Who this is
The Mo Pai Archive is a reference work about a claimed Taoist internal-energy tradition, with a small community section attached to it. It is run privately and it is not a company, a school, or a teaching organisation. Anything to do with this notice — a question, a correction, a request to remove an account or something posted under it — goes to the address at the foot of this page.
Reading the archive
Reading sets no cookie, requires no account, and is not measured. There is no analytics package, no tag manager, no pixel, no heatmap, no session recorder, and no advertising code. The application writes no request log, so there is no file anywhere on the server recording which pages you read or in what order.
The one thing counted is the number of people reading at this moment, which is the figure in the footer. It works like this: your network address and browser identification are hashed together with a random value generated when the server process starts, and the resulting key is held in memory alongside a single timestamp. The key is meaningless outside that running process — it cannot be matched against anything, including yourself after a restart — nothing is written to disk, no address is stored, and entries older than fifteen minutes are deleted. The result is a count and nothing else.
What no site can honestly promise away is the ordinary mechanics of the internet: your address is necessarily visible to the machine serving the page, and to whatever network sits in front of it, for as long as the connection lasts. Certificates for this site come from Let's Encrypt, which is a certificate issuer and sees nothing about visitors.
If you join the community
An account exists so you can post, upload images, and send private messages. Registration asks for a username and a password. There is no email field and no profile questionnaire.
What is stored against an account:
- Your username, and a lowercased copy of it so that two people cannot register names that differ only in capitals.
- Your password, as a hash. The plain text is never written down and cannot be recovered from what is stored: it is combined with a server-side secret held outside the database, then hashed with scrypt against sixteen random bytes generated for your account alone.
- Anything you choose to add to your profile — an avatar image, a bio, a signature. All three are optional and all three are public.
- What you post: threads, replies, and the times they were created and edited.
- Private messages you send or receive, with their timestamps and whether they have been read.
- Account bookkeeping: when you registered, when you were last seen, how many posts you have made, your role, and — if it applies — a mute or a ban with the reason a moderator recorded for it.
- Your sessions: a random session identifier, the security token that goes with it, when it was created and when it expires, and the first 200 characters of the identification string your browser sends. That last field exists so a session in a list is recognisable as "the one on my phone".
Because no email address is collected, there is no way to reset a password by email, no way to notify you of anything, and no way to reach you off this site. That is the trade: less of your data held here, less the site can do for you if you lose access to an account.
Addresses, and where they are used
Sign-in attempts and registrations are rate limited, and the counter is keyed to the address the request came from. Those counters are rows with an expiry — fifteen minutes for sign-in attempts, an hour for registrations — and they are purged once they lapse. They are not linked to your account, your posts or your sessions, and they exist to make scripted attacks expensive rather than to record who was here.
Images you upload
An uploaded image is written to disk under a random sixteen-byte filename in a folder for the month, and recorded in the database with the uploader, the type, the size in bytes, the pixel dimensions, whether it was a post image or an avatar, its review status, and the time. It is served only through a route that looks the filename up first, so nothing on that disk is reachable unless it was recorded as an upload. Uploads from accounts below a small post-count threshold wait in a review queue, visible to their poster and to moderators, until a moderator approves them.
What is public, and what is not
Your username, your profile, your threads and your posts are public: visible to anyone who visits, and to search engines, which are invited to index the board index and each board. Assume that anything you post can be read, quoted and archived elsewhere by people this site has no control over, and choose a username accordingly — a username that is also your name elsewhere ties the two together permanently.
Private messages are not shown publicly and there is no moderator inbox: in the interface only the two people in the conversation can read them. They are, however, stored as plain text in the site's database like everything else, so anyone with access to the server or to a backup of it could read them. Treat them as private from other members, not as confidential.
How long things are kept
- Sessions expire thirty days after they are created, and expired rows are swept away. Signing out deletes the session immediately.
- Rate-limit rows are deleted once their window lapses.
- A removed post leaves a marker in its place: the body stays in the database and remains readable by moderators, which is what makes a moderation decision reviewable. Removal from the page is not erasure from the store.
- When a moderator removes an image, the file itself is deleted from disk and the database row stays behind with its status set to removed.
- The reader count holds nothing for longer than fifteen minutes, and holds nothing at all across a restart.
- Accounts and their contents persist until they are removed on request.
Asking for a copy, a correction, or a removal
Write from the account in question — a private message to a moderator, or the address below — and say what you want done. An account can be removed, and posts can be removed with it or left in place with the account gone, whichever you ask for. A copy of what is held against your account can be sent to you on the same basis. Two honest limits: text of yours that other people have quoted in their own replies belongs to their posts and stays there unless they edit it, and anything already copied off the site by a search engine or another reader is beyond reach entirely.
Readers in the UK or the European Union have the rights the GDPR gives them over their own data — access, correction, erasure, restriction, portability, and objection — and the requests above are how to exercise them here. If you think something about you has been mishandled and writing to us has not settled it, you can complain to the data protection authority for the country you live in.
How this is protected
- The site is served over HTTPS, and its cookies are marked Secure when it is.
- Passwords are hashed with scrypt, salted per account, and combined first with a secret kept outside the database — so a stolen copy of the database alone is not enough to attack them.
- Session and security cookies are HttpOnly, so no script on the page can read them, and SameSite=Lax, so another site cannot make your browser act as you.
- Every request that changes something must present a matching security token.
- Sign-ins, registrations, posts, messages and uploads are all rate limited.
- The registration challenge is generated and checked on this server, with a spelled-out arithmetic alternative for anyone who cannot see it. No third-party captcha service is involved, so registering here does not hand your visit to one.
- Uploaded images are served with headers that stop a browser treating a crafted file as a document.
None of that is a guarantee, and no site can give one. If you find a way through it, the address below is the place to say so, and a report made in good faith will be treated as a favour rather than an attack.
Third parties
This archive does not sell, rent or share anything about its readers or members, and there is no third-party analytics or advertising code on any page. Some pages do carry content that comes from elsewhere — video embeds, images linked in members' posts, and outbound links to booksellers — and those involve your browser contacting somebody else's server. What that means in practice is set out in the Cookies notice.
Children
The archive documents a practice with real physical and psychological hazards, set out in Safety, and the community section is written for adults. Accounts are not intended for under-sixteens. Nothing here asks for an age, and this notice does not pretend the site can verify one.
Changes
If what the software does changes, this page changes with it, and the date below moves. There is no mailing list to announce it on, which is the direct consequence of not collecting addresses.
Last updated: 11 August 2026. Questions, corrections and requests: info@mopaiarchive.com.