Zsaso Privacy Policy

Draft for discussion. Not yet in effect, and not reviewed by a lawyer. Text in [brackets] needs a decision.

Zsaso is funded by its members, not by advertising. We collect what we need to run the service, we don't sell it, and we don't use it to target you with anything.

1. What we collect

When you create an account - Your email address (used to sign you in and to send account and notification emails). - Your chosen username and display name. - Your acceptance of the Terms of Service and confirmation that you are 13 or older, with the date. We do not store your date of birth.

What you add - Profile details you choose to share: bio, avatar, header image, about page, links, creator types, categories. - Posts, replies, direct messages, and images you upload. We keep the original of each image privately so we can regenerate display sizes; the original is never shown or shared. We remove location data (EXIF GPS) from every image we display. - Follows, blocks, mutes, likes, and bookmarks.

When you pay - Payments are processed by Stripe (on the web) or by Apple or Google (in-app). We receive a customer reference, subscription status, and dates; we never see or store your card number.

Automatically - Standard server logs: IP address, browser or app version, pages requested, and timestamps, kept for [30 days] for security and debugging. - A session cookie that keeps you signed in on the web, and a sign-in token in the app. - Push-notification tokens for the app, if you enable notifications. - First-party, aggregate usage counts (for example, how many people viewed a post). No third-party analytics or tracking scripts.

2. How we use it

We do not use your data for advertising, and we do not sell, license, or share your content or data for training artificial-intelligence or machine-learning models.

3. Who else sees it

4. Cookies

We use one session cookie to keep you signed in and one to protect forms against forgery. No advertising or tracking cookies. Blocking cookies will prevent signing in on the web; reading public pages works without them.

5. Image safety scanning

Images you upload are checked against hash databases of known child sexual abuse material before they are displayed. This compares fingerprints, not the image itself, and no person views your images as part of this check. Matches are handled as the law requires (see Code of Conduct §3) and evidence is preserved for the period the law specifies.

6. How long we keep it

7. Your rights and controls

If you are in the European Economic Area, the United Kingdom, or another region with data-protection rights, you can also ask us to restrict processing or object to it, and you may complain to your local authority. Write to [privacy@zsaso.com]. [If EU users become significant, appoint an EU representative and name them here.]

8. Children

Zsaso is not for children under 13, and we do not knowingly collect information from them. If you believe a child under 13 has an account, contact [privacy@zsaso.com] and we will remove it.

9. Security

Connections are encrypted (HTTPS). We use passwordless sign-in (email links and passkeys) so there is no password to steal. Access to production data is limited to the people who need it to run the service. No system is perfectly secure; if we learn of a breach affecting your data, we will tell you.

10. Changes

We'll notify you of material changes before they take effect. The version and effective date are at the top of this document.

11. Contact

[Operator legal name] [Address] [privacy@zsaso.com]