privacy 🍃
the short version: we don't track you, we don't sell anything about you, and public pages set zero cookies. here's the long version.
who we are
controller in the sense of the GDPR: Robert Madocsa Kiss, Dettelbacher Weg 19, 13189 Berlin, reachable at hello@cutecumber.cc.
what we process, and why
your account: your email address and a salted hash of your password (we never store the password itself). legal basis: performance of contract, Art. 6 (1)(b) GDPR — it's how your login works.
your page: the username, display name, bio, pronouns, links and theme you choose to publish. you put this here to be public; it's visible to anyone with the link.
password reset emails: if you request one, your email address is passed to our email delivery provider, Resend (Resend, Inc., USA), solely to deliver that one email. transfer to the USA is safeguarded by the EU Standard Contractual Clauses and Resend's certification under the EU–US Data Privacy Framework.
server logs: our host processes technical request data (such as IP addresses) for security and operation. legal basis: legitimate interest, Art. 6 (1)(f) GDPR. hosting provider: fly.io, Frankfurt Region, Germany.
what we deliberately don't do
no analytics scripts, no advertising pixels, no third-party requests, and no cookies of any kind on public profile pages — for anyone, ever. the only cookie we set at all is a session cookie when you log in to edit your own page, and it does exactly that one job.
how long we keep things
your data stays as long as your account exists. you can delete your account yourself at any time from your account page — it removes your page, your links, and your account data immediately. you can also email hello@cutecumber.cc if you prefer. password reset tokens expire after one hour.
your rights
under the GDPR you have the right to access, rectification, erasure, restriction of processing, data portability, and objection, plus the right to lodge a complaint with a supervisory authority. just write to the contact address above.