Privacy

3 September 2026

sz.ws is run by one person. There are no ads, no tracking cookies, and your data is never sold to anyone.

Contact

sz.ws is run by Suko, an independent developer based in Taiwan. Questions go to suko@sz.ws.

Your data

Browsing the catalogue needs no account. The site is hosted by Cloudflare, and the only things kept in your browser are the language you picked and whether you want light or dark. Once you create an Access account, this is what is stored:

  • Your email address, used to send sign-in codes and the account deletion link. Mail comes from access@sz.ws. It is never shown publicly and never used for promotion.
  • Your passkeys: the public key, credential id, and device name. The private key never leaves your device.
  • Your handle, display name, and bio.
  • Your picture, shown on your public page and in products you have signed into.
  • One record per signed-in browser, with the time you signed in and the IP address. Each lasts 30 days, and you can end any of them from your account page.
  • Which sz.ws products have read your sign-in, and which third-party apps you have approved through OpenID Connect, with the scopes you granted.

What is public

Every handle has a page at sz.ws/@handle showing the handle, picture, display name, bio, verification mark, and the month you joined. Search engines can index it. Your email, signed-in devices, passkeys, and connected services are not public; only you see them, and only after signing in.

Products under sz.ws share the sign-in, so once you are signed in they can read your account id, email, handle, and picture.

Apps on other domains get nothing unless you allow it on a consent screen that names the app and the scopes it is asking for. Anything you have allowed can be revoked from your account page.

None of this is sold or rented, and there is no advertising on sz.ws.

Deleting your account

The account page has a delete option. It sends a confirmation link to your email; using it removes your profile, picture, passkeys, signed-in devices, and every authorisation record.

A deleted handle is not reissued, so an old link never points at someone else.