Legal
Privacy Policy
Effective April 15, 2026
Note: This draft has not been reviewed by counsel and should not be published as a final policy without attorney review. Internal marker: TODO legal review
The short version
We collect as little as possible. We don't run ads. We don't sell data. We don't track you across the web. The contact form sends your message to our inbox and nothing else. The payment processor handles billing; we don't store card numbers.
Structural privacy — the kind baked into how the app works rather than promised in a policy — is described at /privacy. This document covers the legal specifics.
Who we are
SocialWeb is operated by Social Web Cloud LLC, a company incorporated in Oregon, USA. Our contact address is support@socialweb.cloud.
What we collect
Account information. When you create an account, we collect your email address and a password hash. We do not collect your name, phone number, or address unless you provide them in the contact form.
Contact form submissions. When you use the contact form at /contact, we receive your name, email address, and message. This data is delivered to our inbox via Resend (our email delivery provider) and retained as email correspondence.
Subscription billing. When you subscribe to a paid plan, billing is handled by our payment processor. We receive a customer identifier and subscription status from the processor but do not store full card numbers or payment details on our servers. {{TODO: payment processor}} — confirm payment processor name for disclosure here.
Self-hosted instances. If you self-host SocialWeb, we collect no data about your usage. All data lives on your hardware.
App usage. The SocialWeb app does not report reading activity, subscription lists, or search queries to our servers beyond what is functionally required to fetch RSS feeds and proxy searches on your behalf. We do not log which articles you read or how long you spent on them.
Server logs. Our web servers and hosting provider retain standard HTTP access logs (IP address, timestamp, URL requested, response code) for a limited period for security and debugging purposes. These are not linked to user accounts.
What we do not collect
We do not place tracking cookies on your device. We do not use analytics services (Google Analytics, Mixpanel, Segment, or similar). We do not embed third-party advertising scripts. We do not run fingerprinting or cross-site tracking. This website makes no third-party network requests; you can verify this in your browser's Network panel.
How we use what we collect
Account information is used to authenticate you and send account-related emails (password reset, subscription receipts). We do not use your email address for marketing without your explicit opt-in.
Contact form submissions are used solely to respond to your message. We do not add you to any mailing list as a result of submitting the form.
Server logs are used to diagnose errors and detect abuse. They are retained for a limited time and then deleted.
Third-party services
Resend. We use Resend (resend.com) to deliver contact form submissions to our inbox. Resend processes the name, email, and message you submit. Their privacy policy governs their handling of that data.
Hosting. SocialWeb's infrastructure runs on DigitalOcean. DigitalOcean processes network traffic and stores our application data under their data processing agreement.
Payment processor. {{TODO: payment processor — add name and privacy policy link once confirmed before launch.}}
We do not use any other third-party services that process your personal data. We have no relationship with Google, Meta, Amazon, or advertising networks.
RSS fetching and proxied search
When you subscribe to an RSS source in SocialWeb, our servers fetch that feed on your behalf. The publisher receives a request from SocialWeb's servers, not from your device or IP address. We do not retain a permanent log of which sources you subscribe to beyond what is functionally required to deliver the feed to your device.
When you perform a web search in SocialWeb, the query is routed through our servers before reaching a search provider. The search provider receives the query from SocialWeb's network, not from you. We do not log your search history beyond transient server logs.
Data retention
Account data is retained as long as your account is active. If you delete your account, we delete your email address and subscription data within 30 days, subject to legal holds.
Contact form submissions are retained as email correspondence for a reasonable business period.
Server logs are retained for a limited period (typically 30–90 days) and then deleted.
Self-hosted users: we have no copy of your data. Deletion is entirely under your control.
Your rights
You may request a copy of the personal data we hold about you, correction of inaccurate data, or deletion of your account and associated data by emailing support@socialweb.cloud.
If you are a resident of the European Economic Area or California, additional rights may apply under GDPR or CCPA respectively. {{TODO: legal review required — confirm jurisdiction-specific obligations.}}
Children
SocialWeb is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe we have inadvertently collected such data, please contact us immediately.
Changes to this policy
If we make material changes to this policy, we will notify registered users by email and update the effective date at the top of this page. Continued use of SocialWeb after the effective date constitutes acceptance of the updated policy.
Contact
Questions about this policy? Email support@socialweb.cloud. For security disclosures, see our security page.