Privacy policy
Last updated 27 August 2026
Sahul is a free, non-commercial community project run by John Cook in Australia. It is not a company, it does not sell anything, and it has no advertising. This page describes exactly what it stores about you, where, and for how long — written from the database schema rather than from a template, so it should match the software rather than describe a generic website.
The short version
- • You can browse the entire catalogue and knowledge base without an account, and we store nothing about you if you do.
- • If you make an account, we store your email address and which sign-in methods you use. That is essentially it.
- • Your collection, army lists, logged games and photos are stored in your browser, not on our server.
- • We never store your IP address. It is hashed with a secret salt and truncated before it touches the database.
- • There are no passwords to leak, because there is no password field anywhere in the app.
- • Nothing is sold, rented, or shared with advertisers. There are no third-party cookies and no advertising.
- • We do count page views, with a cookieless tool that cannot identify you or follow you to other sites. What it collects, and why, is spelled out below.
What we store if you create an account
All of this lives in a single Cloudflare D1 database. Nothing here is shared with anyone.
- • Your email address, lowercased, and whether it has been verified. This is the account's identity and how you recover it.
- • A display name and avatar, if Discord or Google supplied them when you signed in.
- • Which sign-in methods you have linked — for each one, the provider's own account id and a label such as your Discord handle. We never receive or store your password for those services.
- • Your sessions: a one-way hash of each session token, a shortened browser/OS string, a hashed IP, and when the session was created and last used. The hash means a copy of our database is a record of sessions that existed, not a set of working keys.
- • Passkeys, if you add one: a public key and a credential id. A passkey's private half never leaves your device and we could not obtain it.
- • Recovery codes, if you generate them — stored only as one-way hashes, which is why we cannot tell you what they were.
- • Pending sign-in links: your address and a hash of the link's token, deleted or expired within 15 minutes.
What stays in your browser and never reaches us
The parts of Sahul most people use most are stored entirely on your own device, in your browser's local storage. They are not uploaded, not backed up by us, and not visible to us:
- • Your collection — what you own, what is built, what is painted
- • Your army lists and force-builder work
- • Logged games and events
- • Photos you add, held as small downscaled copies
- • Bookmarks, view preferences and your light/dark choice
The consequence is worth stating plainly, because it cuts both ways: clearing your browser data deletes all of it, and we cannot get it back for you. Nor does it follow you to another device. Syncing this to your account is planned; when it happens, this page will be updated before it ships.
If you report a bug
The report form stores what you wrote, the page you filed it from, the item it was about, your browser's user-agent string, and a hashed IP used only to rate-limit abuse. The contact field is optional and free text — whatever you choose to put there is stored as you typed it, so give an address only if you want a reply.
What we deliberately do not collect
- • Your IP address. It is combined with a secret salt, hashed with SHA-256 and truncated before storage. It exists to count abuse and cannot be turned back into an address.
- • Passwords. There is no password field in Sahul. Sign-in is by emailed link, Discord, Google or a passkey.
- • Payment details. Nothing is for sale.
- • Tracking pixels, advertising identifiers or third-party cookies. There are none. The only cookies Sahul sets are your session and a short-lived one during sign-in.
- • Any analytics that can identify you. See the section below for exactly what the page counter does and does not see.
- • Your location, contacts, or anything from your device beyond what a web page ordinarily receives.
Measurement — what we count, and what we deliberately do not
Sahul uses Cloudflare Web Analytics, which is a page counter rather than a tracker. It sets no cookies, builds no profile, does not fingerprint your browser, and cannot follow you to any other website. There is no way for us to look up what any individual did.
What it records, per page view:
- • the page visited, and the site that linked you here
- • your country, browser and operating system — no more precise than that
- • how quickly the page loaded
Why: to know whether anything is broken, whether pages are slow, and whether anyone is actually using a thing before more time goes into it. That is the whole purpose. It is not used for advertising, it is not sold, and it is not shared.
We would rather count less than more. If something here can be dropped without losing the ability to tell whether the site works, it should be — say so atprivacy@sahul.net and it will be.
Who else is involved
- • Cloudflare hosts the site and the database, provides the anti-spam check on the sign-in form, and counts page views as described above. Data is stored in their Oceania region. They process it on our behalf and do not use it for their own purposes.
- • Discord and Google are involved only if you choose to sign in with them. We receive your account id, email address, display name and avatar. We do not post anything, read your messages, or see your servers or contacts.
- • Cloudflare Email delivers sign-in links.
- • Corvus Belli is not involved. Sahul is an independent community project and shares nothing with them.
How long we keep things
- • Sign-in links — 15 minutes, then unusable. Deleted immediately if delivery fails.
- • Sessions — up to 90 days from last use, and removed the moment you sign out. Expired ones are deleted when next encountered.
- • Your account — until you delete it.
- • Bug reports — kept, because they are a record of what was wrong. Say so and we will remove yours.
Your rights
You can ask for a copy of everything held about you, ask for it to be corrected, or ask for it to be deleted, and you do not need a reason. Write to privacy@sahul.net and we will act within 30 days. Deleting your account removes your user record, your linked sign-in methods, your passkeys, your recovery codes and your sessions.
Sahul is run from Australia and follows the Australian Privacy Principles under the Privacy Act 1988(Cth). If you are in the UK or the European Economic Area, the UK GDPR and GDPR give you these same rights and a few more — the right to object, to restrict processing, and to complain to your local supervisory authority. We treat everyone as having them regardless of where they are, because maintaining two standards would mean getting one of them wrong.
Our lawful basis, where one is needed: we process your email address to perform the contract of giving you an account you asked for, and we process hashed IPs under legitimate interests — keeping a free sign-in form from being abused.
Children
Sahul is not aimed at children and accounts are not intended for under-16s. If you believe a child has created an account, tell us and we will delete it.
If something goes wrong
If a breach happens that could put you at risk, we will tell affected people directly and say what happened, what was involved, and what to do — within 72 hours of finding out. This is a small project run by one person; that is a reason to be more direct about failures, not less.
Changes
If this policy changes in a way that affects what we collect or who sees it, the change is made before the collection starts, not after, and the date at the top moves.
Questions: privacy@sahul.net. See also theterms of use.