[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"legal-en-\u002Flegal\u002Fpolicy":3},{"id":4,"title":5,"body":6,"description":188,"draft":189,"extension":190,"meta":191,"navigation":189,"path":192,"seo":193,"sitemap":194,"stem":196,"updatedAt":195,"__hash__":197},"legal_en\u002Flegal\u002Fpolicy.md","Privacy Policy",{"type":7,"value":8,"toc":175},"minimark",[9,27,32,35,39,42,46,49,53,56,60,63,67,70,74,77,81,88,92,97,104,110,120,126,132,150,156,165],[10,11,14],"callout",{"color":12,"icon":13},"warning","i-lucide-triangle-alert",[15,16,17,18,22,23,26],"p",{},"This document is a placeholder and is not legal advice. Replace it with a policy\nreviewed by a qualified lawyer before going live.\nOnce these documents are real, set ",[19,20,21],"code",{},"legal.termsVersion"," in ",[19,24,25],{},"starter.config.ts","\nto record who accepted which version, and bump it whenever they change\nmaterially.",[28,29,31],"h2",{"id":30},"_1-data-collected","1. Data collected",[15,33,34],{},"Describe what is collected — account details, usage data, cookies, and anything\ngathered by third-party scripts.",[28,36,38],{"id":37},"_2-how-data-is-used","2. How data is used",[15,40,41],{},"Describe the purposes: providing the service, support, billing, analytics, and\ncommunication.",[28,43,45],{"id":44},"_3-legal-basis","3. Legal basis",[15,47,48],{},"Describe the lawful basis for processing, if GDPR or a similar regime applies.",[28,50,52],{"id":51},"_4-sharing","4. Sharing",[15,54,55],{},"List the processors and third parties data reaches, and why.",[28,57,59],{"id":58},"_5-retention","5. Retention",[15,61,62],{},"Describe how long each category of data is kept.",[28,64,66],{"id":65},"_6-your-rights","6. Your rights",[15,68,69],{},"Describe access, correction, deletion, portability, and objection rights, and\nhow to exercise them.",[28,71,73],{"id":72},"_7-security","7. Security",[15,75,76],{},"Describe the safeguards protecting personal data.",[28,78,80],{"id":79},"_8-contact","8. Contact",[15,82,83,84,87],{},"Provide a contact for privacy questions and, where required, a data protection\nofficer. Write to ",[85,86],"contact-email",{},".",[28,89,91],{"id":90},"appendix-what-this-application-stores","Appendix: what this application stores",[15,93,94,95,87],{},"Facts about the code as it ships, not legal advice — an inventory for whoever\nwrites the sections above. Verify it against your own configuration, since most\nof it is switched on and off in ",[19,96,25],{},[15,98,99,103],{},[100,101,102],"strong",{},"Account."," Email address, display name, avatar image, role, the timestamps of\nemail verification and terms acceptance. Held until the account is deleted,\nwhich removes them.",[15,105,106,109],{},[100,107,108],{},"Sessions."," One row per signed-in device holding its IP address, user agent\nand activity timestamps. Revoked rows and rows idle beyond 30 days are pruned\ndaily; deleting the account deletes them outright.",[15,111,112,115,116,119],{},[100,113,114],{},"Activity log."," Sign-ins, credential changes and administrative actions, each\nwith the IP address and user agent that produced it. Retention is\n",[19,117,118],{},"activity.retentionDays"," — 90 days as shipped — after which a scheduled task\ndeletes them.",[15,121,122,125],{},[100,123,124],{},"Authentication tokens."," Magic-link, password-reset and email-verification\ntokens are stored only as SHA-256 hashes, alongside the address they were\nissued for, and expire within minutes to a day. Redeeming one marks it spent\nimmediately; the row itself is removed by the next sweep of expired tokens, or\nat once when the flow it belongs to clears them (a completed password reset, a\nconfirmed email change, account deletion).",[15,127,128,131],{},[100,129,130],{},"Payments"," (when enabled). The payment provider's customer and subscription\nidentifiers, the plan held, and the raw webhook payloads that produced them.\nThe card itself never reaches this application — the provider holds it.",[15,133,134,137,138,141,142,145,146,149],{},[100,135,136],{},"Attribution and cookies"," (when marketing conversions are enabled). Landing\non a page with an advertising click identifier in its URL writes it to an\nhttpOnly ",[19,139,140],{},"_cid"," cookie, holding up to six identifiers for 90 days — the one\nplace this application stores anything on the visitor's own device beyond the\nsession cookie and the consent record. It is written only after marketing\nconsent. When a checkout begins, those identifiers are snapshotted onto the\naccount with the IP address, user agent and consent state of that moment, so\nthe payment provider's later webhook can be attributed. Consent itself is\nremembered in the ",[19,143,144],{},"_ac"," and ",[19,147,148],{},"_mc"," cookies for 180 days.",[15,151,152,155],{},[100,153,154],{},"Analytics"," (when enabled). Cookieless: a visitor is a daily-rotating HMAC of\nIP address and user agent, so the same person is a different identifier\ntomorrow and nothing is stored on their device. Cloudflare Analytics Engine\nretains data points for three months and cannot delete individual rows — worth\nstating plainly, because it bounds what an erasure request can reach.",[15,157,158,161,162,164],{},[100,159,160],{},"Processors."," Cloudflare hosts the application and stores its database,\nfiles and images. Whichever payment, email and analytics providers are enabled\nin ",[19,163,25],{}," receive the data their function requires — the\naddresses mail is sent to, the identifiers a payment needs.",[15,166,167,170,171,174],{},[100,168,169],{},"Rights already implemented."," Settings → Profile offers a full data export\n(",[19,172,173],{},"GET \u002Fapi\u002Fauth\u002Fexport",") and account deletion. Both are self-service and need\nno request to a human.",{"title":176,"searchDepth":177,"depth":177,"links":178},"",2,[179,180,181,182,183,184,185,186,187],{"id":30,"depth":177,"text":31},{"id":37,"depth":177,"text":38},{"id":44,"depth":177,"text":45},{"id":51,"depth":177,"text":52},{"id":58,"depth":177,"text":59},{"id":65,"depth":177,"text":66},{"id":72,"depth":177,"text":73},{"id":79,"depth":177,"text":80},{"id":90,"depth":177,"text":91},"How personal data is collected, used, and protected by this service.",true,"md",{},"\u002Flegal\u002Fpolicy",{"title":5,"description":188},{"loc":192,"lastmod":195},"2026-07-29","legal\u002Fpolicy","EAUyd6XScvcZNTPR-O96TuTayDwEVG0hNW-DOarWzgo"]