Security
How we protect your data
A journal is one of the most personal things you can keep. Here's exactly what we do to make sure it stays yours.
Passwords are never stored in plain text
Every password is hashed using bcrypt with a cost factor of 12 before storage. We never see your password, and neither does anyone with database access.
Authentication via httpOnly cookies
Session tokens are stored in httpOnly cookies, making them inaccessible to JavaScript and resistant to XSS attacks. Cookies are flagged Secure and SameSite=Lax.
HTTPS everywhere
All traffic between your browser and our servers is encrypted using TLS. Connections over plain HTTP are redirected automatically.
Rate limiting on sensitive endpoints
Login, registration, password reset, and email verification endpoints are rate-limited to prevent brute-force attacks.
Email verification for new accounts
New accounts require email verification before login. Verification links expire after 24 hours.
Expiring tokens for sensitive actions
Password resets, email changes, and account deletion all use single-use cryptographically random tokens that expire within 1 hour.
Scoped deletion confirmation
Account deletion requires a confirmation click in an email sent to your registered address. The link works once and expires in 1 hour.
Data encrypted at rest
Your data is stored with a cloud database provider with encryption at rest enabled. Uploaded files are stored on an encrypted cloud volume.
What we don't do
- ✕We don't read your private journal entries
- ✕We don't use your content for advertising or AI training
- ✕We don't store plain-text passwords
- ✕We don't use tracking cookies or analytics scripts
- ✕We don't share your data with advertisers
Found a vulnerability?
If you discover a security vulnerability in Story of Days, please report it responsibly by emailing [email protected]. We'll acknowledge your report within 48 hours and keep you updated as we investigate. Please don't publicly disclose the vulnerability until we've had a chance to address it.