The early-access record.
The early_access table contains the following fields. These are schema definitions, not sample subscriber data.
| Column | Purpose |
|---|---|
id | Text primary key generated with crypto.randomUUID(). |
email | Required, unique text with COLLATE NOCASE. Application input is trimmed and lowercased. |
consent_version | Required consent record. The current handler writes early-access-v1. |
created_at | Required UTC timestamp generated by SQLite when the row is inserted. |
removal_hash | Required, unique SHA-256 hash of a randomly generated removal token. The raw token is not stored. |
No purchase records, reward balances, identity documents or financial-account information are collected by this schema.
Temporary request counters.
The signup_rate_limits table stores key, attempts and expires_at. The key is a SHA-256 hash of the current hourly bucket and the network address supplied by Cloudflare. The application uses local-development when that header is absent.
An atomic upsert increments the attempt count. Expired records are deleted in background work attached to subsequent signup requests. There is no scheduled cleanup task.
The hash is an abuse-control identifier, not a claim of anonymization. Raw IP addresses are not stored in either application table.
From a signup to a choice.
- Validate. Check the method, origin, content type, body size, email, consent and honeypot.
- Count. Increment the network’s hourly signup-attempt counter. Stop if the limit is exceeded.
- Persist. Insert the signup with a unique email constraint. A duplicate leaves the existing row and credential unchanged.
- Confirm. Return success only after the database operation succeeds. For a new signup, show the raw removal token once.
- Remove. Hash a submitted removal token and delete the matching row. Repeating the same request remains safe.
The private removal link uses a URL fragment: /manage/#…. Fragments are not sent in the initial HTTP page request. The page submits the token in a POST body only when the visitor chooses removal.
Retention & access.
Signup records remain until removed through their private token or until the early-access list is retired. The implementation does not include an automatic retirement schedule. Removal deletes the active application row; Cloudflare’s infrastructure and recovery mechanisms have their own lifecycle.
Only an authorized operator should inspect or export the database through Cloudflare. The application has no public subscriber-list endpoint. No automatic confirmation or marketing email is sent by this code.
Read the visitor-facing Privacy notice for the website’s current data disclosures.