Skip to content
Account
Create account

Privacy

Last updated 30 August 2026

A HarithKavish Account is the identity used across harithkavish.com and its services. This page describes what that account stores. It covers the account itself — not what any individual service does once it knows who you are.

What is stored

Your account holds only what it needs to be your account:

  • Your name, as you entered it, and your user ID if you chose one. An account created through a provider has no user ID unless you pick one.
  • Your email address, and whether anyone has confirmed it. It is asked for when you create an account and asserted by a provider when you connect one. See How your address is used below — an address nobody has confirmed is never used to find your account.
  • A password hash, if you set a password — Argon2id, never the password itself. An account that signs in only through a provider stores no password at all.
  • Recovery codes, stored hashed. Each works once.
  • Passkeys, if you add any — see below.
  • Sessions: a SHA-256 hash of the session token, when it was created, last seen and expires, and the browser’s user-agent string truncated to 200 characters so you can recognise your own sessions. The token itself is never stored.
  • An account history — that an account was created, a profile updated, a password changed, a provider connected. Timestamps and event types, with no copy of what changed.

If you connect a provider

Two kinds of provider can be connected, and they do different things. Google proves who you are — it can sign you in. Gravatar cannot sign you in at all; it only lends this account your picture and the profile you have written there.

Connecting a provider such as Google adds another way to reach your account. It does not hand your account to them, and your HarithKavish account remains the identity.

From a connected provider we store:

  • The provider’s subject identifier — an opaque string identifying you to that provider. This is what the connection is keyed on.
  • The email address it asserted, if it was verified, and the picture URL it asserted. Both are for display and for recognising which of your provider accounts is connected.

The email address is deliberately not used to find accounts. Matching accounts by email address is how a verified address becomes a way to take one over, so it is stored and shown, and never looked up.

We request only the provider’s identity scopes — with Google, that is openid email profile. No other scope is asked for, because no other data is wanted. Access and refresh tokens are never stored: the provider’s answer is verified once, at sign-in, and discarded. Nothing here can act on your behalf at a provider, then or later.

A provider’s picture is shown only if you choose it. The default is a placeholder, and you can return to it at any time.

Gravatar in particular

If you connect a Gravatar, the whole profile it returns is stored and shown back to you on your profile page. That is everything you have chosen to put on your Gravatar — which may include your name, description, location, job title, company, pronouns, links, interests, verified accounts, and, if you have added them there, contact details and payment information.

None of it is asked for field by field: it is the profile as Gravatar hands it over. If you would rather this service did not hold some part of it, remove it from your Gravatar profile and reconnect, or disconnect and it goes with the connection.

It is a snapshot, not a live view. The token that could refresh it is discarded as soon as the profile is read — Gravatar’s server-side tokens never expire, and keeping one would mean holding a credential with no end date. So what you see is what was true when you connected, until you reconnect.

What is not stored

  • Your password, in any recoverable form.
  • Any biometric data, or any passkey private key. Neither is ever sent to this service.
  • Provider access tokens, refresh tokens or ID tokens — including Gravatar’s, which would otherwise never expire.
  • Advertising or analytics identifiers. There are no third-party trackers on this site.
  • Any message sent to your address. Nothing is sent to it at all.

How your address is used

Your address is how this service recognises that the person signing in with a connected provider is someone it already knows — rather than creating a second account beside the one you already have.

Only a confirmed address is ever used for that. An address you typed is not confirmed: typing one proves only that it was typed. It becomes confirmed when a provider asserts the same address for an account you are already signed in to, which is what connecting a provider does.

The distinction is the whole point. If an unconfirmed address could be matched, anyone could type someone else’s when creating an account, wait, and collect that person’s next sign-in through a provider. So an unconfirmed address is stored, shown to you, and used for nothing else.

Passkeys

A passkey lets you sign in with your fingerprint, face, device PIN or a security key. The check happens entirely on your device.

No biometric data ever reaches this service. Not a fingerprint, not a face, not a Windows Hello PIN, not anything derived from them. Your device verifies you and then signs a one-time challenge; what arrives here is that signature.

For each passkey, this service stores only public information:

  • The credential’s public key and its identifier.
  • A signature counter, and whether the passkey is synced across your devices — both reported by the authenticator.
  • How the authenticator can be reached — USB, NFC, or built into the device — and the name you give the passkey. This service is not told what device you used, so it does not claim to know.
  • When it was added and when it was last used.

The private key never leaves your device and is never shared with this service. Removing a passkey here deletes what is stored and stops it signing you in; the credential on your device is yours to remove there.

Cookies

Only cookies the service cannot work without:

  • __Host-hk_session — your session. Host-only, Secure, and not readable by scripts.
  • __Host-hk_oauth — the ten-minute state of a sign-in in progress with a provider.
  • hk.user — your display name and picture, readable across harithkavish.com subdomains so each site can show you as signed in. It carries no authority: no service treats it as permission to do anything.

Your IP address

Sign-in and sign-up attempts are rate-limited to five per ten minutes. Your IP address is used as the bucket key for that limit and is never written to the database. Our hosting provider keeps its own request logs, as any web host does.

Who else is involved

  • Vercel — hosting.
  • Neon — the database.
  • Upstash — the rate-limit counter.
  • Google — only if you choose to sign in with or connect it.
  • Gravatar (and WordPress.com, which issues its tokens) — only if you choose to connect it.

Your account is not sold, rented or shared with anyone else.

Deleting your account

Deletion is immediate and permanent. The account row is deleted outright rather than marked deleted, and your sessions, provider connections and recovery codes go with it. Your user ID is released and someone else may take it.

The account history is kept, with its link to you removed — so the record that something happened survives, while nothing identifying you does. It carries no copy of your name or user ID.

Contact

Questions about this account service: harithkavish40@gmail.com.

account.harithkavish.com
PrivacyTermsHarithKavish