§Legal
Privacy Policy.
Effective . Last updated .
This policy explains what this website and Agora collect, why, and who else sees it. It sits alongside the Terms of Service.
This website collects nothing
The page you are on is a single file of text and CSS. It sets no cookie, writes nothing to your browser, and has no analytics, tracking pixels, embedded videos or social buttons. Both typefaces are served from this site rather than from a font network, so opening the page tells no one else that you did. That is also why there is no cookie banner: there is nothing to ask you about.
The only record is the ordinary server log at our host, described under who we share data with. Everything below this point is about Agora itself.
Who is responsible
The controller under Article 4 (7) GDPR is:
Parthix Advisory UG (haftungsbeschränkt)Petzetstraße 21
81245 München
Germany
- Email: ZoDevAi.work@gmail.com
- Phone: +49 172 822 7122
Full provider details are on the imprint. We have not appointed a data protection officer, because we are not required to.
What Agora collects
We keep the service small and collect only what it needs to run the boards, hold accounts, and stop abuse.
- A visitor session. A cookie named
agora_sidholds a random id. It exists so a view or a brand click counts once per visitor rather than once per page load, and so the site can say how many people are looking right now. It says nothing about who you are. It lasts a year in your browser and is deleted on our side after 90 days without a visit. - A hash of your address. Your IP address is never stored. A hash of it, salted with a value that changes daily, is kept briefly to stop scripts inflating view counts. The hash cannot be turned back into the address, and yesterday's hash cannot be matched to today's.
- The name your browser sends. The user agent is stored with the session, to tell people apart from crawlers.
- Your account. Your email address and password, handled by Supabase Auth. The password is stored only as a hash and the site never sees it in the clear. If you sign in with GitHub or Google we receive the email address and public name those services share, and nothing else.
- Your profile and posts. Your username, and whatever you choose to add: a short bio, a location, links, an avatar. Then the projects, images, comments and reactions you post.
- Feedback you send. The message, the topic, the page you were on and your user agent, so it can be read and answered. An email address is optional; without one there is no way to reply. If you were signed in, the message carries your username.
- Brand requests. A brand name, a line of description, a link, a logo and a contact email. The first four appear on the brand board. The email is used for the invoice and the go-live note and nothing else.
Cookies
The session cookie described above is the only cookie, and it is strictly necessary: without it a view cannot be counted once instead of many times. It is not used for advertising and there is no advertising network on the service. Your choice of light or dark, and the emoji you reacted with most recently, are kept by your own browser and never sent anywhere.
Why we use this data
- Contract, Article 6 (1) (b). To hold your account, publish what you post, and place a paid brand on the brand board.
- Legitimate interests, Article 6 (1) (f). To count views fairly, keep bots and scripted traffic off the boards, deliver and secure the site, answer feedback, and defend legal claims. You may object to this, as described under your rights.
- Legal obligation, Article 6 (1) (c). To keep the tax and accounting records the law requires for brand payments.
What is public
Projects, images, comments, reactions, usernames, profiles, view counts and board positions are public by design. Anyone can see them, including search engines, whether or not they have an account. Do not post anything you would not want shown that way. Brand rows are public and marked as paid.
Who we share data with
- Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, United States. Hosts this website and Agora, and therefore writes the ordinary server log: your IP address, the time, the file requested, the result, your browser and the page you came from. Agora's server code runs in Frankfurt; static files are served from whichever Vercel location is closest to you.
- Supabase. The database, accounts and uploaded images, in Frankfurt, Germany. Emails about your account, such as confirmation and password reset, are sent by Supabase Auth.
- Stripe Payments Europe, Limited, Dublin, Ireland, for brand payments. Stripe collects the card details and the billing identity; we never see or store a full card number. Stripe sends us confirmation that a payment succeeded, and an amount, so the brand row can go up. Stripe's own privacy notice applies to what it collects.
- Professional advisers, authorities, or a buyer of the service, where we must share data to comply with the law, enforce the Terms, or transfer the project.
We do not sell personal data. The database and the accounts sit in Frankfurt, and Stripe's European entity is in Ireland, both inside the European Economic Area. Vercel is in the United States, and that transfer rests on the European Commission's standard contractual clauses, which form part of Vercel's data processing agreement.
How long we keep it
- Sessions: 90 days after the last visit. Abuse counters: two days.
- Brand requests that were never followed up: 90 days. Payment records: as long as tax and accounting law requires.
- Feedback: until it is dealt with, then a year, so a decision can be traced to what prompted it.
- Content you remove is hidden at once and marked removed. It stays in the database so a moderator can restore it if it went by mistake, and is deleted with the account.
- An account and everything attached to it is deleted on request.
- Server logs are kept by our host for a short period for security and operations. We keep no copy.
Your rights
You can ask us at any time to:
- tell you what we hold about you, under Article 15
- correct it, under Article 16
- delete it, under Article 17
- restrict what we do with it, under Article 18
- hand it to you in a portable form, under Article 20
- stop processing based on legitimate interest, under Article 21
Write to ZoDevAi.work@gmail.com. Asking costs nothing and we answer within a month. Where we relied on your consent you can withdraw it at any time, without affecting what was done before.
You may also complain to a supervisory authority under Article 77. Ours is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) in Ansbach. You may instead complain to the authority where you live.
Content that is public on your own site or profile does not become private by being removed from Agora. You can ask us to take the post down.
Younger people
Agora is not for anyone under 13, and we do not knowingly collect anything from them. Where the law where you live sets a higher age for agreeing to this kind of processing, as Germany does at 16, a parent or guardian has to agree on your behalf below that age.
If you believe someone below the age limit has made an account, write to ZoDevAi.work@gmail.com and we will delete what we can identify.
Changes
When the service changes, this page changes with it. The date at the top is the current version. There is no mailing list to notify, because we do not have your address unless you gave us one.
See also the imprint and the Terms of Service.