Legal

Privacy

This page is a structural draft. Its statements have not been reviewed against the project's operational reality.

Draft — pending operational and legal review

Nothing on this page has been approved. It exists so a reviewer can see the intended shape and depth of the privacy page. Any statement about data collection, retention, processors or legal bases must be replaced with verified operational fact before publication.

What this page will cover

  • What the project website itself collects, if anything, and why.
  • What the Syndroo software processes when a self-hoster runs it on their own account.
  • Where data is stored, who processes it, and for how long.
  • How to request access, correction or deletion of personal data.
  • How changes to the policy are announced and dated.

The project website

This site is a static prototype. As built, the pages load local files only, and the interactive demonstration runs in the browser without sending anything to a server. No account system, newsletter form or analytics script is included in this prototype.

If the published site later adds analytics, hosting logs with retention, or an email form, this section must describe them explicitly, including purpose, legal basis and retention period. Until then, no such statement should be inferred from this draft.

The Syndroo software

Syndroo is self-hosted software. When you deploy it, the Worker runs in your own Cloudflare account and stores post and publication records in your own D1 database. Platform credentials are Worker secrets that you configure. The project does not operate a hosted service in this version, does not receive a copy of your database, and cannot read your credentials.

Because the deployment belongs to the person running it, the operator of that deployment is responsible for the data it holds, including any personal data in post content, API keys and platform credentials.

Platforms and third parties

Publishing sends content and credentials to the social platform you configured. Each platform applies its own terms and privacy policy to that data. A self-hoster who enables a platform should tell their users what is sent and to whom.

Contact

Privacy questions about the project itself belong in GitHub Issues, alongside bug reports and feature requests. A dedicated contact route and a controller address have not been decided, and neither is invented here.

Status of this draft

This draft carries no effective date and no approval. Operational details and legal review are required before this page is published as an approved policy, and it should not be relied on for compliance purposes in the meantime.