Privacy Policy
Last updated: October 2026 · Pre-beta draft
1. Data controller
Data controller: [TO BE COMPLETED] (legal name or company), registered office: [TO BE COMPLETED] (address).
Privacy contact: [TO BE COMPLETED] (dedicated email, e.g. privacy@contrybution.com).
2. Data we process
Account: email address (used only for one-time-code sign-in), your chosen public handle, preferred language.
Content: drafts, published contributions, cited sources. Unauthenticated drafts are tied to a technical token stored in your browser.
Technical data: application logs with identifiers and hashed IP addresses (your text never appears in logs). No profiling cookies, no advertising trackers.
3. Purposes and legal bases
Providing the service (art. 6.1.b GDPR): account, drafts, publishing contributions, issuing credentials.
Security and abuse prevention (art. 6.1.f GDPR): rate limiting, technical logs, moderation.
Legal obligations (art. 6.1.c GDPR): handling illegal-content reports under Regulation (EU) 2022/2065 (DSA).
4. Cookies and local storage
We use a single technical session cookie (ctb_session), required for authentication, and your browser's localStorage to keep unauthenticated drafts on your device.
No analytics, profiling or third-party cookies: that is why no cookie banner is needed.
5. Contribution evaluation and AI providers
Before publication, the contribution text is evaluated by a language model from an external provider (currently Mistral AI) in stateless mode: the text is not used to train models.
The evaluation concerns the shape of the contribution (whether it adds something to the conversation), never the opinion expressed.
6. Retention
Anonymous drafts: 7 days. Authenticated drafts: 30 days since last update.
Contributions and credentials: kept until account deletion or content removal (see section 7).
Technical logs: 90 days.
Database backups: up to 7 days, for disaster recovery only, never for ordinary purposes.
7. IP addresses
Browsing, drafts, sign-in and contribution evaluation do NOT involve storing your IP address in clear text. Web server access logs contain no IP addresses.
For security, rate limiting and audit purposes we use a pseudonymized IP fingerprint (HMAC with a secret key), which does not allow us to recover the real address.
Only when you publish a Contribution, the publishing IP address is encrypted and stored in a segregated archive, unreadable by the application, accessible solely to authorized personnel through dedicated tools with every access logged. Exclusive purposes: responding to legally valid requests from competent authorities and establishing, exercising or defending legal claims (art. 6.1.f GDPR, following a documented balancing test; art. 6.1.c GDPR for specific obligations). It is never used for analytics, rankings, personalization or ordinary security.
Retention: 365 days from publication (provisional technical value undergoing legal validation), with automatic deletion at expiry, unless preservation obligations are in force (legal hold). Art. 17.3.e GDPR may limit early erasure to the extent necessary for the stated purposes.
8. Account deletion and legal retention
When you delete your account we immediately delete sessions, login codes and unpublished drafts, and anonymize your profile (email, handle, display name). Published contributions are not automatically removed: they remain attributed to “Deleted account” and their credentials remain cryptographically verifiable. Removal of specific content remains a separate procedure.
Before severing the identifying link we create a segregated record containing only: the account's technical identifier, the opaque public identifier, your email encrypted with an authenticated algorithm (AES-256-GCM, dedicated key stored outside the database and inaccessible to the application), deletion date and expiry.
This record exists solely to respond to lawful authority orders and to establish, exercise or defend legal claims. Legal basis: art. 6(1)(f) GDPR (legitimate interest, subject to a documented necessity and balancing test) and, where applicable, art. 6(1)(c) GDPR (compliance with a specific legal obligation). Art. 17(3)(e) GDPR operates as an exception to the right to erasure, to the extent strictly necessary for the same purposes.
The record is not accessible through the application's regular APIs, is not used for analytics, marketing or product features, and every access is logged. It is irreversibly deleted after 365 days (provisional technical value, undergoing legal validation), unless suspended for specific legal needs (documented and audited legal hold).
Backups may contain copies of the record until their natural expiry (section 6): they are encrypted, used only for disaster recovery, and after every restore we immediately delete records past expiry.
9. Your rights
You can delete your account yourself from the Account page.
You can request access, rectification, erasure, restriction and portability of your data by writing to the privacy contact above.
You have the right to lodge a complaint with your data protection authority.
10. Minors
The service is not directed at children under 14. If we learn of accounts belonging to children under 14, we delete them.