As programmers, we know how much programmers care about privacy. We endeavor to only store the minimum data required to operate our services on behalf of the Handmade community, and we never share or sell user data.
This privacy policy covers this website (https://handmade.network/) and its subdomains, as well as our Discord server (https://discord.gg/hmn).
If you have any privacy-related questions, concerns, or requests, please contact us at [email protected].
General data practices
We are located in the United States and our data is hosted on US servers. Our database storage is encrypted at rest. User-created assets and media are stored in a cloud object storage service. Access to production data is restricted to site administrators.
We always endeavor to maintain strong security practices, and to follow industry-standard guidance by organizations such as OWASP.
Explicitly-collected user data
We store the following data provided directly by users as part of our normal operation:
- Authentication information, including usernames, email addresses, passwords, and OAuth access tokens. Stored passwords are hashed and salted according to OWASP guidelines.
- Profile information, including public-visible data such as display names, bios, and avatars, as well as behind-the-scenes info such as email addresses and linked third-party accounts.
- User-created content, such as projects (and associated media), timeline posts, blog posts and forum posts.
- Event-specific information for ticket purchasers, such as name, email address, dietary restrictions, requests for accommodation, and Stripe transaction IDs.
- Newsletter email addresses for newsletter subscribers.
- Other explicitly-provided user information in cases such as surveys or if users contact us for support.
We never process or store direct payment information such as credit card numbers or bank account numbers. Payments are always performed externally through our payment processor, Stripe. We use Stripe's API to get information about transactions, but Stripe never permits us to see users' payment information.
Automatically-collected user data
Some data is automatically collected as part of the normal process of operating the website:
- Basic request information, including IP address and request headers. This data is logged on our server.
- Information used for account creation, including usernames, email addresses, and IP addresses, in order to help fight spam.
We do not use client-side analytics or tracking, including in our emails. We only use cookies for strictly necessary purposes, such as authentication.
Discord bot data
We have a custom Discord bot as part the website codebase that provides various helpful services for the Handmade Network Discord server. The bot is special-purpose and is only used on the Handmade Network Discord. Most user interaction with the Handmade Network Discord is governed by Discord's own privacy policy, but as part of the bot's operation, we process and store some additional kinds of data from Discord:
- Message metadata, such as message ID, channel ID, and author ID. This data is stored for all messages in select channels so that we can quickly fetch messages when a user enables cross-posting.
-
Message contents, including text and attachments, may be processed and stored for various purposes:
- Message contents may be read (but not stored) in order to provide automatic moderation, such as the automatic deletion of messages.
- Message contents may be stored in order to enable Discord messages to be cross-posted to the website. Message contents will only be stored when the message author has linked their Discord account to their website account.
- Profile information, such as user ID, username, and avatar. This is used to provide account information for new signups and to correlate messages to authors.
When a user unlinks their Discord account, all profile information (except the Discord user ID) and all stored message text from that Discord user are immediately deleted. Existing cross-posts are preserved.
Twitch bot data
We have a feature on our Discord server that posts in a channel when community members stream on Twitch. To enable this feature, we subscribe to webhook events from Twitch and store the following data:
- Basic channel info, including ID and channel name.
- Stream and VOD info, including ID, title, category, tags, and start and end times.
- Webhook events, which we store in full for a limited time for debugging purposes.
Third parties
We use a variety of third-party services as part of our normal operation. In some cases these third parties may require user information, but we endeavor to keep this at a minimum.
Third-party services that may encounter user data include:
- DigitalOcean, our web hosting service, where user content and assets are routinely stored as part of normal operation.
- Postmark, for transactional emails and newsletters, where user email addresses are required.
- Cloudflare, for networking and site protection.
- Stripe, for payment processing.
User data controls
Users can edit their own user-generated content, such as forum posts, timeline posts, and user profile contents, at any time. Most user-generated content can be deleted by users at any time; some, like projects, can only be deleted by a website administrator upon request.
Users with a linked Discord account can disable the cross-posting feature at any time, which will stop creating posts automatically but will not stop saving message contents. Users can unlink their account at any time, in which case all message contents will be deleted but previously created cross-posts will remain.
Users may request that their account be deleted by contacting us at the email address provided above. When an account is deleted, user-specific data and associated Discord data will be deleted, but user-generated content may be retained in anonymized form.
Users may at any time request a copy of all data associated with their user or identity. Data will be provided in a straightforward and machine-readable format.
Data retention
Generally speaking, we retain user data for as long as that user has an active account. We delete user information immediately upon account deletion, but some user data may be retained for up to 90 days in server logs and database backups.
Additionally, we may retain some user information indefinitely as part of responsible operation:
- As mentioned above, user-generated content may be retained in anonymized form upon account deletion.
- Banned accounts may be retained for analysis, but are still subject to data deletion requests.
- Bounced email addresses are always retained in order to protect our sender reputation.
Webhook events from Twitch are retained in full for four days to facilitate debugging.
Changes to this policy
Changes to our privacy policy will be announced in a notice on this website and on our Discord server.
Last updated on September 6, 2026. For any questions or requests, please contact us at [email protected].