Curation Network

Account privacy

Last updated:

This notice covers the shared Curation Network account service, operated by Alexey at accounts.alexey.ws. Your account connects libraries, guides and AI access. For questions or data requests, contact mail@alexey.ws.

Your account and sign-in

We store your account ID, name, email address, email verification status, profile image when provided, and account creation and update times. Google sign-in also records your Google account identifier and authentication tokens. Stored Google access and refresh tokens are encrypted.

Google sign-in requests your identity, email and basic profile. It does not request access to Gmail or Drive. Email sign-in, when available, sends a single-use link valid for 10 minutes. Its verification token is stored as a hash. Password sign-in is not enabled.

Sessions and browser storage

We use a session cookie to keep you signed in. Session records include a session identifier, your account ID, IP address, browser user agent and timestamps. Sessions expire after seven days and are renewed during use. Sign-in requests are rate limited, with request counts stored for abuse prevention.

Your browser stores your theme preference. Checkout request identifiers are kept in browser session storage to avoid duplicate requests. A signed cookie preserves an optional newsletter choice for up to 10 minutes during sign-in.

Newsletter choice

A newsletter subscription requires your explicit agreement. The checkbox starts unchecked, and subscribing is not required to create or use an account. We record your verified email, account ID, originating library, choice, consent text and version, and the time of each change.

Change your choice in your account by clearing the newsletter checkbox and saving. Unsubscribing updates your preference and preserves its history. Sign-in messages are separate from newsletter consent. Consent records are also sent to our private Payload CMS for the account newsletter list.

PayPal and library access

Paid plans are shown only when their library access is available. PayPal handles checkout and recurring payments for an approved plan. The account service also uses PayPal Sandbox while testing changes; Sandbox payments do not grant live access.

The subscription system stores your account, chosen plan and library, checkout and PayPal subscription identifiers, payment status, amount, currency and paid access period. It retains limited payment, cancellation and adjustment event details to reconcile access. Card details are entered at PayPal, not in our account forms. We do not store a full PayPal payer profile.

Connected AI clients

An AI connection asks for your approval and lists its permissions. We store the client identifier and registration details, your consent, granted permissions and token records. Approved identity permissions allow the client to receive your account identifier, name, email or profile image. Library access remains limited to your active entitlement.

AI access tokens expire after five minutes. Refresh tokens allow a connection to continue. Disconnect a client in your account to revoke its access. Information already received by a third-party client is handled under that client's own privacy practices.

Services and data retention

Cloudflare hosts the account service and its database. Our Payload CMS stores newsletter consent history. Google handles Google sign-in, PayPal handles payment setup and processing, and your chosen AI client receives the information you authorize. These services process the data needed for their role and may keep their own operational logs.

There is currently no automatic time-based deletion schedule for account profiles, payment records or consent history. Token expiry does not mean all associated records are erased. To request access to, correction of or removal of your account data, email mail@alexey.ws. There is no automatic account export or deletion control in the portal.