Last updated 5 October 2026.
YAVCHN is a reader for Hacker News and Lobsters at yavchn.com. Paul Parks runs it as an individual in Singapore, and he decides what it does with your data. You can reach him about anything on this page at paul@parkscomputing.com.
YAVCHN keeps as little about you as it can. It has no advertising and no analytics, it doesn't track you across other sites, and it doesn't sell your data, and it doesn't share your data with anyone except the services listed below, which it needs in order to work.
If you don't sign in
Without an account, the server keeps nothing that identifies you. Your pins, collections, notes, hidden stories, blocked sites, reading positions and layout are stored in your own browser, and they stay there until you clear the site's data.
The server still sees each request your browser makes, as every web server does. It doesn't keep an access log. To stop any one visitor from overloading the site or the sources it reads, it counts requests by IP address in memory, and it forgets each count after a few minutes.
When you open an article, the server fetches it from the publisher and keeps a copy for 30 days so that the next reader gets it quickly. That copy isn't linked to you or to anyone else.
The server records errors in a log that is limited in size, so old entries are discarded as new ones arrive. An entry can include the address of an article that failed to load, words searched for on Hacker News, an address entered in Find, or a Hacker News or Lobsters user name being looked up. It never includes IP addresses, email addresses or account details.
If you have an account
An account lets you keep the same pins, collections, notes and settings on every device. For each account the server keeps the following.
- A random account number and the date the account was created.
- Each way you sign in. For GitHub, that is your GitHub user number, user name and the address of your GitHub picture. For an email link, it is your email address.
- Your passkeys. The server keeps each passkey's public key, the name you give it, and when it was added and last used. A passkey's private key never leaves your device.
- Your profile picture, if you have one, either a copy of your GitHub picture or a picture you uploaded.
- Your pins, collections, notes and blocked sites, and the reading state YAVCHN restores: where you were in each article and discussion, and the Hacker News user name you entered in Replies to me, if you used it.
- A record of each browser you are signed in to: a scrambled form of its sign-in code, and when the session started and when it ends.
Only you can see any of this. YAVCHN has no public profiles, and your picture is served only to you.
Hidden stories, stories you have opened, collapsed comments and layout stay in each browser, even when you are signed in.
Signing in
Signing in with GitHub asks GitHub only for your public identity: your user number, user name and picture. YAVCHN doesn't ask for access to anything else in your GitHub account, and it doesn't keep the access code GitHub returns.
Signing in with an email link sends your address to Resend, the service that delivers YAVCHN's email. The link works once and expires after 15 minutes, and the server keeps your address with it until then. To stop the sign-in form from being used to flood someone's inbox, the server counts how many links each address and each IP address has asked for in the current hour. It stores those counts against a scrambled form of the address, and deletes them within an hour of the hour ending.
The short-lived records of a sign-in in progress, for GitHub, email and passkeys, are deleted once used, or within an hour of expiring if they are never used.
Cookies and browser storage
YAVCHN sets only the cookies it needs in order to work, and none of them track you.
__Host-yavchn-sessionkeeps you signed in, for up to 30 days.__Host-yavchn-flowand__Host-yavchn-ceremonyhold a GitHub or passkey sign-in while it is in progress, for at most 10 minutes.yavchn-viewandyavchn-reader-placementremember whether you prefer Windowed or Classic view and how new article windows open, for a year.
Everything else YAVCHN remembers is kept in your browser's local storage, which only this site can read.
Services YAVCHN uses
- Cloudflare carries all traffic between your browser and the server, so it handles every request, including your IP address.
- GitHub confirms who you are when you sign in with GitHub. The server, not your browser, fetches your GitHub picture.
- Resend, in the United States, delivers sign-in emails. It receives your email address and the message.
- Hacker News and Lobsters supply the stories, discussions and profiles. The server asks them for what you look at, search for or look up, and never sends them anything that identifies you.
- Publishers supply the articles. The server fetches the text without sending anything about you, but pictures inside an article load straight from the publisher's site, so the publisher sees your IP address and that you came from YAVCHN.
Some of these services keep data outside Singapore. YAVCHN uses them under their standard data protection terms, which require them to protect your data to a standard comparable to Singapore's.
How long data is kept
Account data is kept until you delete the account. A session ends 30 days after you sign in, or sooner if you sign out, and the server deletes its record within an hour of it ending. Article copies are kept for 30 days.
Before an upgrade, the server's database may be backed up. A backup is kept for at most 30 days, so an account you delete can remain in a backup until it is removed.
Your choices
- See and download your data. Export your account data, on the Account page, downloads everything the server keeps about your account, except the passkeys' keys and the sign-in codes of your sessions, which are of no use to you.
- Correct it. You can change your pins, collections, notes, picture, passkeys and ways of signing in yourself, on the Account page and in the reader.
- Delete it. Delete the account, on the Account page, removes the account and everything kept with it at once, and signs out every browser. The copies in your own browser stay until you clear the site's data.
For anything else, or to ask what YAVCHN holds about you, write to paul@parkscomputing.com. You'll get an answer within 30 days. If you think YAVCHN has mishandled your data, you can complain to Singapore's Personal Data Protection Commission, or to the data protection authority where you live.
Security
All traffic is encrypted. Sign-in codes are stored only in scrambled form, so a copy of the database can't be used to sign in as you. If a breach puts your data at risk, YAVCHN will tell you and the Personal Data Protection Commission as the law requires.
Children
YAVCHN isn't meant for children. Please don't create an account if you are under 13.
Changes
If this policy changes, the date at the top changes with it. A change that affects how your account data is used will be announced on the site before it takes effect.
The terms of use cover the rest of your use of YAVCHN.