A registration begins with a choice.
The visitor submits an email and consent. Before keeping anything in the signup table, the handler checks the method, origin, content type, request size, email syntax, consent and honeypot.
Validated attempts then pass through the hourly rate counter. A permitted request inserts an email registration, protected by a unique constraint. A duplicate leaves the existing record and removal credential intact.
First persist.
Then confirm.
Only a successful database operation leads to a success response. A new signup receives its raw removal token once; the database keeps only its hash.
The small record that remains.
The table is named early_access. The following are schema definitions, not sample subscriber records.
- id
- A text primary key produced by
crypto.randomUUID(). - Required unique text, with
COLLATE NOCASE. The handler trims and lowercases input. - consent_version
- The consent record. The current handler stores
early-access-v1. - created_at
- A required UTC timestamp created by SQLite at insertion.
- removal_hash
- The required unique SHA-256 hash of the private removal token. The raw credential is not stored.
The schema contains no purchases, reward balances, identity documents or financial-account records.
Some records are only passing through.
signup_rate_limits stores a key, an attempts count and an expires_at value. The key hashes the current hourly bucket and Cloudflare’s network-address header. Local requests without that header use local-development.
An atomic upsert increments the counter. Later signup requests attach background work to delete expired counters. There is no scheduled cleanup task.
This hash is an abuse-control identifier, not a claim of anonymization. Neither application table stores raw IP addresses.
The choice to leave.
The private removal link carries its credential in a fragment: /manage/#…. That fragment is not sent in the initial page request. The browser submits it in a POST body only when the visitor chooses to remove the signup.
The handler hashes the token and deletes its matching row. Repeating removal remains safe. The record otherwise stays until the visitor removes it or the list is retired; no automatic retirement schedule is implemented.
The Privacy notice explains this flow to visitors.