Privacy Policy
Last updated 30 July 2026
What we store
If you create an account we store your name, username, email address and a hashed password. Passwords are hashed with bcrypt and are never stored or logged in plain text. We also store which topics you have marked complete, any bookmarks, and any suggestions you send.
Security records
For account security we keep a record of sign-in attempts, active sessions and account events such as password changes. These records include an IP address and a browser description, and they are what allow you to see and revoke your own active sessions.
Browsing without an account
You can read every roadmap without signing in. In that case progress is stored only in your own browser using local storage, and we do not receive it.
Cookies
We set a session cookie when you sign in, and an optional long-lived cookie if you choose to stay signed in. Both are marked HttpOnly and Secure. We do not use advertising or cross-site tracking cookies.
We send email for account verification, password resets and security alerts. Security alerts cannot be switched off, because they are the mechanism that tells you if someone else is accessing your account.
Deletion
You can ask for your account and all associated data to be deleted at any time. Write to the support address and it will be removed, along with your progress, bookmarks and session records. Contributions that have already been merged into a roadmap remain, since they are part of the shared content, but they can be anonymised on request.
Contact
Questions about this policy can go to the support address listed on the Hacklido site.