Storage
- The app runs on Vercel. Published files and metadata live in a private Vercel Blob store and are served through our app.
- Files are stored content-addressed (by SHA-256), so identical files are stored once and a version can never be partially written.
- Sites are permanent unless you set an expiry or delete them. We do not delete inactive sites.
Tokens
- Tokens are random 192-bit values. We store only a SHA-256 hash; we cannot show you a token again.
- A token is the only proof of ownership. Treat it like a password. There is no email recovery because we never collect an email.
What we don't collect
- No email address, name, or phone number to publish.
- No analytics scripts on deed.page and none injected into your sites.
- No cookies. The theme switch uses local storage in your browser.
Uploads
- Archives are unpacked in pure Node. Symlinks, hard links, absolute paths, and
.. are rejected; decompressed size is capped. - Everything published is public. Do not publish secrets.
Payments
Stripe handles card data. We store only the Stripe customer and subscription IDs attached to your token.
Honest limits
- No SOC 2 report and no contractual SLA.
- Rate limits are best-effort per server instance.
- Published sites share the deed.page domain family; sites on the path fallback (
/s/slug/) share an origin with each other.
Abuse and security reports
Email ops@avatar33.com. We remove malware, phishing, and illegal content. Health: /api/v1/health.
deed.page is operated by Avatar 8 LLC.