Privacy
Version 2026-08-05 · 5 August 2026
This describes what the site actually does, not what a policy generator thinks a site does. Where it names a mechanism, that mechanism exists.
What we hold
- Your handle. Public. Chosen by you, and it should not be your real name.
- Your email address. Never shown to other members. Used to confirm your address, to reset a password, and to tell you what an administrator decided.
- Your password, as an Argon2id hash. We cannot read it and cannot recover it. Nobody here can tell you what your password is.
- Your service claim — branch, country, rough years, and anything you wrote. You choose who can see the detail. Whether an administrator has checked it is held separately, and shows on your profile as a Service Verified badge; that is a badge, not a membership level, and it does not open or close anything.
- What you post, and the photographs you attach.
- An audit record of consequential actions: approvals, rejections, suspensions, removals. Kept because a member turned away deserves an answer about why.
What we deliberately do not hold
- Your real name. We never ask for it.
- Your IP address, in readable form. Sessions store a keyed hash of the address and browser, not the address itself. It lets us notice a session moving somewhere new; it does not give us a log of where you live. A hash alone would be trivially reversible for IPv4, so it is keyed.
- Location data from your photographs. Every image is decoded and re-encoded on upload. GPS coordinates, camera serial numbers and timestamps do not survive that, and the original file is discarded. This is unconditional and there is no setting to turn it off.
- Advertising. None. Nothing here is sold to advertisers, no advertising network is loaded, and the advertising parts of Google’s tag are switched off in code whatever you answer to the prompt.
Google Analytics
We use Google Analytics, and only if you say yes. It tells us which stories get read, which pages people leave from, and roughly where in the world our readers are. It is how we find out that the memorial page is read three times as often as anything else, or that half the people who start writing a yarn never finish — questions we could not answer at all before, and answers that change what gets built.
Nothing you write is ever sent. Not a yarn, not a comment, not a photograph, not a message, not a Vault entry. What Google receives about a story is its number, its service tag and its era; never its words, never its title, never who wrote it.
Which pages you looked at is sent, and that includes all of them. The Vault, the support numbers, The Gouge and the payment pages are counted like every other page here. We are straight about that because the alternative is a site nobody can improve: if we cannot tell that a page is never found, we cannot fix it.
The address is cleaned before it goes. Anything after a
? is removed — so the country you picked on the support
page, and what you typed into a form, are not in it. Anything that
identifies one row is replaced by a marker: a Vault entry is reported as
/vault/:id, never as itself. The pages that carry a
one-time link from an email — verifying an address, resetting
a password — are not measured at all, because that link is a key and
keys do not leave this site.
We do not send Google an account identifier. The most we ever say about the person reading is one of four words — anonymous, pending, free or Tier 1. We do not tell them which member you are, and we do not send your handle, your email address or anything you have typed except one thing, which is on this list because it is the exception: if you use the search box, what you typed is sent. If that matters to you, say no to the prompt.
Google sets its own cookies once you agree, and it is their company policy that governs what they then do with them. Say no and none are set: the measurement runs without storage, we lose the ability to tell a returning reader from a new one, and you lose nothing at all. You can change your mind by clearing this site’s data in your browser.
What is stored on your device
One cookie, and only once you sign in. It is called
dgm_session and it holds a random token and nothing else
— no identity, no claims. It is HttpOnly, SameSite=Lax and Secure.
The database stores only a hash of that token, so someone reading the
database cannot use it to become you. Signing out deletes it.
One preference, and only if you ask for it. If you press the
light/dark button, your choice is kept in your own browser under
dgm-theme. It never reaches us — it is not sent with
any request and there is nothing on the server that knows it. Leave the
button alone and nothing is stored at all: the site follows whatever
light or dark setting your device already has.
Your answer to the measurement prompt, kept in your own browser
under dgm-analytics so you are not asked twice. It is stored
on your device and never sent to us.
Google’s cookies, and only if you said yes. They are set by Google Analytics and are the reason the prompt exists. Say no and they are never set.
That is the lot — and the prompt is a real question, not a formality. Both buttons are the same size, saying no is one press, and the site behaves identically either way.
Who else sees it
- Resend delivers our email. They see the address we send to and the content of that message.
- DigitalOcean hosts the server, in Sydney, Australia.
- Google receives the analytics described above, if you agreed to it. Which pages you looked at, and nothing you wrote.
Nobody else. We do not sell, rent or share member data.
Where it lives
On a single server in Sydney, Australia. Unless you are in Australia, your data is held outside your country — wherever you are reading this from. Daily backups are kept on the same server.
How long
While your account exists. Removal is a soft delete by default — the record is kept so a moderation mistake can be undone and so the audit trail stays meaningful — and your material stops being visible immediately. Ask us for a full erasure and we will do it, subject to the ownership clause in the terms and to backups, which age out on their own.
What you can ask for
- A copy of what we hold about you.
- Correction of anything wrong.
- Deletion of your account and material from view.
- An explanation of a moderation decision that affected you.
Ask through the suggestions form. Wherever you live, whatever your country’s privacy law says, and whether or not it reaches us — ask, and we will do it. We are not going to argue about which rules apply, because the answer is the same either way.
If something goes wrong
If member data is exposed, we will say so — what happened, what was affected, and what to do about it — rather than waiting to be asked.
The honest limits
Anything shown to another member can be copied by them. Stripping location data from a photograph does not stop the photograph itself being recognisable. No site can promise perfect security, and this one is run by a small number of people. Post accordingly.