Privacy
This page is for the Drain site and API. We do not sell account data. Checkout is not live, so we do not collect card numbers here.
What we store
Username, Argon2id password hash, role, license flag, optional HWID, web session hashes, admin TOTP secret when set, hashed password-reset tokens, and short contact-form notes in the event log. Passwords, cookies, CSRF, and reset tokens are not written to application logs.
Cookies
We use cookies so you stay signed in and so forms cannot be submitted by another site in your name. They are required for the account pages to work. We do not use them for ads or tracking other sites.
Third parties
If Turnstile is enabled, Cloudflare sees the captcha token on register, contact, and forgot-password. When Stripe exists later, that provider will see billing data at checkout. We do not claim a full GDPR program on this local build.
Questions
Email contact@mikua.cc or use Contact if you want an account looked up or removed.