Privacy Policy
Last updated: 4 August 2026
The short version:
- Visibility follows the surface you post on. Content in publicly accessible communities, channels and sections — posts, comment threads, chat archives, moderation logs and profiles — can be read by anyone and indexed by search engines. Content in private, members-only or moderator-only areas is limited to the people authorized to view it.
- An account needs a username, an email address and a password. The password is stored only as a salted hash; your email address is never displayed publicly.
- Optional product analytics (PostHog) runs only after you explicitly allow it, and you can withdraw that choice at any time on this page.
- If you connect an open-source project, Earde stores public GitHub metadata about it. It never stores your GitHub tokens and never reads repository contents.
- You can export your profile, posts and comments as JSON, and delete your account at any time from your settings.
This policy covers the Earde service at earde.com. It is not a terms-of-service document.
Who controls your data
Earde is a small, independently operated service. The operator of Earde decides how and why the personal data described in this policy is processed, and is the data controller for it.
For any question or request about your data, contact the operator at metacirculardispatches@gmail.com. Earde has not appointed a data protection officer.
Data we collect
Account and profile
Creating an account requires a username, an email address and a password. Without them you can read public content but cannot post, comment, chat, vote or join communities. The password is stored only as a salted argon2id hash — Earde cannot read it back. Your email address is used to confirm your account and to reset your password; it is never displayed publicly and is not included in analytics. You can optionally add a bio and an avatar image to your profile; both are public.
Signup confirmation
When you sign up, Earde stores a pending record with your chosen username, email address, password hash, a hashed confirmation token, and the IP address and browser identifier (user agent) of the signup request. The confirmation link expires after 24 hours. Signup may also include a Cloudflare Turnstile bot check (see Who receives data).
Service and technical data
- Login sessions, stored server-side in Earde's database; the browser cookie holds only a session identifier.
- Rate-limiting records keyed by IP address and endpoint, for signup, login and password-reset requests.
- First-party page-view statistics: the page path, the referring site's host name, and a pseudonymous identifier rebuilt each day from IP address, browser and date — it cannot link your visits across days, and the raw IP address is not stored with it.
- Server request logs for operating and debugging the service; security-sensitive values (tokens, authorization codes) are redacted before logging.
Community content and activity
Posts, comments, chat messages, votes, karma, community memberships, reports you file, moderation actions that concern you, and notifications addressed to you. Live presence, typing and cursor indicators are transient signals that are broadcast to other viewers of the page and are not stored.
GitHub project data
Only if you connect an open-source project — see GitHub integration.
Analytics data
Only after you allow it — see Cookies and analytics.
Where this data comes from
From you (forms and the content you write), from your browser (technical data that accompanies each request), and from GitHub (public metadata, when you connect a project).
How and why we use data
| Purpose | Data | Legal basis |
|---|---|---|
| Providing your account and the service: signing you in, publishing the content you write, memberships, notifications, data export | Account, profile, content and activity | Performance of a contract (Art. 6(1)(b) GDPR) |
| Sending transactional email: signup confirmation and password reset | Email address | Performance of a contract |
| Security and abuse prevention: rate limiting, the signup bot check, bans, moderation and report handling | IP address, technical data, moderation records | Legitimate interest: keeping the service and its communities secure and usable. You can object (see Your rights). |
| Aggregate first-party usage statistics (page-view counts with a daily-rotating pseudonymous identifier) | Technical data | Legitimate interest: understanding aggregate usage of a public service without profiling individuals across days. You can object. |
| Optional product analytics and session replay (PostHog) | Analytics data | Consent (Art. 6(1)(a) GDPR), withdrawable at any time |
| Complying with the law when a competent authority lawfully requires information | As required | Legal obligation |
Earde does not rely on legitimate interest for optional analytics, and does not treat publishing content as blanket consent to unrelated processing.
Public content and search engines
How visible your content is depends on the visibility of the specific surface you post it on, not just on the community it belongs to. Content posted in publicly accessible communities, channels and sections — posts, comment threads and chat channel archives — can be read by anyone, including signed-out visitors, and may be indexed by search engines. Your profile page — username, bio, avatar, join date and your posts and comments on publicly accessible surfaces — is public too. A community's moderation log (the action taken, the acting moderator's username and the reason given) is visible to anyone who can view that community.
Vote totals on posts and comments are public; which way you voted is stored but not shown to other users. When a chat conversation is promoted into a thread, the thread displays the referenced chat messages with their authors, subject to the source surface's access rules.
Content posted in private, members-only or moderator-only areas — private communities and everything inside them, moderation queues, and the private workflow records described elsewhere in this policy — is limited to users authorized to view that area (which always includes Earde's administrators). Pages of private communities also ask search engines not to index them.
Anything published publicly can be crawled, cached, quoted or copied by search engines and other third parties. Deleting content on Earde stops Earde from displaying it, but does not reach copies that others have already made outside Earde's control.
GitHub integration
Connecting an open-source project through GitHub is optional, and it is not a way to sign in: your Earde account remains a separate username-and-password account.
When you connect a project, Earde receives from GitHub and stores: the numeric ID, login name and type (user or organization) of the GitHub account the app is installed on; the installation's identifier and status; and, for the public repositories you select, their repository IDs, names, owners, descriptions, default branches, archived status and public github.com URLs. Only repositories that are public on GitHub are stored — private and internal repositories are never kept. Project pages and connected community pages display this metadata publicly.
Earde never stores your GitHub tokens. The short-lived token GitHub issues during the flow is used only for the read-only requests needed to verify the installation and list the public repositories available through it, and is then discarded. The integration does not read repository contents and does not change anything on GitHub. During the flow, a temporary encrypted cookie (15 minutes, scoped to the connect pages) carries the flow's security material.
GitHub itself independently processes what you do on github.com — including the install and authorize screens — under its own privacy statement.
If you uninstall the Earde app on GitHub, no further access is possible, but the project metadata already stored on Earde is not removed automatically — contact the operator to have it removed.
Who receives data
- Brevo (transactional email delivery): receives your email address and the confirmation or password-reset message sent to you. See Brevo's privacy policy.
- Cloudflare (Turnstile bot check on signup, when enabled): your browser loads the challenge widget directly from Cloudflare, which processes that interaction under Cloudflare's privacy policy. Earde's own server sends Cloudflare only the challenge token to verify — not your IP address.
- PostHog (EU cloud): the consented analytics data described above.
- GitHub: when you connect a project, you interact with GitHub directly; GitHub acts as an independent service, not on Earde's behalf.
- Hosting infrastructure: Earde runs on a server hosted with Hetzner; the service data described in this policy is stored there, in Earde's own PostgreSQL database.
- Other users, moderators and communities: content according to its visibility; reports you file go to the moderators of the community concerned; private request notes reach the limited audience described under Shared Threads.
- Authorities: only if disclosure is lawfully required.
Earde does not sell personal data and does not share it for cross-context behavioral advertising.
International transfers
Earde's analytics is configured to use PostHog's EU region endpoints. GitHub, Cloudflare and Brevo are independent global providers; when you interact with them as described above, they may process data outside the European Economic Area, as described in their own privacy notices linked in this policy.
How long we keep data
- Account data: while your account exists. On deletion, your identifying details are removed as described under Account and content deletion.
- Login sessions: expire after about two weeks, or immediately on logout.
- Signup confirmation records (including the signup IP address and browser identifier): valid for 24 hours, then removed during routine cleanup.
- Password-reset records: valid for 2 hours; removed when used, unusable afterwards.
- Rate-limiting records (IP address and endpoint): used only for the current one-minute request window; routine cleanup deletes records shortly after their window has lapsed.
- First-party page-view statistics: kept as pseudonymous usage statistics; the daily-rotating identifier cannot link visits across days.
- Posts and comments: until you or a moderator deletes them. Deleting a post or comment replaces its text with a neutral placeholder; the placeholder row remains so that surrounding discussion stays coherent.
- Chat messages: until deleted. A deleted chat message is hidden from every reader, though the original text currently remains in the database record.
- Reports, moderation logs and lifecycle records: retained while needed for community safety, moderation accountability and dispute handling.
- Notifications: stored with your account; removed when the thing they point to is deleted.
- Project and GitHub metadata: for as long as the project remains on Earde. It is not removed automatically when the connecting account is deleted; contact the operator to remove it.
- Analytics data at PostHog: held by PostHog until deleted; deleting your Earde account triggers a deletion request for your analytics profile and its events.
- Server logs: kept for operating and troubleshooting the service.
Security
- Passwords are stored only as salted argon2id hashes, never in a readable form.
- One-time email tokens (signup confirmation, password reset) are stored only as SHA-256 hashes.
- Sessions are kept server-side; the browser cookie carries only an identifier. Every state-changing form is protected by a signed anti-forgery token.
- The GitHub connect flow uses PKCE, single-use state values stored only as hashes, and an encrypted, short-lived flow cookie.
- The production service is served over HTTPS, and security-sensitive values are redacted from server logs.
No online service can promise perfect security. If a breach affecting your data occurs, the operator will handle it as applicable law requires.
Your rights
Under the GDPR you can ask for access to your data, correction, deletion, restriction of processing, and a portable copy; you can object to processing based on legitimate interest; and you can withdraw consent (for analytics, directly via the controls above) at any time without affecting past processing.
You can exercise several of these yourself: edit your profile in account settings, download your profile, posts and comments as JSON via data export, delete individual posts, comments and chat messages, and delete your whole account. For everything else — including access to data the export does not cover — email metacirculardispatches@gmail.com; the operator may need to verify that you control the account concerned.
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state where you live, where you work, or where you believe an infringement occurred.
Account and content deletion
You can delete your account at any time from account settings (Danger zone → Delete account). This is irreversible. When you do:
- Your username is replaced by a neutral placeholder, shown as [deleted]; your email address, password hash, bio and avatar are removed from the account record; the uploaded avatar image file is deleted from Earde's storage; and your sessions are ended.
- Earde automatically requests deletion of your analytics profile and its events at PostHog.
- Your posts, comments and chat messages remain in their communities, no longer attributed to you. Delete any of them individually first if you do not want them to remain.
- Records needed for community safety — reports, moderation logs, lifecycle records — and project or GitHub metadata you connected are retained as described under How long we keep data.
- Copies of formerly public content held by search engines or other third parties are outside Earde's control.
Automated decisions
Earde does not make automated decisions about you that produce legal or similarly significant effects. Automated protections exist — rate limiting, the signup bot check and a spam trap — but they only limit form submissions; if you believe one blocked you in error, contact the operator.
Changes to this policy
When this policy changes, the new version is published on this page with an updated date at the top, and material changes are summarized here. This page is always reachable without an account.
Contact
Questions, requests, objections, or anything unclear: metacirculardispatches@gmail.com.