House of Curds

Privacy policy

Last updated: October 7, 2026. This policy covers the House of Curds web journal and its account service.

Who is responsible

The data controller is House of Curds. For privacy requests, contact privacy@houseofcurds.com.

Information we process

We store your name, email address, salted password hash, email-verification status, private journal records, and record timestamps. Session and account-action tokens are stored as hashes. We do not store your plain-text password.

We use short-lived hashed account and network identifiers to limit abusive requests. Application logs contain request IDs, methods, response statuses, and timings, not journal contents, passwords, email links, or session tokens. Hosting and email providers may process network addresses and delivery metadata.

Why we use it

Account and journal data are necessary to provide the service you request (contractual necessity where applicable). Verification, recovery, abuse prevention, and operational diagnostics protect the service and its users (legitimate interests where applicable). We do not sell personal data, use it for advertising, or train models on private journals.

Cookies and third parties

An essential HttpOnly session cookie keeps you signed in for up to 30 days. There are no advertising or analytics cookies. Fonts and journal illustrations are served locally; opening the journal does not require Google Fonts or Unsplash requests.

Hosting provider: UpCloud. Email-delivery provider: Proton. Processing locations: EU. International-transfer safeguards: No personal data is transferred outside the European Economic Area (EEA). International transfer safeguards therefore do not apply..

Retention and security

Account and journal records are kept until you delete your account. Verification links expire after 24 hours; password-reset links after one hour. Password resets invalidate all sessions. Abuse counters expire at the end of their configured windows, normally within 15 minutes, and are cleaned on subsequent requests.

Account deletion removes active database records immediately. Database and infrastructure backups must be restricted, encrypted, and expired within seven days. Deleted records must be removed again before any restored database is made available. Logs must be access-controlled and subject to the operator's documented retention schedule.

Your choices and rights

Account settings let you export your profile and journals as JSON and delete your account after confirming your password. You can recover a forgotten password through your email address. Contact the controller to request access, correction, erasure, restriction, or objection where applicable; you may also complain to your local data-protection authority.

Policy changes

Material changes will be published here with an updated date. The operator should notify affected account holders when required. Avoid placing other people's personal or sensitive information in journal notes.

Return to journal