Privacy at a Glance
- We use AI to provide helpful context on posts, but we don't train AI models on your data.
- We use PostHog for analytics, Mailgun for emails, and Cloudflare Images for image hosting.
- We never sell, rent, or trade your personal information to third parties.
- You can delete your account anytime - we keep your data for 30 days, then permanently remove it.
- You have full rights to access, correct, or delete your personal information.
Information We Collect
- Personal Information:When you register for an account, we collect your first and last name and email address. You may also provide additional information like a profile picture, biography, and other profile details. This information is used to create your public profile and maintain community transparency.
- Usage Data:We automatically collect information about your interactions with the Platform—pages visited, posts viewed, voting patterns, comments posted, spaces joined, and engagement metrics—to improve our services and personalize your experience.
- Technical Information:We automatically collect technical data—IP address, browser type, operating system, and device identifiers—necessary for Platform operation and security.
What's Public vs Private
| Public Information | Private Information |
|---|---|
| Your name, username, profile picture, and bio | Your email address and password |
| Your posts, comments, and replies | Your IP address and device information |
| Your followers | Your voting patterns and reading history |
| Spaces you've joined | |
| People you follow |
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Platform and its features
- Personalize your experience and recommend relevant content and spaces
- Communicate with you about your account, updates, and notifications
- Ensure platform security, prevent fraud, and enforce our Terms of Service
- Analyze usage patterns and improve our services
- Comply with legal obligations and respond to legal requests
- Send marketing communications with your consent (you may opt out at any time)
Legal Basis for Processing (GDPR)
For users in the European Union, we process your personal data based on the following legal grounds:
- Performance of a Contract: We process your data to provide the services you signed up for, as described in our Terms of Service.
- Legitimate Interests: We process data for security, fraud prevention, service improvement, and analytics based on our legitimate interest in operating a safe platform.
- Consent: We rely on your consent for sending marketing communications and using analytics cookies, which you can withdraw at any time.
- Legal Obligation: We process data when required to comply with legal requirements or respond to lawful requests from authorities.
How We Use AI to Enhance Your Experience
We use artificial intelligence to help maintain the quality and accuracy of discussions on Sankira:
- Our "Additional Context" feature uses AI to analyze posts and provide helpful context, alternative perspectives, or fact-checking information.
- Only post text is sent to our AI provider—no personal information (email, IP address, etc.). Our AI provider doesn't train models on your data or retain it.
- This feature is automatic for certain content and is clearly labeled.
Data Retention
We retain your personal information only as long as necessary to provide our services and comply with legal obligations. Here are our specific retention periods:
- Account Data: Account deletion starts a 30-day recovery period. After 30 days, we permanently delete your personal information.
- Posts and Comments: Deleted posts/comments are immediately replaced with "[deleted]" placeholders with no author info. Content is permanently removed after 30 days.
- Analytics Data: Analytics data (usage patterns, page views, engagement metrics) retained for up to 2 years.
- Server Logs: Technical logs (IP addresses, access times) kept for 30 days, then automatically deleted.
- Backup Data: Deleted data may persist in backups for up to 30 days before being permanently purged from all systems.
- Legal Compliance: If required by law or ongoing legal proceedings, we may retain specific data for longer periods as legally mandated.
Data Security
We implement security measures including encryption, secure servers, access controls, and regular security assessments to protect your information. However, no internet service is completely secure.
Your Privacy Rights
We provide these rights to all users globally:
Your Rights:
- Access: Request a copy of the personal data we hold about you, including details about what we've collected, used, or disclosed.
- Correction: Request correction of inaccurate or incomplete information.
- Deletion: Request deletion of your account and personal data (30-day recovery period available).
- Portability: Request your data in JSON format.
- Restriction: Request that we limit how we process your personal information in certain circumstances.
- Object: Object to processing based on legitimate interests or for direct marketing purposes.
- Withdraw Consent: Where we process data based on your consent, you can withdraw it at any time.
- Opt-out: Unsubscribe from marketing emails at any time.
- File a Complaint: Contact regulators if you believe we've mishandled your data.
- Non-Discrimination: No discrimination for exercising privacy rights.
How to Exercise Your Rights:
To exercise any of these rights, please email us at privacy@sankira.com with:
- Your full name and email address associated with your account
- A clear description of which right you'd like to exercise
- Any relevant details to help us process your request
Response Time: We'll respond to your request within 30 days (45 days for complex requests). For data access or portability requests, we'll provide your data in JSON format via secure download link.
Children's Privacy
You must be at least 16 years old to use Sankira, or 13 if permitted by your country's laws. EU users must be 16 unless their country allows a lower age limit with appropriate consent.
We don't knowingly collect personal information from children below these age limits. If you're a parent or guardian and believe your child has provided us with personal information, contact us at privacy@sankira.com. We'll take immediate steps to remove any information collected from children below the legal age without proper consent.
Data Breach Notification
If a data breach occurs, we'll:
- Investigate immediately and contain the breach
- Notify regulatory authorities within 72 hours if required by law
- Notify you without delay if the breach poses high risk to your rights
- Provide details about what data was affected, consequences, our response, and recommended steps
If you believe your account has been compromised, contact privacy@sankira.com immediately and change your password.
Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices, services, or laws. Material changes will be indicated by updating the "Last Updated" date and may include additional notice.
Contact Us
Questions about this Privacy Policy, data practices, or privacy rights? Contact privacy@sankira.com. For general support, use Platform support channels.