Site Policies

Home

Privacy Policy

Last updated: June 18, 2026

This Privacy Policy explains how Ariadne's Journey collects, uses, and stores information when you browse the site, contact us, or use a member account. This page is written to match the site's current configuration, including account login protection, Cloudflare proxying, contact-form handling, Cloudflare Turnstile, optional passkeys, and backup codes.

Information We Collect

Account and profile data

If you are given an account on this site, we may store your email address, display name, password hash, account status, email verification status, passkey records if you add them, backup-code hashes if you generate recovery codes, and timestamps related to account activity. Passwords and backup codes are not kept in plain text.

Login and account security data

When you log in successfully, we store security-related login event data so we can detect unusual account activity and protect user access. Depending on what is available at the time of login, this may include your IP address, login time, user agent, device/browser/operating-system details, and IP-based network or location data such as city, region, country, timezone, latitude/longitude, ASN or network organization, reverse DNS, and risk-scoring fields used to flag suspicious sign-ins.

Failed login attempts may also be logged with the attempted email address, IP address, and timestamp for rate limiting and abuse prevention.

Contact and Joy submissions

If you use the contact form, we collect the name, email address, and message you submit, along with submission metadata such as the time, IP address, and user agent. This information is used to respond to your message and protect the form from spam or abuse.

If you submit a Joy moment, we collect the display name, optional email address, title, story text, submission time, IP address, and user agent. Joy moments are held for review and may be edited for spelling or clarity before any approved title, story text, and display name appear publicly. Email addresses, IP addresses, user agents, and internal review notes are not shown publicly.

Technical and browser storage data

The site uses cookies and browser storage to keep you signed in, protect forms, remember your theme preference, and support certain editing features. This includes session cookies, CSRF protection cookies, a short-lived post-login redirect cookie, theme preference storage, and, for site editors, draft recovery data stored locally in the browser.

How We Use Information

We use the information above to:

  • operate the website and render its content correctly;
  • create, maintain, verify, and secure user accounts;
  • detect suspicious login behavior and reduce account abuse;
  • respond to contact requests and site-related messages;
  • review, moderate, and publish approved Joy submissions;
  • send account-related email, including verification messages when applicable;
  • maintain site security, troubleshoot issues, and review abuse or fraud signals; and
  • store interface preferences and restore unsaved editor drafts on the same browser when applicable.

Cookies and Browser Storage

  • aj_session: keeps signed-in users authenticated. Sessions are refreshed while you remain active and expire after about 24 hours of inactivity.
  • aj_csrf: helps protect forms against cross-site request forgery attacks.
  • aj_next: temporarily stores the page to return you to after login. It is short-lived.
  • aj_theme_mode in local storage: remembers your explicit light or dark theme choice in your browser. If you have not chosen a theme, the site follows your device color setting.
  • Editor draft storage in local storage: for admin/editor editing screens, the site may store unsaved draft data locally in your browser to reduce accidental data loss.
  • Turnstile-related checks: Cloudflare Turnstile may use privacy-preserving browser and network signals as part of bot and abuse protection.

Third-Party Services

Cloudflare

This site is served behind Cloudflare. Cloudflare acts as a reverse proxy and security layer in front of the site. As part of that role, Cloudflare may process your IP address and request metadata to deliver, cache, and protect traffic. When the site is configured to trust Cloudflare’s proxy headers, it uses the original visitor IP provided by Cloudflare rather than the Cloudflare edge IP so that security logs and geolocation are more accurate.

Cloudflare Turnstile

The login and contact flows use Cloudflare Turnstile to help prevent spam, automated abuse, and malicious sign-in attempts. Turnstile is provided by Cloudflare and may process device, browser, interaction, and network information under Cloudflare's own privacy and service terms.

Cloudflare's Privacy Policy applies to Cloudflare services used by the site.

Email delivery providers

Account and contact emails are sent through the site’s configured mail transport or SMTP provider. That provider may process message content and delivery metadata in order to send email on the site’s behalf.

How Long We Keep Data

We retain information for as long as reasonably necessary to operate the site, secure accounts, maintain records, and handle support or abuse issues. Session cookies and redirect cookies are short-lived. Login security records, contact messages, and account records may be retained longer when needed for security, audit, support, or operational reasons. Browser local-storage items remain on your device until they expire, are overwritten, or you clear them.

How We Share Information

Information may be shared with service providers that help the site operate, such as Cloudflare Turnstile and the configured email delivery provider. Information may also be disclosed when reasonably necessary to enforce site security, investigate abuse, comply with legal obligations, or protect users and the site.

Your Choices

  • If you have an account, you can change your password and email address from your user panel.
  • If you add a passkey, you can remove it from your user panel.
  • If you generate backup codes, you can revoke unused codes from your user panel.
  • You can sign out of your account at any time.
  • You can control browser cookies and local storage through your browser settings, although some site functions may stop working correctly.
  • You can contact us through the contact page for privacy-related questions or requests.

Data Security

We use reasonable administrative and technical measures to protect the site and account data, including password hashing, hashed one-time backup codes, passkey support, session handling, CSRF protection, abuse controls, and login anomaly detection. No internet-based service can guarantee absolute security, so we cannot promise complete security in every circumstance.

Children’s Privacy

This site is not intended to knowingly collect personal information from children under 13 through a public sign-up flow. If you believe information has been provided by or about a child in error, please contact us through the contact page.

Changes to This Policy

We may update this Privacy Policy as the site changes. When we make a material update, we will revise the “Last updated” date on this page.