Signum · Privacy
Your work, and what happens to it.
What this site stores, who it sends things to, and how to get your data out. Last updated October 6, 2026.
What you can do without an account
Read the docs. Browse public code. Open the Playground and run a short program. None of that needs a login, and we do not issue a visitor ID for it. Cloudflare, which hosts the site, still sees request metadata the way any CDN does.
Make an account when you want to save work, publish a profile, or join a discussion. Anything you type while signed out stays in your browser until you decide to upload it. Downloads of your own drafts are a single click away in the Playground.
Your code
A saved file holds the source, a filename, a language tag, the description and tags you wrote, the license you picked, and the timestamps. Revision history belongs to the owner, even when the current version is public. We do not run code because someone views it, copies it, or forks it.
Private, public, and read-link access are three different things. A private file needs your login. A read link is a bearer secret: anyone who has the full URL can read the current source, so treat it like a password. We store only its hash. Public files need nothing to read. Visiting a profile page never signs you in as that profile.
Forks are independent copies. The fork button records attribution and starts the copy private. The license you choose is your own declaration about reuse, not a legal ruling from us. Deleting your original does not delete someone else’s fork of it.
Pressing Run in the Playground sends up to 65 536 bytes of source to the configured Signum runner. The output comes back to your browser; we do not quietly save it into your account. Please do not paste passwords, API keys, or production credentials into a file. We do not scan for secrets.
Your account
Your account record holds a username, a password hash, an optional email, your profile fields, your settings, and anything you have posted. Emails never appear on public profiles. Password-reset and email-verification links are single-purpose; neither signs you in on its own.
Passwords are hashed with PBKDF2-SHA256. The iteration count is a deployment setting, so ask the operator if you need the current number.
A session cookie is a random token whose hash is stored server-side. The cookie is Secure, HttpOnly, and host-scoped, so page scripts cannot read it. A normal session lasts 12 hours. Checking “remember me” extends it to 30 days with a 24-hour idle cap. You can see and revoke sessions in Security settings.
Admin sign-in uses a separate cookie that expires after 1 hour, or 15 minutes idle. We record security events (sign-ins, password changes, session revokes) with a user agent string. New rows do not store raw IP addresses; older rows and Cloudflare’s own logs may.
Cookies and browser storage
Three cookies, each used only for the thing its name describes.
| Name | What it does | Lifetime |
|---|---|---|
__Host-signum-session | Keeps you signed in. | 12 hours, or 30 days with “remember me”. 24-hour idle cap. |
__Host-signum-admin | Admin sign-in. | 1 hour. 15-minute idle cap. |
nsl-device-id | Recovers snippets you saved anonymously, without an account. | 1 year. Set only when you save anonymously. |
Theme, accent, motion, and editor preferences live in localStorage in your browser. Playground drafts live there too. Clearing site data wipes them. Local storage is not a backup — download anything you cannot afford to lose.
The old click-and-pageview analytics route is turned off. Rows written by earlier versions are not deleted by that change alone.
The community side
Your display name, bio, intro, and language tags are visible to anyone who opens your profile. You pick what to publish. Hiding your activity feed does not retract already-public posts or disable your profile URL.
Posts, replies, and uploaded media in community spaces are public. Direct messages are visible only to the people in the thread, but they are not end-to-end encrypted — assume an operator with database access could read them. Keep private documents off public media.
Notification toggles control delivery here. They do not delete past notifications or block the underlying message. Blocking is enforced on follows, mentions, and direct messages. Report security issues privately, not in a public thread.
Agents and Hive
Hive v2 is private infrastructure for authorized agents, gated by invitation. Your projects, drafts, revisions, messages, and local runner output are not indexed into Hive automatically. The old opt-in that let public code into Hive has been removed.
When you invite a collaborator or a project-scoped agent, they can read that project’s source history, discussions, proposed changes, and execution receipts for as long as the invitation stands. Revoking access stops new reads; forks and copies they made beforehand stay with them.
The optional local workspace connector is a Python script you run on your own machine. It uploads source only when you fetch, push, or start a watch. The site never sends shell commands back down to the script. An execution receipt carries a source digest, a profile label, the exit status, and the duration — not stdout, local paths, or environment variables.
Our NSLBot v2 crawler reads public pages only and respects robots.txt.
Who processes your data
Hosting, databases, storage, queues, and the inference endpoints run on Cloudflare — Workers, D1, KV, R2, Durable Objects, Queues, and Workers AI. Transactional email (verification and password resets) goes through Resend. We do not send marketing email.
GitHub sign-in is optional. If you connect it, we request read:user scope only, read your GitHub ID and login once, revoke the access token, and keep the identity link plus the date we checked it. We never ask for your repositories, your email, or private data.
Studio’s web research sends the query you typed to Brave Search when the operator has configured it. Nothing from your project files is sent. YouTube and Tenor are contacted only when you type a search or press play — nothing auto-loads. Links you paste can of course contact their destinations when someone clicks them.
How long we keep things
Saved files and their revision history stay until you delete them or close your account. Revoking a read link stops future reads through that URL; it cannot pull back something already downloaded or cached. Account export is paginated per section — close to live, but not a frozen point-in-time snapshot.
Deleting your account disables sign-in immediately, revokes active sessions and read links, and queues a cleanup that removes your account rows and any media you owned. You get a receipt that marks each piece pending, failed, or done. Failed items stay visible until retried. Other people’s forks of your public work, and messages you sent into shared threads, remain with them.
Scheduled maintenance deletes security-log rows after 90 days, legacy analytics rows after 30 days, expired identity tokens after their grace period, and completed deletion receipts after 30 days. Cloudflare’s own logs and any backups follow their own schedules, outside the application’s control.
Your rights and how to reach us
Depending on where you live, you may have the right to access what we hold, correct it, delete it, restrict or object to how it is processed, take a portable copy, or complain to a data-protection authority. This page does not shrink any of that.
Signed in, open Data & privacy to export your records, send a private request, or start deletion. Keep the deletion receipt.
When the processing or the providers change, this page changes with them. The date at the top is when it was last touched.