1. Who We Are
This Privacy Policy explains how ableproman ("we", "us", "our") collects, uses, and protects information when you use getyourhandle.ableproman.hu (the "Service"). We built the Service to be as minimal as possible: it does not ask for your email address, real name, or phone number to work.
2. Information We Collect
| Data | Why we collect it |
|---|---|
| Handler (username) | To identify your account and let others see the identity you've claimed. |
| Password hash | To authenticate you at login. We never store your password in plain text and cannot see or recover it. |
| Session cookie | To keep you logged in during your active browser session. |
| Persistent token cookie & hash | If "Remember me" is checked at login, a secure 30-day token is saved in a cookie and its cryptographic hash in our database to re-authenticate your device after your session ends. |
| Timestamp of last password change | To enforce a minimum 24-hour cooldown between password changes, as an anti-abuse measure. |
| Basic request metadata (e.g. submission timing) | To detect and block automated bot registrations, alongside a hidden honeypot field. |
We do not collect your email address, phone number, real name, physical address, or payment details, because the Service does not require any of them.
3. How We Use Your Information
- To create, secure, and authenticate your account.
- To display the total number of registered users on the Service.
- To enforce the acceptable-use rules described in our Terms of Service.
- To maintain the security and stability of the Service, including preventing automated abuse.
We do not use your information for advertising, and we do not sell or rent your information to third parties.
4. Cookies & Local Storage
We use essential cookies strictly required to maintain your authentication state:
- Session cookie: Keeps you signed in during your active browser session. It expires when your browser session ends.
- Persistent "Remember Me" cookie (
gyh_remember): If you check "Remember me on this device" during login, we issue a cryptographically secure token cookie valid for 30 days. A hashed copy is stored in our database. When your browser session expires, this cookie automatically re-authenticates you and rotates to a new secret key for maximum security. This token is instantly deleted whenever you explicitly log out, change your password, delete your account, or sign in without checking "Remember me".
All authentication cookies are set with strict HttpOnly (inaccessible to scripts), SameSite=Lax, and Secure flags over HTTPS. Additionally, we store your light/dark visual theme preference in your browser's local storage, which remains entirely on your device and is never transmitted to our servers.
5. Data Sharing
We do not share, sell, or disclose your account information to third parties, except:
- Where required to comply with a valid legal request from a competent authority.
- Where necessary to protect the rights, property, or safety of ableproman, our users, or the public.
- With infrastructure providers (such as hosting) strictly to the extent needed to operate the Service, under obligations to keep data confidential.
6. Data Retention
We retain your account data for as long as your account exists. If you delete your account, your handler, password hash, remember token hash, and related account records are permanently removed from our active database immediately, and your handler becomes available for others to claim.
7. Your Rights
Depending on your location, you may have rights to access, correct, or delete your personal data, and to object to or restrict certain processing. Because the Service is designed around a self-service account model, you can exercise most of these rights directly:
- Access/portability: your handler and account status are visible to you whenever you're logged in.
- Correction: you can update your password at any time from account settings.
- Deletion: you can permanently delete your account and all associated data from account settings.
For anything not available through self-service, contact us via the details on ableproman.hu.
8. Data Security
Passwords are hashed with bcrypt before storage and are never stored or logged in plain text. Session and remember tokens are protected using strict cryptographic hashes and HttpOnly/SameSite cookies. While we take reasonable technical measures to protect your data, no method of storage or transmission is 100% secure, and we cannot guarantee absolute security.
9. Children's Privacy
The Service is not directed at children under 16. We do not knowingly collect data from children under this age. If you believe a child has registered an account, contact us so we can review and, if appropriate, remove it.
10. International Data
Our infrastructure may be located in Hungary or other countries within the European Economic Area. If you access the Service from outside this area, your information may be transferred to and processed in a country with different data protection laws than your own.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date above. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
12. Contact
Questions about this Privacy Policy can be directed to us via the contact information listed on ableproman.hu.