Privacy Notice
Version: 2026-08-05
This notice explains what PageTown processes, why, who can see it, and the controls available to residents.
Information we process
- Account: email address, Supabase Auth identifiers, password-verifier material held by the Auth provider, confirmation state, and security/session records.
- Profile and social content: username, display name, biography, optional identity fields, themes, media, posts, comments, reactions, friends, blocks, boards, reports, and community memberships.
- Private communications: encrypted private-message payloads, participant and delivery metadata, and server-channel messages. PageTown is not end-to-end encrypted.
- Safety and operations: moderation evidence, appeals, audit events, quota and maintenance records, HMAC-derived abuse keys, call participation and relay diagnostics, and limited request security information.
- Eligibility and policy record: an age-threshold attestation and the policy versions accepted at registration. PageTown does not ask for a birth date.
Why we process it
The deployment operator must map each purpose to a lawful basis in each launch jurisdiction. The intended framework is:
- provide accounts, profiles, messaging, communities, export, and deletion as requested under the resident agreement;
- protect residents and the service, prevent abuse, enforce rules, secure accounts, and retain proportionate evidence where the operator has a reviewed legitimate interest or legal duty;
- meet applicable legal, tax, preservation, reporting, and dispute obligations; and
- seek separate, freely given consent before introducing optional analytics, marketing, recording, precise location, or other processing that requires it. Those features are not enabled today.
Visibility and sharing
Public profiles and public posts can be viewed without an account. Friends-only content is policy-filtered for accepted friends. Private messages are visible to conversation participants and are encrypted at rest, but are not end-to-end encrypted. Authorized staff can access reports and evidence only for a recorded moderation or security purpose. Infrastructure providers process data only to operate Auth, database, Storage, email, hosting, and relay services under operator-approved agreements.
Retention, deletion, and export
Retention varies by category and is documented in the operator data inventory. Residents can download a reauthenticated JSON export and request deletion from Account Security. Deletion has a 30-day grace period and can be delayed by server ownership, a valid legal hold, or asynchronous Storage cleanup. Some moderation, security, attribution, and conversation tombstone records remain with identity references removed or limited where required for safety, accountability, or law.
Your choices and rights
Residents can change profile visibility, remove content where supported, block accounts, revoke sessions, export data, and request deletion. Depending on location, additional access, correction, objection, restriction, portability, withdrawal, or complaint rights may apply. Contact the operator to exercise a right. Identity verification will be proportionate and the operator must not request unnecessary documents.
International processing and children
The operator must document hosting locations, subprocessors, transfer mechanisms, and regulator contacts before launch. PageTown is limited to people aged 16 or older and records only an attestation, not a birth date. The service is not designed for children. Reports suggesting an underage account or child-safety risk receive restricted, urgent review.
Contact
Privacy and legal contact: admin@example.com. The operator must publish its legal identity, address where required, and applicable supervisory-authority information before launch.
Related documents: Privacy, Terms, Community Guidelines, Acceptable Use, Cookies and Sessions, and Copyright.