Policies & Security
How extort.bio keeps the platform safe and what we expect from users.
Acceptable Use
extort.bio is a platform for creators to share their online presence. By using extort.bio, you agree to use it in a way that is lawful, respectful, and not harmful to others.
- You must be at least 13 years old to use extort.bio.
- You are responsible for all content on your profile.
- You may not impersonate other people or organisations.
- You may not use extort.bio to distribute spam or unsolicited messages.
Prohibited Content
The following content is not permitted on extort.bio profiles:
- Illegal content of any kind
- Content that promotes violence, hate, or discrimination
- Malware, phishing links, or deceptive URLs
- Content that violates another person's intellectual property rights
- Non-consensual intimate imagery
Violations may result in immediate account suspension or permanent ban without notice.
Security
How we protect your account
- All connections are encrypted via HTTPS/TLS.
- Passwords are hashed using bcrypt — we never store plaintext passwords.
- Sessions use secure, HTTP-only cookies managed by Supabase Auth.
- TOTP-based 2FA is available for all accounts.
- Security headers (HSTS, X-Frame-Options, CSP) are applied on every response.
Reporting a vulnerability
If you discover a security vulnerability, please report it privately via our Discord server. Do not publicly disclose vulnerabilities before we've had a chance to address them.
Your Data
- We store only what's necessary to run your profile — your handle, display name, links, theme, and uploaded assets.
- Analytics data (views, clicks) is anonymised using a random viewer key stored in your browser.
- We do not sell your data to third parties.
- You can delete your account and all associated data at any time from Settings → Danger Zone.
Enforcement
extort.bio staff may suspend or ban accounts that violate these policies. Suspended accounts will see an "account restricted" message on login. If you believe your account was restricted in error, contact us via Discord.