Privacy policy
Last updated 11 September 2026
What we collect
Account details
When you register we store your username, your email address, and a bcrypt hash of your password. We never store the password itself and cannot recover it. We also record when the account was created and the time of your most recent sign-in.
Session data
Signing in creates a server-side session row containing your user ID and an anti-forgery token. Your browser only holds a signed session identifier in a cookie. No personal data lives in the cookie itself.
Download records
Downloading requires an account, so every download is recorded against one: which resource was fetched, when, and your user ID. Your IP address is not stored in readable form. We keep a one-way SHA-256 hash of it combined with a secret key, which lets us spot automated abuse without building a readable log of who downloaded what.
Content you post
Resource requests, their text, and your votes are stored against your account and are publicly visible alongside your username. Resources uploaded by administrators are stored with the uploading account's ID.
Abuse-prevention signals
To enforce suspensions and make ban evasion harder, we record three signals against a signed-in account. All three are stored as keyed SHA-256 hashes, so we cannot read the original values back out of them:
- Your IP address, hashed. Not stored in readable form, and never linked to individual page views.
-
A device cookie (
fl_did), a random identifier we generate. It contains no personal data and identifies a browser, not a person. - A browser fingerprint derived from characteristics your browser reports: user agent, platform, language, time zone, screen dimensions, colour depth, pixel ratio, CPU core count, memory class and touch-point count. We deliberately do not use canvas or WebGL fingerprinting.
We cannot and do not collect hardware identifiers. No MAC address, no disk or CPU serial, no motherboard ID โ browsers do not expose these to websites, and we make no attempt to obtain them by other means.
These signals are used for one purpose: deciding whether a visitor is subject to an active suspension. They are not used for analytics, advertising, or building a profile of your behaviour.
Administrative actions
If your account has administrator rights, actions such as publishing or deleting a resource are written to an internal audit log with your user ID and a timestamp. This log is visible only to administrators.
Why we collect it
- To operate accounts
- Authenticating you, and keeping you signed in.
- To run the library
- Attributing uploads and requests, and showing download counts.
- To prevent abuse
- Rate limiting, identifying automated scraping, and enforcing suspensions against people who try to evade them.
- To hold administrators accountable
- The audit log records who changed what.
We do not profile you, we do not build advertising audiences, and we do not run automated decision-making that affects you.
Third parties
These are the only outside services involved in serving this site:
- Backblaze B2
- Stores the resource archives and cover images. When you download something, your browser connects directly to Backblaze using a short-lived signed link, so Backblaze receives your IP address and user agent as part of that request.
- Google Fonts
- The site's typefaces load from Google's font CDN, which means Google receives your IP address when a page loads. If you would rather that did not happen, a browser extension that blocks third-party fonts will stop it; the site stays fully usable with a fallback typeface.
- Our hosting and database provider
- Operates the servers this site and its database run on.
We do not sell personal data, and we do not share it with anyone for advertising or marketing.
How long we keep it
- Account data
- Kept until you ask us to delete the account.
- Sessions
- Expire after 14 days of inactivity, then purged automatically.
- Download records
- Kept indefinitely in hashed form. They contain nothing identifying once your account is gone.
- Requests and votes
- Removed when the request is deleted, or when your account is.
- Abuse-prevention signals
- Deleted with the account. Hashes attached to an active suspension are kept until it is lifted or expires.
Deleting your account removes your username, email and password hash. Resources you uploaded remain published but are no longer attributed to you, so that other people's servers do not break.
Your rights
Depending on where you live you may have the right to access a copy of your data, correct it, have it deleted, object to processing, or receive it in a portable format. If you are in the UK, EU, or EEA these rights come from the UK GDPR and the EU GDPR respectively.
To exercise any of them, contact us using the details below. We will respond within 30 days. You also have the right to complain to your local data protection authority.
Security
Passwords are hashed with bcrypt at cost factor 12. Sessions are stored server-side and the session identifier is rotated when you sign in, so a captured pre-login identifier is useless. All database access uses bound parameters, and every state-changing form carries an anti-forgery token.
No system is perfectly secure. If you believe you have found a vulnerability, please report it privately using the contact details below rather than disclosing it publicly, and give us reasonable time to fix it.
Changes to this policy
If this policy changes materially, the date at the top of this page will be updated. Significant changes affecting how we use existing data will be announced on the site before they take effect.
Contact
Email a85855496@gmail.com for anything relating to this policy or your data.
FiveLeak is operated by FiveLeaks.