Mess Ledger

Privacy policy

Last updated

This describes what Mess Ledger actually stores and does, not what a template says a policy should claim. Everything below can be checked against the running system.

What we collect

For your account: your email address, your name, and your password — the password only as a bcrypt hash, never as text anyone can read, including us.

For your mess: the entries you and your mess-mates make. Meal counts, grocery trips and their items, deposits, shared costs like rent and bills, standing meal plans, and a log of who changed what. That is what a ledger is; without it there is nothing to show you.

We do not ask for a phone number, a postal address, a date of birth, or payment details. There is no card field anywhere in the product.

What we do not collect

There is no analytics on this site. No Google Analytics, no Facebook pixel, no advertising network, no session recorder, no third-party script of any kind. Nothing on the page reports back to anyone else about you.

Our request logs record the method, the path, the response status, how long the request took, and a random request id. They do not record IP addresses, and they do not record who you are. They are kept for seven days and then deleted.

Your IP address is used once, in memory, to limit how many sign-in attempts can come from one place — which is how a password-guessing attempt gets stopped. It is not written to disk and not kept.

Cookies

One cookie, named mh_refresh. It keeps you signed in. It is HttpOnly, so no script on the page can read it — including any script an attacker manages to inject. It is Secure, so it only travels over HTTPS. It is SameSite=Strict and scoped to the sign-in endpoints, so another site cannot cause your browser to send it. It expires after thirty days, and signing out deletes it immediately.

There are no advertising or tracking cookies, because there is no advertising and no tracking.

Your browser also remembers three preferences on your own device: the theme you picked, the language you picked, and which mess you opened last. These never leave your browser and are never sent to us.

Who can see your data

The members of your mess can see that mess's entries — that is the point of a shared ledger, and everyone in it can see the same numbers. Someone who is not a member of your mess cannot see it, cannot list it, and is not told it exists.

We do not sell your data. We do not share it with advertisers, data brokers, or anyone else, because there is nobody we share it with.

Where it is kept

The application runs on Amazon Web Services in the Singapore region, and the database is hosted with Neon. Pages and images are served through Amazon CloudFront, which has servers worldwide, so the page itself may be delivered from a machine near you. Your account and mess data stay in the database.

Everything travels over HTTPS. The site sends HSTS, so once your browser has visited it will refuse to connect any other way.

Getting your data out, or deleting it

The settlement screen exports a month as CSV, which you can open in any spreadsheet.

There is not yet a button that deletes your whole account, and we would rather say so than imply otherwise. Write to us at the address on the contact page and we will delete your account and the personal data attached to it.

One honest limitation: entries you made in a shared mess are part of that mess's ledger, and removing them would silently change other people's settled figures. We remove your account and your personal details; historical entries stay in the mess's own record.

Children

Mess Ledger is not aimed at children and we do not knowingly collect data from anyone under 13. If you believe a child has created an account, write to us and we will remove it.

Changes to this policy

If this changes in a way that affects what we collect or who can see it, we will update the date at the top and say what changed. Small corrections of wording will not be announced.