Privacy
What is stored, for how long, and why; your email address is never shown to anyone but you.
Placeholder — content pending from the client. Do not launch with this page live.
This page still needs its real text. It should cover:
- Identity of the controller (name and contact details — the same entity as the Imprint)
- Categories of personal data processed: email address, pen name, submitted text, votes, and technical data such as request logs and cookies — PRIVACY-NOTES.md at the repository root has the field-by-field audit this section should be built from
- Purpose and legal basis for each category (GDPR Art. 6) — account operation, moderation, abuse prevention
- Retention periods for each category, and when data is deleted rather than kept
- Recipients: the hosting provider (Coolify) and the SMTP provider used to send mail, if a third-party one is chosen for production
- Whether any processing happens outside the EU/EEA
- Data subject rights: access, rectification, erasure, portability, objection, and the right to lodge a complaint with a supervisory authority — access and erasure already exist in-app as "Download my data" and "Delete my account" on /me/settings; this section should point to them, not duplicate the mechanism
- Cookies actually set (PRIVACY-NOTES.md lists them) and the basis for setting them without a consent banner
- That there is no analytics or tracking (true today — confirm it stays true before publishing this page)