Fairly Sorted

Security and trust

Private by design, with honest limits.

Fairly Sorted limits access around each shared list, keeps uploaded media behind private storage boundaries and treats generated suggestions as drafts requiring human review.

Account and list access

Signed-in API requests use an HttpOnly session cookie. Shared-list records are projected through server-side membership checks, and sensitive mutations require authentication and same-origin requests.

  • Invite codes are six characters and expire after fourteen days
  • Only the organiser can change or permanently delete an organised list
  • People must be members of a list before reading its cards or results

Photos and walkthroughs

Uploads use private object storage and signed, time-limited operations. Images are sanitised before product use, and raw or failed inputs follow short deletion windows.

AI-generated detections are suggestions. The organiser reviews them before shared cards are created.

Data minimisation

Analytics is opt-in and constrained by an event allowlist. Session replay and autocapture are disabled. Operational records are designed to avoid item text and media contents.

No absolute guarantee

No online system can promise perfect security or uninterrupted availability. Fairly Sorted is still an early service and should not be used as the only record of legally or financially critical decisions. Keep an appropriate independent copy of final results.

Report a security concern

Do not include exploit details in general product feedback. Use the contact form, identify the message as a security report, and include a safe way to reply. Do not access another person’s data while investigating a concern.

Report a security concern