EJEngine Journal
PRIVACY POLICY

How Engine Journal handles information.

This policy describes account information, necessary security records, browser-local data, and the choices available to visitors.

Information you provide

If you create an optional account, we store the email address you enter and a normalized copy used to prevent duplicate registration. We do not verify that the email belongs to you and do not offer email verification or password recovery. Browser-only comments store their text, generic guest label, time, and helpful-vote activity only in that browser. Do not submit sensitive personal or financial information.

Passwords and sessions

Passwords are stored only as versioned Node.js scrypt hashes with a random salt, never as plaintext. Sign-in uses a random Session token in an HttpOnly cookie; the database stores only a one-way hash of that token. Changing a password increments the account authentication version, revokes prior Sessions, and issues a new Session for the current browser.

Security and technical information

Six-digit image-code answers, Session tokens, and raw rate-limit email or IP values are not stored directly. The service stores keyed or one-way hashes needed to bind image codes, rate-limit abuse, and validate Sessions. Hosting infrastructure may also process IP address, browser type, requested page, timestamps, and redacted error records to deliver and protect the service.

Browser storage

Local storage supports comment drafts and submissions, helpful votes, a browser guest identifier, and DMV study progress. Necessary cookies support the first-visit notice, image-code browser binding, and signed-in Sessions. See the Cookie Policy for names and durations.

How information is used

  • Create an optional low-trust account and maintain signed-in Sessions.
  • Prevent automated registration and sign-in attempts, enforce rate limits, and diagnose errors.
  • Provide comments and DMV study progress in the visitor's browser.
  • Respond to privacy, correction, or support requests.

Sharing and selling

Engine Journal does not sell browser-local information. Technical data may be processed by service providers that host, secure, or operate the site, subject to their contractual and legal obligations. Information may also be disclosed when required by law or necessary to protect visitors and the service.

Retention and security

Sessions expire after 30 days unless revoked earlier. Image codes expire after five minutes, failed-attempt records are retained only for short security windows, and expired security rows are periodically removed. Account records remain while the account feature operates or as needed for security and legal obligations. Browser-local information remains until you delete it or clear site data. No online system can promise absolute security.

Your choices

You can sign out, change your password, delete browser-saved comments where a removal control is available, or clear this site's cookies and local storage. Depending on your location, applicable law may also provide access, correction, deletion, restriction, or objection rights.

Children and updates

The service is intended for a general audience and is not directed to children under 13. We may revise this policy as features or service providers change; the latest publication date appears above.