Draft version — to be reviewed before public launch.
Privacy Policy / Datenschutz
This draft explains how a perfect place (APP) processes data. It is not final legal advice and must be reviewed before public launch.
Last updated: April 30, 2026
Who Is Responsible
The responsible operator is [FULL LEGAL NAME], located at [FULL POSTAL ADDRESS]. Contact: [CONTACT EMAIL]. The operator is based in Switzerland.
What Data Is Processed
- Account data, including user id and email address handled through Supabase Auth.
- Profile data, including username, avatar, bio, badges, and public profile information.
- User content, including posts, comments, input ideas, replies, and reports.
- Interaction data, including reactions, follows, badge progress, and daily winner snapshots.
- Technical data, including logs, IP address, device and browser data needed for security, troubleshooting, and abuse prevention.
- Analytics data if analytics are enabled, such as product usage events and aggregated app performance signals.
Purposes
- Operate and maintain APP.
- Authenticate users and protect accounts.
- Provide community features such as posting, comments, follows, badges, and Hall of Fame snapshots.
- Moderate content, handle reports, and keep the community safe.
- Prevent abuse, spam, automated misuse, and enforce rate limits.
- Improve the product and understand usage if analytics are enabled.
Legal Basis
Depending on the context, processing may be based on contract performance, user consent where required, legal obligations, and the operator's legitimate interests in operating, securing, moderating, and improving APP. This wording is draft-level and should be reviewed for the final launch jurisdiction and product setup.
Service Providers
APP may use Supabase for authentication, database, storage, and backend services, and Vercel for hosting, deployment, and technical infrastructure. If analytics are enabled later, PostHog may be used for product analytics.
Cookies, Local Storage, and Session Storage
APP may use cookies, local storage, or session storage for authentication, session handling, login resume behavior, feed or UI state, security, and analytics if analytics are enabled.
Data Retention and Account Deletion
Data is retained as long as needed to operate APP, provide community features, comply with legal obligations, resolve disputes, and prevent abuse. Account deletion is available in profile settings. If an account is deleted, personal profile data is removed where feasible, while Hall of Fame snapshots may remain visible in anonymized form to preserve historical daily winner records.
User Rights
- Request access to personal data.
- Request correction of inaccurate data.
- Request deletion of personal data, subject to legal and technical limits.
- Object to or request restriction of processing where applicable.
- Contact the operator at [CONTACT EMAIL] for privacy requests.
Security
APP uses technical and organizational measures intended to protect user data. No online service can guarantee absolute security.
Contact
Privacy questions or requests can be sent to [CONTACT EMAIL].