WE NEVER STORE YOUR EMAIL ADDRESS.

There is no password either. Here is everything, on one page.

NOT EVEN WE CAN SEE YOUR EMAIL ADDRESS.

what you type

david@example.com

never written to disk

what we hold

6881fb08a645…@mc.internal

all we will ever have

Look up your address

There is no column holding it. A query for it returns nothing, because nothing is there.

Email you

No confirmations, no newsletter, no recovery link. We could not if we wanted to.

Sell or leak a list

A stolen database, a leaked backup, a rogue admin — none of them yield a single address.

Hand it to anyone

Asked by a partner, an employer or a court, the honest answer is that we do not have it.

The one thing we can still do, stated plainly: if you hand us an address, we can hash it and see whether it matches an account — that is exactly how signing in works. So we can confirm a guess. What we cannot do is go the other way and produce an address, or a list of them, from what is stored.

WHAT WE KEEP

  • A random account id

    means nothing on its own

  • A hash of your email

    one-way, keyed with a server secret

  • Your card content

    because a card is meant to be shared

  • A view count per card

    one number, no visitor records

WHAT WE NEVER KEEP

  • Your email address

    only the hash of it

  • Your name

    not even from Google

  • A password

    there is no password

  • Analytics or ad tracking

    none, anywhere

HOW SIGNING IN WORKS

Your address travels three steps, then stops.

When an email is needed, and what happens to itYou build a card with nothing stored. If you only want the image, you export a PNG or PDF and nothing is ever saved. If you want a shareable link, a QR code, comments or NPS, you give an email — typed in, or via a provider that verifies it. The address is then hashed with HMAC-SHA256 using a server-only key and discarded, leaving a pseudonymous account that the card is saved to.YOUBUILD YOUR CARDnothing is stored yetEXPORT AND GOPNG or PDF, made in your browserno email, nothing stored, everSHARE OR GET FEEDBACKa link, a QR, comments, NPSthis is the part that needs an emailGIVE AN EMAILtyped in — or via a provider,which verifies that it is yoursHMAC-SHA256keyed with a server-only secretone way — cannot be reversedyour addressDISCARDEDPSEUDONYMOUS USERyour card is saved to ithash · 6881fb08…@mc.internal
Building and exporting a card needs nothing from you. An email is only the price of a card that outlives the tab — one that can be shared, scanned and commented on. Signing in is never required; it just proves the address is yours, so the card follows you to another device.

YOUR WHOLE ACCOUNT

This is the entire record. There are no other columns.

idemail_hashcreated_at
3f9a…c1e26881fb08…@mc.internal2026-08-27

YOUR CARD IS PUBLIC

Anyone with the reference or QR code can read it. Put nothing on it you would not pin to a wall.

WE LOG ONE THING

The IP address and browser a card was created from, written once and never updated or shown. It is there for audit: if a card turns out to be spam, organisers can see where it came from. Every three months it is cleaned — the browser is erased and the address is cut back to its network, so it no longer points at a person.

WE CANNOT EMAIL YOU

No confirmations, no recovery, no newsletter. That is the trade for not keeping your address.