A signup has a lifecycle.
What is stored, why it is stored, and what happens when someone leaves the early-access list.
Enter, with consent.
A valid signup contains an email address and explicit consent to Sideby early-access updates. The server trims and lowercases the email, checks it and rejects missing consent.
The database enforces unique email addresses case-insensitively. A duplicate submission does not create a new row, replace the original credential or reveal it.
Two tables. Different purposes.
early_access
id TEXT PRIMARY KEY
email TEXT UNIQUE, NOCASE
consent_version TEXT
created_at TEXT
removal_hash TEXT UNIQUE
signup_rate_limits
key TEXT PRIMARY KEY
attempts INTEGER
expires_at INTEGER- A registration
idis generated withcrypto.randomUUID(). The record stores email, consent version, database-generated UTC signup time and the SHA-256 hash of its removal credential. The current consent value isearly-access-v1.- A private credential
- Thirty-two cryptographically random bytes are encoded as 64 lowercase hexadecimal characters. The plaintext credential is returned only for a new signup; only its hash is persisted.
- A temporary counter
- The counter key is a SHA-256 hash of the current hourly bucket and network address. Attempts and expiry are stored; the raw IP address is not stored in these tables. This is a changing rate-limit identifier, not a claim of anonymization.
Expired counters are deleted in a background task attached to the request. Cleanup runs as new signup traffic arrives, so expiration does not guarantee immediate physical deletion.
Leave with the link you saved.
The private link places the token in the URL fragment. The browser reads it into the removal form. A successful POST hashes the token and deletes the corresponding signup.
The email stays on the early-access list until removed or until the list is retired. Removing a signup does not remove the shared, temporary network rate counter. There is no scheduled expiry for registrations.
Anyone holding it can remove the associated signup. Save it privately. It is not sent by email, returned by repeat signups or recoverable through an account interface.
The frontend clears the fragment after confirmed removal. A no-JavaScript visitor can paste the token displayed on the native confirmation page into the removal form.