Privacy

Privacy

What softon.dev collects about you, why, who else handles it, and how long it is kept. Written from what the code does rather than from a template, so where there is a gap, this page names it instead of papering over it.

The short version

When you read the site

Reading the site, the documentation and the notes needs no account and sets no cookie. Three things happen anyway, and you should know all three.

Analytics

softon.dev can count visits with Google Analytics 4. It is off until you say otherwise: before you answer, no Google Analytics script is on the page, no analytics cookie is set, and the page's security policy would refuse Google's script if it were there. Declining is one click, the same as accepting.

If you accept, Google Analytics:

It runs on the public pages and on the account pages you see before signing in — sign-up, sign-in, the contact form and the email confirmation link. Never on the dashboard, and never on the forgotten-password or password-reset pages, whatever you answered: those are where a new API key is shown and a password is reset, and no third-party script runs on them. Google processes what it collects under its own terms, and may do so outside the EU, including in the United States.

Your answer is kept in a cookie for 180 days, after which you are asked again. Declining after accepting also deletes the _ga cookies.

You have not answered yet, so analytics is off in this browser.

Cookies

None before you sign in or answer the analytics question. Ours are first-party and HttpOnly: only softon.dev receives them, and no script on the page can read them.

CookieSet whenWhat it holdsHow long
__Host-softon_customerYou sign inA random session token. We store only a digest of it.Until you sign out, after 14 days unused, or 30 days after you signed in
__Host-softon_analyticsYou answer the analytics questionYour answer: granted or denied180 days
_ga, _ga_…You accept analyticsGoogle Analytics' identifier for your browser180 days after your last visit

Your account

When you create an account we keep:

An email confirmation link works for 24 hours and a password reset link for an hour. Both are stored only as digests, and a reset request also records the IP address it came from.

API keys and requests

When you write to us

The contact form takes your name if you give it, your email address, a subject and your message, and records the IP address it came from — which is how one address is limited to five messages an hour. The message is stored and emailed to us, and a short acknowledgement goes to the address you gave, quoting only the subject. Messages are not deleted automatically: they are how we answer you, and how we look back at what was asked.

Email we send

Only email about your account or a message you sent: the address confirmation, password reset and password-changed notices, a note when a key is ready, a warning when somebody tries to sign up with your address, and the acknowledgement of a contact message. No newsletter and no marketing. Each one is delivered by Sweego, which receives the address and the message. Our own log of sent mail records the subject and a masked form of the address.

Who else handles it

Three outside companies handle personal data for us:

There is no payment processor. This site never asks for card details: a paid plan is arranged with you directly, by email.

How long we keep it

WhatHow long
Your account, its keys and your dashboard messagesUntil the account is deleted
A sign-in sessionIt ends when you sign out, after 14 days unused, or 30 days after you signed in. Its row is deleted a week after that 30-day limit.
Confirmation and reset linksUsable for 24 hours and an hour; deleted a week after they expire
A key you have not collectedUntil you see it, or 72 hours
The per-request API log90 days, deleted by a command we run
Monthly request countsKept
Contact messagesKept; nothing deletes them automatically
The audit trailKept. It is append-only by design.
Server logsOverwritten as they pass their cap: 30 MB per service, and 50 MB for the API's own log
Your analytics answer180 days
BackupsHetzner keeps seven nightly images of the site's server. The API database is copied every night to the site's server, and each copy is kept for 14 days.

People in our datasets

The datasets are built from public pages, and some of what those pages publish is about people: a job posting can name a recruiter and give their email address or phone number. Our crawler also stores profiles that job seekers publish on Azerbaijani job boards. The API does not serve those, and no plan includes them.

If you are in any of it and want out, write to us and say so. We suppress the record by your email address or by the source's own id, so it leaves every response, the archive included, and a request about your own personal data is handled as an erasure request. Our crawler's page says how removal works.

What you can ask for

Write to us, and you can ask for:

Changes to this page

The date at the top is when this page last changed. Several of its figures — how long sessions, links and uncollected keys last, the per-address limits, the log caps, and how long the request log and the backups are kept — are checked against the code and configuration that enforce them, so changing one of those without changing it here fails the build.