Privacy
Last updated 25 July 2026
Short version: we keep what an account needs and nothing else. There are no analytics, no advertising, no third-party scripts and no tracking cookies on this site.
What we store
- Your account — username, full name, email address, a scrypt hash of your password (never the password itself), your role and plan, and the dates the account was created and last changed.
- Security data — failed sign-in counters and lockout timers, pending verification codes (hashed, valid for ten minutes), and, if you turn them on, your two-factor secret and recovery code hashes.
- Sessions — a session token per sign-in, which expires after twelve hours and is revoked when you sign out or change your password.
- Vault data — secrets you store in the apps are encrypted on your own machine. We hold the ciphertext and cannot read it.
Cookies
One cookie: your session. It is encrypted, marked HttpOnly and Secure, and restricted to this site (SameSite=Strict), so scripts in your browser cannot read it and other sites cannot use it. There are no other cookies.
Logs
The servers keep short-lived request logs and rate-limit counters that include your IP address. They exist to stop brute-force attempts and abuse, and are not used to build a profile of you.
Your address is used for verification codes, password resets and account notices. It is not used for marketing and is not shared with anyone.
Where it lives
Accounts are stored on our own servers in Europe. There is no third-party account provider, no external captcha service and no content delivery network in front of this site.
Deleting your account
Ask from inside any app in the suite, or email NinjaMind@ninjastic2008.com. Deleting removes the account, its sessions and its vault blobs. Backups roll over within fourteen days.