Security
Specifics rather than adjectives. Everything below describes what FotoInPDF actually does.
Accounts and passwords
- Password storage
- PBKDF2-SHA256 with 600,000 iterations of work, salted per user. Your password is never stored or logged in any recoverable form.
- Sessions
- Held server-side, with an HttpOnly, Secure, SameSite cookie. Signing out destroys the session on the server, not just in your browser.
- Password reset
- Links are single-use, expire after an hour, and are stored hashed. Resetting signs out every other session — if someone else had your password, they are gone.
- Rate limiting
- Sign-in and sign-up are throttled per address, checked before any password is processed.
Your data
- Export
- Download everything held about your account in a portable format, at any time, from your settings.
- Deletion
- Deleting your account cancels any subscription first, then removes your records. It is not a flag on a row.
- Payment details
- Card details are handled by Stripe and never reach our servers.