Millesime Labs

Draft, 7 October 2026. Review this page before production. It is a starting point for this install, not a finished legal document.

Privacy policy

This draft describes the data the Millesime Labs application stores and sends. It covers accounts, profile preferences, sign-in, the admin list, and the contact form. Review it, and replace it, before you use this install in production.

Who this applies to

The person who runs this install operates it. The application does not add a separate hosted account service. If you sign in, you are creating or opening an account on that install.

Account and profile

An account is created the first time an email address signs in. The account stores that email address, a role (admin or member), and the time it was created. If Google provides a name, that name can be stored with the account.

The profile stores a display name and a theme: light, dark, or system. Those preferences are saved in a SQLite file on the machine running the app (data/millesime.sqlite). That file is not part of the git repository.

Sign-in

Email sign-in sends a one-time link through Resend to the address you enter. The link expires in one hour. The same address can request a new link once a minute. Google sign-in uses Google's OAuth flow. A verified Google address is linked to an existing account with the same email.

A session cookie identifies the signed-in account. The cookie is HttpOnly and SameSite=Lax. The session uses a signed token. You can sign out from the account page, which ends that session in the browser.

When someone creates an account and Resend is configured, the app emails ADMIN_EMAIL with the new address and whether that account is the admin.

Admin

The address in ADMIN_EMAIL becomes the admin when that person signs up. The admin page lists each account's email, role, and creation time. Other accounts cannot open that list.

Contact form

The contact form asks for a name, an email address, and a message. When Resend is configured, that message is emailed to CONTACT_EMAIL, or to ADMIN_EMAIL when no contact address is set. The form does not write the message into the account database. If Resend or a recipient is not configured, the page says so and does not send the message.

Other parties

Google receives the sign-in request when you use Google. Resend receives email when this install sends a sign-in link, a signup notice, or a contact message. This application does not include advertising or a separate analytics product.

What this draft does not decide

It does not set a retention period, a region, or a request process beyond signing out and contacting the operator. Those choices belong to the person running the install. Use the contact page for a question about this install. Replace this draft before production.