The short version

You can read every article on BYD Lab without an account, and reading is not tracked. There is no analytics service, no advertising network and no third-party script on the pages you read. Signing in is optional, and exists so that lab products can be downloaded and licences managed.

If you never sign in

Nothing about you is stored. The site is static files; the only thing kept in your browser is your light/dark preference, saved in localStorage undertheme. That never leaves your device and is not a cookie.

If you sign in

Sign-in uses Google, GitHub or Facebook. BYD Lab never sees your password — the provider authenticates you and returns a limited profile. What is stored, in full:

  • an identifier for you at that provider, and which provider it was
  • your display name, where the provider supplies one
  • your email address, where the provider supplies one — GitHub withholds private addresses and Facebook omits it if you decline, and the account works without it
  • when the account was created, and when it was last used

Licences are stored against your account: which product, when issued, when it expires or is revoked, and a reference from the payment provider so a purchase can be reconciled. Downloads are recorded as which release, by which account, and when.

What is never stored

  • your password — the provider holds it, and it is never sent here
  • payment card details — these go to the payment provider, never to this site
  • the access token from your provider — it is used once, during sign-in, and discarded
  • your reading history, or which articles you opened

Cookies

Two, both strictly necessary, neither used for tracking:

  • bydlab_session — signs you in. It holds your account id, provider, name and email, signed so it cannot be altered. It lasts fourteen days and is issued for.bydlab.dev, so one sign-in covers the blog and the app site.
  • bydlab_oauth — exists only during the few seconds of the sign-in handshake, to prevent a forged sign-in, and is deleted immediately after.

There is no cookie banner because there is no cookie that would need consent.

Who else sees it

  • Your sign-in provider (Google, GitHub or Facebook) knows you signed in here, under their own privacy policy.
  • Cloudflare hosts the site and the database, as a processor.
  • The payment provider, once one exists, for purchases. It is not selected yet; this section is completed before anything is sold.

Nothing is sold, rented or shared with anyone else, for any purpose.

Where it is stored

In a Cloudflare D1 database. TO CONFIRM: the region D1 placed the database in.This is not stated until it has been checked in the Cloudflare dashboard, because the answer decides which transfer rules apply.

How long it is kept

TO CONFIRM: retention. Two separate answers are needed — how long an account is kept after its last sign-in, and how long licence and purchase records are kept after an account is deleted. The second is usually longer than the first and outlives an erasure request, because tax and refund rules require it; that has to be stated plainly rather than discovered by someone who asked to be forgotten.

Why it is stored

TO CONFIRM: legal basis. For licences and downloads this is performance of a contract — you cannot be given a licence without a record of it. There is nothing here that relies on consent, and nothing done for marketing.

Your rights

You can ask for a copy of what is held about you, ask for it to be corrected, or ask for your account to be deleted. Signing out is immediate and needs no request.

Write to contact@bydlab.dev. TheReport an error page is for article corrections and is not a privacy contact.

TO CONFIRM: who receives it. The address reaches the site; which person or company is answerable for the request follows from the data controller below.

Who is responsible

TO CONFIRM: the data controller — whether that is an individual or a registered company, and in which country. Everything above depends on this, including which supervisory authority a complaint would go to.

Changes

This page changes in the same commit as any change to what is stored. It is version controlled, so what it said on a given date is a matter of record.