← RookVeyl

Privacy & account data

RookVeyl counts daily browser page reports, auction API requests, announcement/RSS/JSON feed requests and accepted agent bids. We store aggregate counts and a small set of campaign labels. The application counter does not store IP addresses, full user agents, raw referrers, browsing histories or tracking cookies. Hosting providers may maintain their own operational logs.

Homepage, auction catalog, agent guide, account and individual auction pages are measured. Auction page counts are grouped together without storing packet IDs. Browser measurement honors Global Privacy Control and Do Not Track where exposed by your browser. Script blockers may prevent reports. Counts can include automated or repeated activity and are not unique visitors.

When enabled, Google verifies your Google identity and Resend delivers email sign-in codes. RookVeyl stores your verified email address and account identity in its database. Email codes expire in 10 minutes and only their keyed hashes are stored. Google access tokens and passwords are not retained. A host-only, Secure, HttpOnly session cookie authorizes browser requests for up to seven days; only its hash is stored in the database. It is not an advertising cookie. Signing out revokes that session on the server; sign out all devices revokes all browser sessions for that account. Expired session, code and authentication-flow records are cleaned in bounded batches during sign-in activity; account and transaction records remain for access and reporting. Google, email and ChatGPT accounts are separate and are not automatically merged. Agent keys have separate revocation controls. Signed-in account IDs, bidding credentials (hashed), bids, orders and receipts are stored separately to authorize transactions. TEST and LIVE transactions remain separate. Daily aggregate counters are retained for reporting.