Privacy
What this service stores, why, what anyone can see on a certificate, and how to delete your account.
What we store, and why
- Seller account
- Your email address (to log in; it is never shown publicly), your display name (shown on your certificates), the date you joined, and your password as a scrypt hash. The password itself is not stored. If an account is suspended for abuse, the date and reason are kept with it. The date you confirmed your email address is kept too.
- Emails we send
- Two kinds, both only about your own account: a link to confirm your email address when you sign up, and a link to choose a new password when you ask for one. Each link holds a one-time code; the server keeps a hash of the code until it expires (24 hours for confirming, 30 minutes for a password), not the code itself. We send no newsletters or advertising.
- Logins
- When you log in on the website or in the app, the server keeps a hash of the login token, not the token itself, so it can recognise your browser or app until you log out or the login expires (30 days for the website, one year for the app).
- Test reports and certificates
- Each certificate is stored with the full test report the app sent: the card's name, unique ID, board serial number (if the card reports one), VBIOS and driver versions, memory size, the sensor readings taken during the test, the card's settings, and your PC's operating system and Python version. It is linked to the account that submitted it. This is the service itself: the report is what the certificate page shows.
- Buyer checks
- Buyers need no account. When a buyer check confirms a certificate, the server stores the receipt the app sent (the card's identity and the check results) and the time.
- Network addresses
- The database holds no plain IP addresses. With each certificate and each buyer confirmation it stores a keyed hash of the IP address it came from. The only use is to notice when a buyer confirmation comes from the same network the certificate was created on, which the certificate page then says. Limits on repeated requests (for example login attempts) count by address in memory and are forgotten when the server restarts. The server's request log lists each request with its address and time; it is used to keep the service running and to look into abuse.
- Cookies
- Two, both needed for the site to work: one keeps you logged in, one protects forms against forged requests. There are no analytics, advertising or tracking cookies, and pages load nothing from other websites.
What is public on a certificate
Anyone with a certificate's link or QR code can see:
- the seller's display name and the date they joined (and whether the account is suspended or deleted);
- the card's name, unique ID, serial number, VBIOS and driver versions, and memory size;
- the grade, the check results, the temperature and clock charts, and the test date;
- the dates of buyer confirmations, and whether one came from the same network as the certificate.
The machine-readable certificate also contains a random ID for the seller account. Your email address and password are never shown, and IP addresses and their hashes are never shown.
Who else handles your data
Cloudflare is our network provider: requests to this site travel through Cloudflare's network, so Cloudflare handles your IP address and the pages you request in order to deliver the site and protect it from attacks.
Resend is our email provider: to deliver the two kinds of email above, Resend receives your email address, your display name and the text of the message, including the one-time link.
We don't sell your data, and we don't share it with anyone for advertising.
Deleting your account
Log in, open your account page, and use Delete account (also in the My account menu at the top). You'll be asked for your password and to type DELETE. Straight away:
- your email address, display name and password hash are deleted, and every login is ended;
- all of your certificates are revoked. Their pages stay online, marked as revoked, with "Seller account deleted" in place of your name, because buyers may already hold the link or QR code. The test report, the card's details and the hashed network address stored with each certificate are kept with it, and so is the random account ID inside the signed certificate.
Deletion can't be undone, but the same email address can be used to sign up again later. If your account is suspended you can't log in to delete it; write to the address below instead.
Backups
The server's data is backed up, and the backups are encrypted. Data you delete stays in those backups for up to 6 months before it is purged.
Contact
Questions about your data, or requests you can't do yourself on the account page: [email protected].