Privacy
Version 2026-08-05 · 5 August 2026
This describes what the site actually does, not what a policy generator thinks a site does. Where it names a mechanism, that mechanism exists.
What we hold
- Your handle. Public. Chosen by you, and it should not be your real name.
- Your email address. Never shown to other members. Used to confirm your address, to reset a password, and to tell you what an administrator decided.
- Your password, as an Argon2id hash. We cannot read it and cannot recover it. Nobody here can tell you what your password is.
- Your service claim — branch, country, rough years, and anything you wrote. You choose who can see the detail; the “verified” badge is separate from it.
- What you post, and the photographs you attach.
- An audit record of consequential actions: approvals, rejections, suspensions, removals. Kept because a member turned away deserves an answer about why.
What we deliberately do not hold
- Your real name. We never ask for it.
- Your IP address, in readable form. Sessions store a keyed hash of the address and browser, not the address itself. It lets us notice a session moving somewhere new; it does not give us a log of where you live. A hash alone would be trivially reversible for IPv4, so it is keyed.
- Location data from your photographs. Every image is decoded and re-encoded on upload. GPS coordinates, camera serial numbers and timestamps do not survive that, and the original file is discarded. This is unconditional and there is no setting to turn it off.
- Analytics. There are none. No third-party scripts, no tracking pixels, no advertising network, no cookies except the one that keeps you signed in.
Cookies
One, called dgm_session. It holds a random token and nothing
else — no identity, no claims. It is HttpOnly, SameSite=Lax and
Secure. The database stores only a hash of that token, so someone reading
the database cannot use it to become you. There is no cookie banner
because there is nothing to consent to.
Who else sees it
- Resend delivers our email. They see the address we send to and the content of that message.
- DigitalOcean hosts the server, in Sydney, Australia.
Nobody else. We do not sell, rent or share member data, and there is no third party embedded in these pages.
Where it lives
On a single server in Sydney, Australia. If you are in the UK, Canada or the United States, your data is therefore held outside your country. Daily backups are kept on the same server.
How long
While your account exists. Removal is a soft delete by default — the record is kept so a moderation mistake can be undone and so the audit trail stays meaningful — and your material stops being visible immediately. Ask us for a full erasure and we will do it, subject to the ownership clause in the terms and to backups, which age out on their own.
What you can ask for
- A copy of what we hold about you.
- Correction of anything wrong.
- Deletion of your account and material from view.
- An explanation of a moderation decision that affected you.
Ask through the suggestions form. Depending on where you live you may have rights under the New Zealand Privacy Act 2020, the Australian Privacy Act 1988, the UK GDPR, or Canadian or state privacy law. We will not argue about which applies — ask, and we will do it.
If something goes wrong
If member data is exposed, we will say so — what happened, what was affected, and what to do about it — rather than waiting to be asked.
The honest limits
Anything shown to another member can be copied by them. Stripping location data from a photograph does not stop the photograph itself being recognisable. No site can promise perfect security, and this one is run by a small number of people. Post accordingly.