VS. NOTHINGBY HERITAGE HOLDINGS

PRIVACY · EFFECTIVE AUGUST 11, 2026

The account is private.
The record is public.

Vs. Nothing keeps those two things separate. This page explains what the optional account collects and what can appear on the public site.

01

What we collect

When you sign in with Google, we keep your verified email address and Google subject identifier. Google is the identity provider; we do not receive your Google password, and provider tokens are verified and discarded.

If you use the account, we keep the Creator Records and Calls you follow, ticker watchlist entries, the side you lock in a Fight, and the receipts and corrections attached to that side. If you import this browser's record, we temporarily keep the import preview and a one-way hash of its anonymous device identifier.

We also keep the records needed to operate and protect the account: hashed session and CSRF values, session times and revocations, short-lived sign-in attempts, request IDs, and audit events such as sign-in and sign-out.

We do not build an account profile from: ad-tracker data, third-party analytics, card details, Google passwords, or raw OAuth tokens. A request's network address necessarily reaches the hosting infrastructure, but raw IP addresses and user agents are not persisted in the account database, account profile, or application logs.
02

Why we keep it

To recognize you, carry your follows and watchlist across devices, preserve the sides you locked, issue verifiable receipts, protect sessions, and investigate account errors. A verified email is an account contact; it is not marketing consent.

Your account data is never sent to a model and is not used to train anything.

03

Where it lives—and who can process it

The account record lives in the production PostgreSQL control plane and encrypted backups. It does not enter git, the static public-site export, sealed Call or verdict files, analytics events, Slack, deployment logs, or model prompts. The public export is automatically rejected if account-service files, database artifacts, credentials, or unapproved email addresses appear in it.

Google processes the sign-in. Our hosting, managed-database, and encrypted-storage providers process only the data needed to run and protect the service. We do not sell account data, share it for advertising, or allow another party to use it for its own training.

04

How long it stays

We keep active account data while the account exists and while it is needed to provide and protect the account. Sessions expire after 30 days without use and no later than 90 days after creation. Sign-in attempts stop working after 10 minutes; import previews stop working after 15 minutes.

Backups are part of the privacy boundary too. The seven most recent encrypted backup files remain locally. Encrypted off-box backup objects rotate out under a 35-day storage lifecycle. An expired backup is removed by that lifecycle; we do not claim that an individual row can be rewritten inside a historical encrypted backup.

05

What stays public

Fights, captured Calls, source links, verdicts, market and evidence grades, corrections, and the editorial record are public and stay public. They do not expose your account identity or private activity.

A Named Record is private by default. Publishing one requires a separate, explicit opt-in for that position. A private record does not become public because an account is removed.

06

Deleting an account

You can request deletion from Your Account. The request immediately signs out every device. You then have a 24-hour grace period: signing in with Google before the exact deadline shown cancels the request. After that deadline, sign-in cannot cancel it, and online account data is targeted for removal within 25 hours of the request.

Deletion removes the Google identity, email, sessions, follows, watchlist, preferences, import state, and private account links. A Named Record remains without its account owner, along with any correction notes already appended, because rewriting or deleting those ledger events would break the record. The record stays private and no longer identifies the account.

Encrypted copies expire through the normal 35-day backup rotation. The deletion confirmation shows the online target and the latest backup-expiry date rather than pretending every historical encrypted backup can be rewritten immediately.

07

Questions and corrections

For a privacy or account-data question, email h@cchfound.org.hk. Use the random support ID shown in Your Account instead of putting account details in email where practical.

If the public Call, comparison, challenge, or reality grade is wrong, use the Correction Room. Confirmed corrections append to the record; the original never quietly disappears.