Privacy policy
What we collect, why, how long we keep it, and how to get it back or have it erased. Written to be read, not to be signed blindly.
Last updated :
1.Who is responsible for your data
The data controller is the publisher of Amorcia, reachable at [email protected]. Registration details appear in the legal notice and will be completed once the entity is incorporated.
As long as no fundraising is open, Amorcia processes neither banking data nor identity documents.
2.What data is collected
Amorcia only collects data you provide yourself, with one exception: your country, inferred from your IP address.
- Account: email address, display name, username, role chosen at sign-up, language.
- Profile, optional: phone, country, biography, photo.
- Security: a coarse fingerprint of your trusted devices, IP address at sign-in time, one-time verification codes (stored only as a hash, never in clear text).
- Usage: projects created, contributions, comments, follows.
- Country: inferred from your IP address by our distribution provider, to adapt language, currency and payment methods. Neither city nor coordinates are passed to us.
No data is bought from a third party, and none is inferred from your behaviour beyond what is described here.
3.Why, and on what legal basis
Each processing activity has its own purpose and legal basis. A legal basis is not a formality: it determines which rights you hold over that particular activity.
| Activity | Legal basis |
|---|---|
| Creating and managing your account | Performance of a contract |
| Two-factor authentication, trusted devices | Security obligation |
| Log of sensitive actions | Legitimate interest, security |
| Newsletter | Consent |
| Audience measurement (Google Analytics) | Consent |
| Country adaptation | Legitimate interest, service relevance |
5.How long your data is kept
Every piece of data has a lifetime, and that lifetime is enforced by a daily automated task, not by hand.
- Account: as long as it is active, then as described in "Your rights" below.
- Activity log: 1 year. Enough to analyse a security incident after the fact, which is its only purpose.
- Trusted devices: 1 year without a sign-in, then deleted. Beyond that, it is no longer a known device.
- Verification codes: 10 minutes, then purged hourly.
- Unconfirmed newsletter sign-ups: 30 days. Without confirmation, no consent was ever given.
- Anonymised accounts: permanently erased after 3 years, once no retention obligation stands in the way.
6.Who else sees your data
Your data is neither sold, rented, nor passed on for advertising. It is processed by a small number of technical providers, each for one specific task.
- Hetzner (Germany): server and database hosting. Your data lives there, inside the European Union.
- Cloudflare: site distribution and protection, country detection.
- Resend (United States): sending verification emails, security codes and the newsletter.
- Google (United States): audience measurement, only if you consented to it.
- Geoapify: turning a place name into coordinates, called from our server. Your IP address is never passed to it.
Transfers outside the European Union.Resend and Google process data in the United States, under the European Commission's standard contractual clauses and the EU-US Data Privacy Framework. In practice: Resend sees your email address, and Google sees nothing until you accept audience measurement.
7.Your rights, and how to exercise them in two clicks
You can exercise your rights of access, portability and erasure directly from your account, without writing to anyone and without waiting.
- Access and portability: the "Export my data" button in your profile downloads everything we hold about you, in a file readable by both a machine and a human.
- Rectification: your profile fields can be edited at any time.
- Erasure: the "Delete my account" button. If your account has no project and no contribution, everything is erased immediately and permanently. If you have run a project or backed someone else's, your account is anonymised rather than deleted: the project and its contributions must remain readable to the people who committed money. Either way, your personal data is gone.
- Objection and withdrawal of consent: the "Manage cookies" link at the bottom of the page for audience measurement, the unsubscribe link in every email for the newsletter.
For any other request, write to [email protected]. You may also lodge a complaint with your national data protection authority.
8.How your data is protected
Protection does not rely on trusting the application code: access rules are enforced by the database itself, and tested the way a direct attack on the API would.
- Database unreachable from the internet.
- Encryption in transit across the whole site, and encrypted backups whose restoration is tested automatically every week.
- Session stored in a cookie unreadable by JavaScript, and two-factor authentication by email code available on every account.
- Passwords stored hashed, never in clear text, and never readable by us.
Should a data breach be likely to put you at risk, you will be informed, and the supervisory authority within 72 hours.
9.Changes to this policy
Any substantial change will be announced on this page and, if it concerns you directly, by email. The last-updated date appears at the top of the page. Previous versions are kept in the public history of the site's source code.
A question about this page? Contact us