that no one but you and the recipient can ever read them. For anything where your safety depends on true secrecy, use a dedicated end-to-end encrypted tool.
Passwords
Passwords are stored only as salted hashes (never in plain text).
How long we keep things
DREADLIST forgets by design: the living feed fades and is genuinely gone by dawn unless the night lifts it into the Vault. Whispers stay until deleted (ephemeral ones vanish the instant they are read). Deleting your account removes your posts and scrubs your identifying fields. Short-lived security and rate-limit records are kept only while they are useful.
Where your data lives
Your data is hosted by the operator named below and may be processed in the country where they host it. Where that involves a transfer out of your region, the operator is responsible for an appropriate safeguard.
Age
DREADLIST is not directed at children. You must be at least 16 and old enough to use a service like this where you live.
Security
We use hashed passwords, TLS in transit, CSRF protection, login lockout, and strict security headers. No system is perfectly secure, but we take protecting your data seriously.
Third parties
If card payment is enabled, your payment is handled by our payment processor under its own privacy policy and we never see your full card details. Otherwise we share your data with no one.
Changes to this policy
We may update this policy as the service evolves; the "last updated" date below always reflects the current version.