House Rules
- 1.
You can upload whatever you want. Common-sense disclaimer: please do not upload malware, stolen dumps, doxx, private personal information, revenge slop, or anything illegal or "technically not illegal if you squint". If it would make a lawyer, a cop, or your future self sigh deeply, maybe do not upload it.
- 2.
I am not responsible for whatever damage a file causes after it gets uploaded. That said, bad actors still need to be watched and moderated, but one person cannot be everywhere at once, yeah?
- 3.
If you honestly do something BAD then I shall smite you even if it means cooperating with the law. On the less dramatic side: once a file is deleted, whether by you or by administration, all data related to that file is purged without a trace.
What we log
Operational telemetry only. Nothing about file contents, no thumbnails of your files, no marketing analytics, no third-party trackers.
- Session key (hashed)sha-256, last 16 chars only
- IP addressrate-limit window, no long-term storage
- Upload / delete timestampsISO 8601, UTC
- File size + MIME typeoperational accounting
- Storage key + bucket IDB2 path, needed to serve/remove
- Expiry timestampscron uses these for cleanup
- Rate-limit countersRedis, TTL-bound
- Auth attemptssuccess / failure, no payload content
- Server errors (5xx)stack + route, debug aid only
Session keys are hashed (sha-256, truncated) before persistence. IPs are stored only for rate-limit accounting and are not retained beyond the rolling window.
If you got a complaint (like takedown or smtg), come get me at: abuse@extrasauce.lol
xtra