deltavdevs / ward
Privacy Policy
Effective September 24, 2026 · Version 2026-09-24
Ward is the sign-in service for DeltaVDevs sites, including the blog, DeltaTime and SynthCity. It is run by DeltaVDevs, the independent developer publishing as DeltaVortex. This policy covers Ward itself at ward.deltavdevs.com. Each site you sign into with Ward also has its own policy for what it does with your data. For privacy questions or requests, contact contact@deltavdevs.com.
What Ward stores
Your account: a random account ID, display name, username, profile picture link, and email address. Ward only stores an email once you've proven it's yours, either by clicking a link we sent or because Google, GitHub or Discord says it's verified. We also store when you created the account and last signed in, and which version of these policies you agreed to.
Sign-in methods: if you use Google, GitHub or Discord, we store that provider's ID for your account, plus the username and verified email it reports. If you set a password, we store a salted scrypt hash, never the password. If you turn on two-factor authentication, we store your authenticator secret encrypted, and your recovery codes as hashes.
Sessions and security records: for each browser you're signed into, we store the IP address, browser user-agent, sign-in time, method used and last activity. We also keep an activity log of security events such as sign-ins, failed attempts, password and 2FA changes, and apps connected or disconnected, with the IP address involved.
Connected apps: which DeltaVDevs sites you've let use your Ward account, what they can see, and the access tokens issued to them. Tokens are stored as hashes.
What sites you sign into receive
When you sign into a site with Ward, it receives only what it asked for and you allowed. That can include your account ID, display name, username, profile picture, and verified email. Ward never shares your password, 2FA secret, recovery codes, IP history or other connected apps. Each site uses that information under its own privacy policy. You can see and disconnect connected sites from your account page at any time.
Why we use it
We use this information to sign you in, keep your account secure, let you use one account across DeltaVDevs sites, detect and stop abuse such as password guessing and account takeover, and answer your requests. Where data protection law requires a legal basis, we rely on providing the service you asked for, our legitimate interest in running and securing it, and legal obligations where they apply. We don't sell personal information, show ads, or use tracking or analytics cookies.
Other services involved
Ward runs on Railway, and its data is stored in a PostgreSQL database there. Account emails such as confirmation, password reset and change notices are sent through Resend. When you choose a new password, the first five characters of its SHA-1 hash are checked against the Have I Been Pwned breach list. Your password itself and its full hash never leave Ward. If you sign in with Google, GitHub or Discord, that provider processes your sign-in under its own privacy policy. Pages load stylesheets and fonts from DeltaVDevs and Google Fonts, and show profile pictures from the provider that hosts them. Your data may be processed outside your country, with protections required by applicable law.
Cookies
Ward only uses cookies it needs to work:
- a session cookie that keeps you signed in for up to 30 days;
- a browser cookie that protects forms against cross-site request forgery;
- short-lived cookies, lasting at most 15 minutes, that hold a sign-in, 2FA setup or sign-up that's in progress.
There are no advertising or analytics cookies.
How long we keep it
Account information is kept while your account exists. Sessions end when you sign out or after 30 days. Access tokens expire after an hour, and refresh tokens after 30 days without use. Email links expire after an hour. The security activity log is kept for about 13 months, and it stays after an account is deleted so we can investigate abuse. Server logs and any backups follow our hosting provider's rotation.
Your choices and rights
From your account page you can:
- edit your profile;
- change your email or password;
- link or unlink sign-in methods;
- turn two-factor authentication on or off;
- sign out other browsers;
- disconnect sites;
- download everything Ward stores about you as JSON;
- delete your account.
Deleting your Ward account removes your profile, sign-in methods, sessions and connected-site permissions, and ends every site's access. It does not delete data a site stored itself, so ask that site separately. You can also contact contact@deltavdevs.com to request access, correction, export or deletion. Depending on where you live, you may have further rights, such as objecting to or restricting processing, and complaining to your local data protection authority. We may need to confirm a request is really from you. We will never ask for your password, 2FA code or recovery codes.
Security
We use hashed credentials, encrypted 2FA secrets, single-use and short-lived sign-in codes, rate limits, and optional two-factor authentication. No internet service can promise perfect security. If we learn of a breach that affects you, we will tell you as the law requires.
Children
Ward accounts are not for children under 13, or under the minimum age where you live. If you think a child has created an account, contact contact@deltavdevs.com and we'll look into it and remove it where appropriate.
Changes
Changes are dated on this page. If a change is material, we'll give notice and, where required, ask you to agree again. Questions go to contact@deltavdevs.com.