RealHandles
Directory Protocol Verify Account

Privacy Policy

Last updated: July 15, 2026

The short version

  • Your private signing key never leaves your browser. It is generated on your device and is never sent to, seen by, logged by, or stored on our servers, even encrypted.
  • We collect very little and never sell it, run ads, or use third-party tracking.
  • Your public profile is public on purpose. The accounts you verify and choose to show are meant to be seen and machine-read. Accounts you hide are never published.

Who we are

RealHandles ("we", "us") is operated by David V. Kimball LLC. This policy explains what we collect when you use realhandles.com and the RealHandles service, why, and your choices. Questions or requests: davidvkimball.com/contact.

What we collect

  • Login identity. When you sign in through our login provider (Auth0), we receive an account identifier and your email address. We use this only to know which identity you are allowed to edit. It is never used to sign your proof.
  • Verification data. The account handles, domains, organization or server names, and public profile URLs you choose to verify or claim; the method used and the time it was verified; and, for organizations and servers, their public logo/icon.
  • Your public key and signed manifest. The Ed25519 public key you generate and the signed proof file it produces. Public keys are, by nature, public.
  • Anchor details. If you set one, the domain or gist location where you host your anchor file, and whether it currently verifies.
  • Technical data. Standard request information (such as IP address and browser type) processed by our hosting and login providers for security, abuse prevention, and reliability.
  • Cookies. We use only functional cookies and local storage needed to run the service: a signed, short-lived cookie during account linking, and login-session storage set by our login provider. No advertising or cross-site tracking cookies. Because these are essential to the service, no consent banner is required, but you can clear them anytime in your browser.

What we deliberately do not collect or keep

  • Your private key. It stays in your browser. Your encrypted backup is stored in your browser's local storage and/or a file you download; the passphrase is yours alone. We cannot recover it, which is the point: no one but you can sign as you.
  • OAuth access tokens. When you link an account, we exchange the code on our server, read your account once to confirm it, and discard the token. We do not store platform access tokens.
  • Gravatar email. If you use the Gravatar option, your email is used in your browser to compute the avatar address and is then discarded, not stored.

What is public

Your public profile page and its signed manifest are intentionally public and machine-readable (both as HTML and as JSON, plus structured data for search engines and AI agents). This includes your username, display name, avatar, key identifier, decentralized identifier, anchor, and the accounts you have chosen to show. Accounts you mark hidden are excluded from the published manifest and do not appear anywhere public.

Who we share data with

We do not sell your data. We use a small set of service providers to run RealHandles:

  • Auth0 (login/authentication).
  • Netlify (hosting and serverless functions).
  • Turso (database / directory cache).

When you verify or import an account, we make a request to that platform (for example GitHub, X, Reddit, or your own domain) on your behalf to read the public proof. Those platforms handle that request under their own privacy policies. We may also disclose information if required by law.

Your rights and choices

  • Access and portability. Export everything we hold about you as JSON from your dashboard at any time.
  • Correction. Edit your profile, remove accounts, or hide them from your dashboard.
  • Deletion. Request deletion of your identity and associated data by contacting davidvkimball.com/contact. Note that your signed manifest is portable by design: any copy you or others have hosted elsewhere, or that third parties have cached, is outside our control and cannot be recalled by us.
  • Depending on where you live (for example the EU/UK under GDPR, or California under CCPA/CPRA), you may have additional rights to access, delete, correct, or port your data, and to object to certain processing. We do not sell personal information. To exercise any right, contact us.

Retention

We keep your data while your identity is active and for as long as needed to operate the service and meet legal obligations. When you delete your identity, we remove it from our database and directory. Copies of your signed manifest hosted outside RealHandles remain wherever they were placed.

Security

The design keeps the one thing that matters most, your signing key, out of our hands entirely. We use reputable providers and standard safeguards for the rest. No online service is perfectly secure, so we cannot guarantee absolute security. To report a vulnerability, see our security.txt.

Children

RealHandles is not directed to children under 13 (or under 16 where a higher age applies), and we do not knowingly collect their data.

International users

Our providers may process and store data in the United States and other countries. By using RealHandles you understand your data may be handled in locations with different data-protection laws than your own.

Changes

We may update this policy. Material changes will be reflected by the date above. Continued use after an update means you accept the revised policy.

See also our Terms of Service.

© 2026 RealHandles. Built by David V. Kimball.

Compare Privacy Terms Security