What's kept, why, and what never is — in full, not a summary.
No IP address. No user agent. No referrer. No browser or device fingerprint. No email address — none is ever asked for. No real name. No payment details of any kind (there is nothing to pay for yet). None of this is disabled by a setting; it is simply never written down anywhere in the stack, logs included.
Nothing here reports to anyone outside this service. No analytics, no advertising network, no third-party error-reporting tool, no tag manager, and no font or script loaded from someone else's server who could otherwise see your visit. If something here ever fails, it's logged to disk, on the machine that runs it — nowhere else.
There are two separate locks, and they are never mixed. Your own words — task answers and letters — are locked with a key that lives outside the codebase and outside the database, unlocked only to show them back to you. Her private notes about you are locked completely separately, under a passphrase that only she holds on her own machine; the server that runs this site can never read them, under any circumstance.
Settings has a single button. Pressing it is immediate and total: your handle, your answers, your letters, and everything about your standing with her are erased from the database at once — not deactivated, not held, not recoverable afterward by anyone, including her.
That erases what the service reads from day to day. Whether anything of it can briefly persist in an operational backup before that copy is itself cycled out is being confirmed, and this page will say so plainly once it is.
If what's stored ever changes, this page changes with it — there is no separate notice, so it's worth a re-read now and then.