Zsaso Privacy Policy
Draft for discussion. Not yet in effect, and not reviewed by a lawyer. Text in [brackets] needs a decision.
Zsaso is funded by its members, not by advertising. We collect what we need to run the service, we don't sell it, and we don't use it to target you with anything.
1. What we collect
When you create an account - Your email address (used to sign you in and to send account and notification emails). - Your chosen username and display name. - Your acceptance of the Terms of Service and confirmation that you are 13 or older, with the date. We do not store your date of birth.
What you add - Profile details you choose to share: bio, avatar, header image, about page, links, creator types, categories. - Posts, replies, direct messages, and images you upload. We keep the original of each image privately so we can regenerate display sizes; the original is never shown or shared. We remove location data (EXIF GPS) from every image we display. - Follows, blocks, mutes, likes, and bookmarks.
When you pay - Payments are processed by Stripe (on the web) or by Apple or Google (in-app). We receive a customer reference, subscription status, and dates; we never see or store your card number.
Automatically - Standard server logs: IP address, browser or app version, pages requested, and timestamps, kept for [30 days] for security and debugging. - A session cookie that keeps you signed in on the web, and a sign-in token in the app. - Push-notification tokens for the app, if you enable notifications. - First-party, aggregate usage counts (for example, how many people viewed a post). No third-party analytics or tracking scripts.
2. How we use it
- To run your account and show your content to the people you choose.
- To send you sign-in links, notifications you've opted into, and important account or policy notices.
- To process payments and prevent fraud.
- To keep the community safe: reviewing reports, enforcing the Code of Conduct, and scanning uploaded images against databases of known child sexual abuse material, as described in §5.
- To improve the service using aggregate, non-identifying statistics.
We do not use your data for advertising, and we do not sell, license, or share your content or data for training artificial-intelligence or machine-learning models.
3. Who else sees it
- Other people on Zsaso see your public profile and posts, and members see your replies and likes. Direct messages are visible only to their participants and, if reported, to moderators.
- Other services, if you enable federation: copies of your public posts and profile are delivered to servers on the ActivityPub network (such as Mastodon) that you or your followers use. Those servers have their own privacy practices.
- Service providers that process data for us, under contracts that limit their use to our instructions: [Cloudflare] (network security and content delivery), [email provider] (transactional email), Stripe (payments), Apple and Google (app distribution and in-app purchases), [image-scanning provider] (child-safety hash matching), and [error-monitoring provider]. Data may be processed in the United States.
- Authorities, when the law requires it — for example, we are required to report apparent child sexual abuse material to the National Center for Missing & Exploited Children — or to protect someone's safety.
4. Cookies
We use one session cookie to keep you signed in and one to protect forms against forgery. No advertising or tracking cookies. Blocking cookies will prevent signing in on the web; reading public pages works without them.
5. Image safety scanning
Images you upload are checked against hash databases of known child sexual abuse material before they are displayed. This compares fingerprints, not the image itself, and no person views your images as part of this check. Matches are handled as the law requires (see Code of Conduct §3) and evidence is preserved for the period the law specifies.
6. How long we keep it
- Account and content: while your account exists, and for a [30-day] grace period after you delete it, in case you change your mind.
- Server logs: [30 days].
- Payment records: as long as tax and accounting law requires, typically [7 years].
- Moderation records: kept after account deletion so that enforcement history and appeals remain accurate.
- Child-safety reports and related evidence: one year, as required by 18 U.S.C. §2258A.
7. Your rights and controls
- Export: download your posts and images from settings at any time.
- Delete: delete individual posts, or your whole account, from settings on the web or in the app.
- Correct: edit your profile and account details at any time.
- Control federation and AI opt-out: choose how much of each post is delivered to other servers, and whether we send machine-readable opt-out signals to AI crawlers (on by default).
- Notifications: turn email and push notifications on or off in settings.
If you are in the European Economic Area, the United Kingdom, or another region with data-protection rights, you can also ask us to restrict processing or object to it, and you may complain to your local authority. Write to [privacy@zsaso.com]. [If EU users become significant, appoint an EU representative and name them here.]
8. Children
Zsaso is not for children under 13, and we do not knowingly collect information from them. If you believe a child under 13 has an account, contact [privacy@zsaso.com] and we will remove it.
9. Security
Connections are encrypted (HTTPS). We use passwordless sign-in (email links and passkeys) so there is no password to steal. Access to production data is limited to the people who need it to run the service. No system is perfectly secure; if we learn of a breach affecting your data, we will tell you.
10. Changes
We'll notify you of material changes before they take effect. The version and effective date are at the top of this document.
11. Contact
[Operator legal name] [Address] [privacy@zsaso.com]