Skip to content
ResetRemind

Privacy

Last updated: 2026-09-16

What we collect

Exactly one thing: the email address you type in, plus the list of plans you ticked. No account, no password, no name, no payment details.

We do not collect IP addresses, browser fingerprints or browsing behaviour.

How your address is stored

The plaintext address is never stored. Each address exists as two derived values: an irreversible HMAC hash (used to answer "is this address already on the list" and to carry the uniqueness constraint), and an AES-256-GCM ciphertext (because we must be able to email you, so it has to be recoverable).

Both keys live in server-side environment variables, never in the database. A database dump therefore does not yield addresses.

The admin console only ever shows a mask such as ab***@example.com.

What is inside the emails

No tracking pixel, no remote images, no click tracking. We cannot tell whether you opened a message, and that is deliberate.

Every message carries a one-click unsubscribe link, plus the RFC 8058 List-Unsubscribe headers that make mainstream clients show their own unsubscribe button.

After you unsubscribe

The status flips to unsubscribed immediately and no further mail is sent to that address. The record itself is retained — otherwise the same address could be added again by someone else.

Hard bounces and spam complaints add the address to a suppression list, which is also permanent.

Is the list sold

No. The mailing list is not sold, rented or shared with any third party.

Sponsorship appears only as a clearly labelled block inside a message that was going out anyway. Sponsors never see the list and cannot influence who receives which alert.

Removing your data

Use the unsubscribe link in any email we sent, or reply to any of them and we will handle it manually.

We never ask a vendor for your account credentials, and we never request access to your editor or your local tokens.