Sicherheit

Hier steht nur, was der Code wirklich tut. Was wir nicht tun, hat einen eigenen Abschnitt – den solltest du zuerst lesen, wenn du es eilig hast.

Zuletzt aktualisiert: 2026-09-05

Dieses Dokument ist auf Italienisch und Englisch verfasst, und diese Fassungen gelten. Hier liest du die englische. Italiano · English

1The money

2Deletion, and what survives it

When you delete your account you disappear from every public surface immediately and stay restorable for six months. After that the row is anonymised: unroutable e-mail, neutral name, emptied profile, messages and friendships deleted.

Payments are never deleted, not even then — and that is not an oversight, it is the right decision made twice. The first version deleted them, and it also deleted payments other people had made to groups founded by whoever was leaving. Today erasure happens on the user row, not on the ledger: the accounting record stays and no longer identifies anyone.

3Signing in

4Who can look inside

The administration panel lives on a separate subdomain and passes, in this order: Cloudflare's corporate access with a Google account, a closed list of permitted addresses, a dedicated password (bcrypt, unrelated to any user password) and a freshly generated six-digit code. Actions that write something ask for a new code every time, not once per session. A session lasts an hour.

Administrators are a separate table, with no link at all to the users' table. There is no "you are an administrator" column on your account: no vulnerability in the app can promote anyone, because there is nothing to promote. Administrator accounts are created only from the command line on the server.

Every administrative request goes into a log that is written and not deleted — including the refused ones, which today are most of them. Sensitive values in request bodies are redacted before being written.

5The infrastructure

6The code

7What we do NOT promise

This section exists because a security page that lists only the good parts is not a security page.

8Found a problem?

Write to [email protected] describing what you did and what you got. We answer, we tell you what we understood, and we let you know when it is fixed.

We ask only two things: do not touch other people's data, and do not degrade the service for people using it. Anyone who behaves that way will have no trouble from us.

Web-App öffnen Kontaktiere uns