Your privacy.
This page explains how the MossyScripts application handles information when you use an account or browse the library.
Account information
We store your username, email address, password hash, verification status, profile bio, and account timestamps. Passwords are hashed with Argon2id; the application does not store readable passwords. Your email address is not included in public profiles.
Public contributions
Your username, bio, join date, scripts, and contribution statistics are public. Script source code, descriptions, tags, and update history are public while a script is published. Do not include secrets or personal information in submitted code.
Sessions and preferences
An essential HttpOnly cookie keeps you logged in. Session records include a browser label, activity times, expiry, and a keyed hash of the connection address. The application stores your theme preference in your browser. It does not store authentication tokens in browser local storage.
Saved scripts and browsing history
Your saved scripts and signed-in viewing history are available through your account. Public pages show aggregate view and save counts. View deduplication uses a daily keyed identifier derived from connection information. You can revoke sessions and log out of all devices in account settings.
Email and infrastructure
Your email address is used to deliver verification and password-reset messages through the site’s configured email provider. The hosting service and any configured reverse proxy process network requests to deliver the site and protect it from abuse. The application itself includes no advertising or third-party analytics scripts.
Moderation records
Reports and administrative actions are stored to support moderation and accountability. Report details are available to authorized moderators. Public pages do not expose report authors, session credentials, or password-reset tokens.
Data management
You can edit your bio, remove bookmarks, delete your published scripts, and revoke sessions from your account. Script deletion removes the contribution from the public library; retained version and moderation records support review and recovery. Site operators manage database backups and retention under their deployment policies.