Privacy Policy
What the site records about you, who can see it, how long it stays, and how to make it go away. This describes what the code actually does. Where a promise made here and the software disagree, the software is the bug, tell us and we will fix one or the other.
The short version
You can read every page here without an account and without signing in. Making an account takes a display name, an email address and a password, and nothing else, no real name, no date of birth, no phone number, and no payment details, because there is nothing here to buy from us.
We do not sell anything about you, we run no advertising, we do not hand the database to anybody, and we do not give it to anybody training an AI model. Your votes and notes carry your display name in public; your email address never appears anywhere on the site. Ask us and your account goes.
What we collect
What you type in
To make an account: a display name, an email address, and a password. The password is stored only as a hash, it cannot be read back, not by us and not by anyone who steals the database, and if you tell us your password in a message we will ask you to change it.
Optional, and blank until you fill them in: pronouns, a short bio, a profile picture, and identity labels (which get their own section below, because they are the sensitive field on this site). A profile picture is decoded and re-encoded as a PNG the moment it arrives, so the file we store is never the file you sent. EXIF metadata, including any GPS coordinates a phone wrote into a photo, does not survive that and is never saved.
Then whatever you contribute: descriptor votes, star ratings, titles on your shelf, notes, titles you submit along with any cover you upload, links you suggest, credits you submit about the people behind a work, descriptors you propose, reports you file, and messages you send staff.
What the server records as you use it
- An audit log. Actions that change something, such as registering, signing in unsuccessfully, submitting, approving, rejecting, editing a descriptor, banning, granting a badge, write a row saying who did it, what it was, when, and the IP address the request came from. Failed sign-ins record the email address that was typed, which may be an address that has never had an account here. Only admins can read it.
- Rate-limit counters. A bucket name, a count and a one-way hash of whatever identified the attempt. The IP address or email address behind that hash is not written to that table in readable form.
- An error log that includes a date, request method, URL and a stack trace when something breaks. Form contents are not written to it.
- Web server access logs, kept by the hosting company in the ordinary way: usually IP, URL, referrer and browser string, on their retention schedule rather than ours.
What we do not ask for
Real name, date of birth, postal address, phone number, payment details, contacts, location. If you would rather your email address not connect this account to the rest of your life, a throwaway address is fine by us: it only has to work long enough to confirm the account, and later to reset the password if you lose it.
Who can see what
Public, anyone at all, signed in or not, search engines included: your display name, profile picture, pronouns, bio, badges, the month you joined, how many votes you have cast and titles you have added, every note you have written with your name on it, and any title, link or credit of yours that has been approved.
Any signed-in member: your vote history (which title, which descriptor, which way you voted), your submissions including the ones still queued or rejected, your identity labels, and how many descriptors you have proposed.
Moderators: all of the above, plus your email address, plus reports you have filed, messages you have sent staff, and anything of yours sitting in a queue.
Admins: all of the above, plus the audit log, which is where the IP addresses are.
Nobody: your password. Nobody but you: your shelf, and your individual star ratings (those appear only inside a title's average, never attributed). There is no member-to-member messaging here, so the only messages you can send are to staff.
The honest footnote: whoever administers the server can read every table in the database. That is one or two people, it is true of every site you have ever used, and it is the reason the next section says what it says.
Identity labels are the sensitive one
Identity labels are how you describe yourself on your profile, the vocabulary is separate from the descriptors used on titles, because a member is not a plot element. They are optional, they start empty, and you can change or clear them from your settings at any time.
They are visible to any signed-in member who opens your profile. They are used for nothing else: no page lists members by label, no filter searches them, they never feed a vote, a descriptor or a credit, and staff will never cite them at you in a moderation decision.
Given what this site is about, being on a list of queer people is not a neutral thing in every country or every household. Treat that field as public-facing, not as a secret told to friends. Leaving it blank costs you nothing here.
Cookies
Signing in sets a cookie named jhqit, holding nothing but a session identifier. It is HttpOnly (script cannot read it), SameSite=Lax, and marked Secure so it only travels over HTTPS. It is created when you sign in, when a page gives you a form to fill in, such as the sign-in, registration and removal-request pages all do, so the form can be protected against forgery, or when the site has something to tell you across a page load. A visitor who is only reading the catalogue is never given one.
The session behind it lasts two days of inactivity if nobody is signed in, seven days signed in, and thirty days if you ticked "remember me", after which the file on our side is deleted by a nightly job. Deleting the cookie in your browser signs you out immediately. Nothing is stored in localStorage.
Nothing in a cookie here is used to advertise to you, and none of it follows you off the site. The whole site is built to work with JavaScript switched off, so a content blocker or a browser set to refuse cookies will not break a single page, you will simply be asked to sign in again more often.
Other sites your browser talks to
- Cover thumbnails while you search on the submit form load straight from
image.tmdb.org,covers.openlibrary.organd Comic Vine, so those hosts see your IP address for as long as that search is on screen. Once a title is accepted its cover is copied onto our own server, so ordinary browsing never touches them. - Amazon buy links carry our Associates tag, so if you click one Amazon knows you arrived from here, and we earn a commission if you buy something. That commission is the only money this site takes. We are not told who clicked, and there is no Amazon script on any page.
- Links members have added, like an official site, an itch.io page, a publisher's own shop, go where they say they go, and what happens then is between you and that site.
There is no advertising network, no social widget, no comment platform and no session recorder anywhere on this site.
What our server fetches for you
When you search for a title to submit, the search text goes from our server to TMDB, OpenLibrary or Comic Vine, not from your browser. Those services see a request from our server and learn nothing about you. Their answers are cached here for a day so the same search does not go out twice. The API keys never reach your browser.
How long we keep things
- Your account and your contributions: until you ask us to delete it.
- Session files: two days idle for a signed-out session, seven days signed in, thirty days for a remembered one, then deleted by a nightly job.
- Email links (confirm, reset, change of address): a reset link lasts an hour, the others two days, and every one of them is single-use. Only a hash of the link is stored.
- Rate-limit counters: deleted after a day.
- Cached lookups from TMDB and friends: reused for a day, deleted after a week.
- Content removed alongside a ban: stashed for thirty days so the ban can be undone, then permanently deleted.
- The audit log: kept for as long as the site runs. It is the one place an IP address is written down in readable form, and only admins can read it.
- The error log: until it is cleared by hand.
- Web server access logs: whatever the hosting company keeps them for.
What we never do
We do not sell, rent or trade anything about you, and we do not hand your account, your contributions or your email address to advertisers or data brokers. We send no marketing email of any kind. The only mail we will ever send you confirms an address, resets a password, warns you that somebody asked to change your email address, or tells you staff have replied to your message.
We will not hand this database to anyone training an AI model, licence it to anyone who would, or train anything on your notes and votes ourselves. The honest limit on that promise: public pages are public, and a scraper can read whatever a visitor can read. What we control is what we hand over, and we hand over nothing. Anything behind the sign-in, your email address above all, is not in a scraper's reach.
Changing or deleting your data
From your settings you can change your email address, password, pronouns, bio, picture and identity labels, and sign out every device at once. Votes, star ratings and shelf entries can be changed or cleared from a title's page whenever you like, and clearing one deletes the row rather than hiding it.
Notes cannot yet be edited or withdrawn by the person who wrote them, message staff and a moderator will take one down.
To close your account, write to privacy@justhowqueeristhis.com from the address the account uses, or send staff a message from the account itself. It is done by hand, and we aim to have it finished within thirty days; we are volunteers, and it is usually much sooner. What that removes: the account, your email address, your password hash, your votes, your ratings, your shelf, your pending email links and your message threads. What survives, with nothing left pointing at you: titles you submitted that are now live, and notes you wrote, both of which other members' votes hang off, the author becomes nobody. Say in your message if you want the notes taken down as well and we will do that too.
If you want a copy of what we hold on you before it goes, ask in the same message and we will send it.
Where the site runs, and your rights
The site and its database are hosted in the United States. Using it means your data is handled there, whatever country you are reading from.
If you are in the UK, the EU or a US state with a privacy statute of its own, you have rights to see what we hold, correct it, have it deleted, object to how it is used, and receive a copy. There is one way to exercise all of them, write to the address below, it costs nothing, and we will not make you create an account or prove your identity beyond replying from the address the account uses. Nothing here is sold, so there is no "do not sell my information" to opt into: that is already the arrangement. If we handle a request badly, you can complain to your national data protection authority, and we would rather you told us first so we can put it right.
People under 13
The Terms of Use put the minimum age at 13. We do not knowingly collect anything from anybody younger, and if we learn an account belongs to someone under 13 we delete the account and what it holds.
Keeping it safe, and what happens if we do not
Passwords are hashed with a slow algorithm and re-hashed as the cost rises. Email links are stored only as SHA-256 hashes and expire. Every form that changes anything is protected against cross-site request forgery. Uploaded images are re-encoded rather than stored as sent. Pages are served over HTTPS, and no card details exist anywhere in this system because nothing here is ever charged for.
The honest limit: this is a volunteer project, not a company with a security team. If you find a hole, write to privacy@justhowqueeristhis.com, we would much rather hear it from you, and nobody has ever been in trouble for reporting one.
If the database is ever exposed, we will say so on the site and email the accounts affected with what happened, what was in it and what to do about it. We would rather post an embarrassing notice than a quiet one.
Changes to this policy
The date at the top is the only version marker. Small corrections happen without ceremony; anything that materially changes what we collect or who sees it will be flagged on the site, and we will not quietly apply a worse policy to data that was collected under this one.
Contact
privacy@justhowqueeristhis.com reaches the people who run the site. Use it for anything in this policy, for a data or deletion request, for a security report, and for appeals if your account is suspended and the message form is closed to you. Signed-in members can also use the message form, which is usually faster.