Skip to content

Annex BSecurity

Fewer pipes. Fewer leaks.

Security here is mostly subtraction: no accounts to phish, no third-party scripts to supply-chain, no pixels watching the library. California, USA is the forum if a dispute follows.

  1. No third-party JavaScript

    This app does not load analytics, tag managers, chat widgets, or ad networks. Fewer scripts means a smaller attack surface and nothing quietly phoning home.

  2. No tracking pixels

    The previous DAAM library requested Amazon impression beacons (ir-na.amazon-adsystem.com) as you scrolled books. Those requests are gone. Retailer pages load only after an explicit click.

  3. Local media

    Book covers are drawn here. Film stills and plates are files on this origin. We do not embed YouTube, pull Amazon cover art, or load podcast CDNs. A click is the only time you leave.

  4. HTTPS exits only

    The original site mixed http:// exits with https:// pages. Mixed content is a gift to anyone on the path. Outbound links here are HTTPS, with rel="noopener noreferrer" and a strict-origin-when-cross-origin referrer.

  5. No accounts, no session cookies

    There is no password to steal, no reset email to phish, and no session token in a cookie. Practice lives in localStorage on this origin. That is a theft-of-device risk, not a theft-of-database risk — wipe it from Privacy if you share a machine.

  6. Honest documents

    The 2021 privacy policy denied third-party links while the page loaded them. This annex and the privacy center are written to match the code. If we add a third party, we will name it.

  7. What we still cannot control

    Your browser, extensions, OS, and network operator can still observe traffic. Amazon, YouTube, and other sites apply their own policies the moment you leave. We cannot encrypt a note you typed into a laptop someone else can unlock. We do not warrant that the Service is invulnerable, uninterrupted, or free of defects. Use is at your own risk, as stated in the Terms.

  8. Your device, your risk

    You are responsible for physical access, browser profiles, backups, and malware on machines you use. A Protected Party is not liable for data lost or read from your localStorage, clipboard, or mail client. If you share a computer, wipe the log before you stand up.

  9. Good-faith reports only

    If you find a real vulnerability, email contact@daam.io with enough detail to reproduce it, and give us a reasonable time to fix it before any public write-up. Do not access other people’s data, degrade the Service, or demand payment. There is no bug bounty unless we publish one. Extortion, ransom, or “pay or we disclose” is a crime; we may refer it to law enforcement in California. We may ignore theatrical, repetitive, or bad-faith “reports.”

  10. Legal process

    We have no user database, session log, or practice archive to subpoena. We will not invent records we do not keep. Process intended to harass the operator — overbroad demands, shotgun subpoenas, or threats of suit in a foreign forum — will be treated as vexatious. Disputes about security or this annex follow the Terms: California law, exclusive venue in the state or federal courts in California, USA.

  11. Report a problem

    Email contact@daam.io. We have no duty to reply. Related reading: Privacy and Terms.