Steroid Radar

Privacy Policy

What we collect, why, and how to make us forget.

What we collect

To browse the site anonymously, you give us nothing beyond what any web server sees: a short-lived request log with your IP address, user agent, and requested path. To post reviews or vote, you create an account, which stores:

  • Username (chosen by you, public).
  • Email address (private, used for login and password reset).
  • Hashed password — we never store or see the plaintext.
  • Any review text, replies, votes, or uploaded images you submit.
  • An optional avatar you upload.

What we do with it

  • Authenticate you and keep you logged in via a signed session cookie.
  • Associate your reviews and votes with your account so you can edit them later.
  • Calculate the karma and activity numbers shown on your public profile.
  • Detect coordinated voting/brigading (see the methodology).
  • Send the occasional password-reset or email-verification email.

We do not sell your data. We do not run third-party advertising or behavioral tracking.

Third parties we use

  • Resend — transactional email delivery only (password reset, verification).
  • Our hosting provider — standard request logs, kept for a short retention window.

No analytics or ad SDKs are loaded in the browser. If that changes, this list will be updated before the change goes live.

Cookies

We use one first-party cookie for your session (set on login, cleared on logout) and a small amount of browser storage for UI preferences (e.g. which review list is expanded). No tracking pixels.

Deletion

You can delete your account from the profile settings or by emailing [email protected] from the address on file. Deletion removes your email and avatar immediately. Your posted reviews are either anonymized (username replaced with deleted-user) or fully removed — your choice at deletion time. Public activity that has already been aggregated into ratings continues to influence scores, but is no longer attributed to you.

Contact

Privacy questions, data-access requests, and deletion requests go to [email protected].