doksli.fun
Privacy
What Doksli collects, why it collects it, and what it deliberately does not. Written to be read rather than skimmed past.
Last updated 29 September 2026
What this covers
Doksli serves four surfaces from one place: the community, the archive, the shop, and the landing page that links them. This policy covers all of them.
What we collect
Everything on this list is here because the site cannot work without it. Nothing is collected to build a profile.
- Your email address, used to sign in and for nothing else.
- Your handle, and the capitalised form of it that we display.
- Your password, stored only as a PBKDF2-SHA256 hash with a salt unique to your account. We cannot read it and we cannot recover it for you.
- A session record when you sign in: a hash of the session token, an expiry time, and a hash of your browser’s user-agent string.
- Rate-limiting counters, keyed on your IP address for sign-in attempts and on your account for posting. These live briefly in Cloudflare KV and are what stop one person hammering the sign-in form. They are not a visitor log.
- What you post: image posts, text threads, comments, upvotes, and the files you upload, which are stored in Cloudflare R2.
- The date you joined, and a count of your posts and comments.
What we do not collect
This list is as deliberate as the one above it.
- No real names, no phone number, no date of birth, no postal address, no location.
- No contacts, no address book, no imported profiles from anywhere else.
- No third-party analytics, no advertising trackers, no pixels, no device fingerprinting.
- No social sign-in. There is no “continue with Google”, and there never will be.
- No wallet. Nothing in Doksli links a Solana wallet to an account — the code to verify a wallet signature exists in the repository and is deliberately left unwired. Signing in is email and password, full stop.
Cookies
Two, and no more. One is the session cookie that keeps you signed in: it is HTTP-only, SameSite Lax, lasts 30 days, and is renewed while you keep using the site. The other remembers whether you read Doksli in English or Indonesian.
There is no tracking cookie, no third-party cookie, and therefore no consent banner. There is nothing to consent to.
What is public
Your handle, the date you joined, your post count, and everything you choose to post. That is the whole list.
Your email address is never shown to anyone, including moderators. We do not ask for anything else, so if you do not type it, we do not have it.
Where it is kept
On Cloudflare: D1 holds records, R2 holds files, KV holds sessions and rate-limit counters. Traffic is served over HTTPS with HSTS.
We do not run our own servers yet. When we do — and it is on the roadmap — this section will say so before anything moves.
How long we keep it
Sessions expire after 30 days of disuse. Your account and its content stay until you remove them or ask us to delete the account.
Removing a post or a comment is a soft delete: it stops being shown, and the record stays, marked as removed. That is deliberate and it is the same rule the archive follows, because the promise of this project is that removal is recorded rather than silent. If you need a record genuinely erased rather than unpublished, ask us.
Your choices
You can remove your own posts and comments at any time, from the user area.
You can ask us to delete your account and the personal data attached to it, and we will, unless we are legally required to keep something.
Write to info@doksli.fun to ask what we hold about you, to correct it, or to have your account and its personal data deleted.
Children
Doksli is not intended for children under 13, and we do not knowingly hold data belonging to anyone under that age. If you believe a child has created an account, tell us and we will remove it.
Changes to this policy
If this policy changes in a way that matters, we will say so on this page and change the date at the top. We will not quietly widen what we collect.