Skip to content
DarkPrint
Legal

Privacy

What DarkPrint stores about you, why it is stored, who else can see it, and how to remove it. Written against the database schema rather than from a template, so every field named here is a field that exists.

Last updated 11 September 2026

You can read the whole site without an account

Browsing blueprints, reading cards, searching, and validating a folder on Publish need no account and store nothing about you. The validator runs in your own tab.

What signing in stores

Signing in uses GitHub or Google. DarkPrint never sees your password. From GitHub it asks for read:user user:email, and from Google for openid email profile, which are the narrowest scopes each offers for identity. Nothing about your repositories, your Drive, your contacts or your calendar is requested.

What is written to the database is your provider account id, the login name the provider asserts, the email address it asserts, and the display name and avatar it returns. If you link a second provider, that identity is stored beside the first with the address it asserted at the time, kept as the record of why the two were joined. Identities are matched on the provider’s own stable id and never on an email address, because addresses move between people.

A handle, a display name and a bio are yours to set, and are public when set. Your email address is not shown on any page.

What using the site adds

Blueprints and cards you publish, forks you cut, drafts you start, and the visibility you set on each. Saves, stars and notes you leave, which are public where they render. Run reports you submit, which carry what a run cost and never the run’s content. An audit trail of account actions, which records what was done and to what, and deliberately never a credential, a query or a stack trace.

Cookies

One cookie, darkprint_session, set when you sign in and holding a signed session. It is HttpOnly, so scripts cannot read it, and it is sent only to this site. There is no advertising cookie and no cross-site tracker.

API keys

A key is shown to you once, at the moment you mint it, and only a hash of it is stored. DarkPrint cannot show it to you again and cannot recover it, which is also why nobody who reads the database can use your key. Revoking a key is the way to take it back, and revocation is immediate.

Who else processes it

The site runs on Vercel and the database and file storage are Supabase, in the European Union. Sign-in goes through GitHub and Google, who see that you signed in here.

Vercel Web Analytics counts page views. It sets no cookie and does not follow you across sites. Where a page address contains a secret, which is true of a live tutorial page, the address is rewritten to its route before the count leaves your browser, so no token reaches the dashboard.

Nothing is sold, and nothing is shared with anyone else. No mail is sent, because no sender is configured.

Deleting your account, and the one thing that survives it

You can delete your account from Settings. Your bundles and their releases go, and so do the files behind them.

Two things outlive the deletion, and both are deliberate. A tombstone row remains, so that counts and references elsewhere do not silently change meaning. And your handle is reserved permanently: nobody can claim it afterwards, including you. That is there so a name someone linked to cannot later point at a different person. Tell us if you need the tombstone itself removed.

Asking for a copy, or a correction

Write to dev@darkprint.io for a copy of what is held about you, a correction, or a deletion that the Settings page does not cover. DarkPrint is a small project rather than a company; the answer comes from a person reading the same database this page describes.

Changes

This page is versioned with the site, so its history is in the repository beside the schema it describes. The date at the top is the day it last changed.

Terms of use covers what you may do here and what DarkPrint promises in return. The canonical address for this page is https://www.darkprint.io/privacy.