Last updated 5 September 2026
Tweezers is run by an individual in Indonesia. This page describes what the service collects and who else touches it. Questions go to [email protected].
What you give us
- Your email address
- For an account, it is how you sign in. For a guest post, it is required to take a card and is the only evidence available if that charge is disputed. It is never shown to other readers.
- What you write
- Posts, replies, the name and description on a product link, and anything you put on a profile: display name, bio, location, picture. All of it is public by design, and a paid post is meant to be read.
- Pictures you upload
- Re-encoded on arrival, which strips the metadata a camera writes, including GPS coordinates. The original file is never stored.
What we record as you use it
- Your IP address, against sign-in attempts, uploads and sessions. It is used for rate limiting and for abuse response, and for nothing else.
- Your browser's user agent, stored with a session so you can tell one sign-in from another.
- What you paid: amount, currency, status, and the reference the payment provider gave us.
- Likes, follows, notifications and reports, which are the mechanics of the site working.
What we deliberately do not have
- Card numbers. No card detail ever reaches our servers. The provider gives us a brand and the last four digits so a confirmation screen can name the card, and that is all we hold.
- Sign-in codes. Only a scrypt hash is stored, so the code in your email cannot be read back out of our database.
- Session tokens. Only a SHA-256 hash. The token itself exists in your cookie and nowhere else.
- Passwords. There are none.
Cookies
- tweezers_session, set when you sign in. HTTP-only, same-site, and expires after 30 days.
- tweezers_theme, set when you choose light or dark, so the page arrives in the right palette instead of flickering into it.
- Microsoft Clarity sets its own cookies where it is enabled. See below.
None of these follow you to other sites.
Who else sees it
- Dodo Payments
- Merchant of record for card payments. They take the card and see your email and the amount. Their terms and privacy policy govern that part.
- Midtrans
- Processes QRIS payments for Indonesian payers, on the same basis.
- Neon
- Hosts the database and the uploaded pictures.
- Cloudflare
- Sits in front of the site, so it handles every request, and provides the anti-bot check on the sign-in form.
- Microsoft Clarity
- Analytics, and it records sessions. Text you type is masked by default, and the compose sheet and the email shown on your own profile are masked explicitly on top of that, so what you are writing and what your address is do not end up in a recording.
- An email provider
- Sends the sign-in code. It sees your address and that message.
Nothing is sold, and nothing is shared for advertising.
How long it is kept
- Sign-in codes expire in minutes and are single use.
- Sessions expire after 30 days, or immediately when you sign out.
- An uploaded picture nothing points at is deleted from storage a few hours later.
- Posts, payments and profiles are kept while the account exists. Payment records are kept afterwards for as long as a charge can still be disputed, because they are the only defence against a chargeback.
Deleting things
You can delete any post you wrote, at any time, from the menu on it. Deleting does not refund what it cost.
There is no self-service account deletion yet. Write to [email protected] from the address on the account and it will be done by hand: the account, its posts, its pictures and its profile. What survives is the record of payments, which we are required to be able to produce, and it is reduced to the amount, the date and the provider's reference.
Children
The service takes payments and is not intended for anyone under 17. If you believe a child has an account here, write to us and it will be removed.
Changes
If this page changes in a way that matters, the date at the top changes with it.