Privacy Policy
Last updated: April 2026
1. Who we are
Commonplace is a self-hosted instance of Commonplace software. The instance operator is responsible for data processing on this instance. Contact the operator via the report form for privacy enquiries.
2. What data we store
When you log in, we store:
- Your handle, display name, and avatar URL from your identity provider
- A session token (stored as a one-way hash) with a 30-day expiry
- The collections and resources you create
- The timestamp of your consent and last activity
We do not store your password. We do not store your upstream OAuth access token in plain text — it is encrypted at rest using AES-256-GCM.
If you interact with a collection via the Fediverse (e.g. following a collection or submitting a proposal via mention) without logging in explicitly, we may store your public actor URI and display name under the legitimate interest lawful basis (Article 6(1)(f) GDPR). This data is limited to information you have already made public on your home server.
3. Lawful basis
For logged-in users: processing is based on your explicit consent given at the time of first login (Article 6(1)(a) GDPR). You may withdraw consent at any time by deleting your account.
For federated-only interactions: processing is based on legitimate interest to operate a federated service (Article 6(1)(f) GDPR).
4. Data sharing
Public collections and resources are shared with followers via ActivityPub (Fediverse) and AT Protocol (Bluesky). Once delivered to another server, that server's privacy policy applies to the copy they hold.
We do not sell data. We do not use third-party analytics. There are no advertising networks.
5. Your rights
Under GDPR (if applicable to you), you have the right to:
- Access the data we hold about you — contact the operator
- Erasure — delete your account at account settings; this hard-deletes your identity record and soft-deletes your content
- Portability — request a JSON export of your data from the operator
- Object to processing based on legitimate interest
6. Retention
Session tokens expire after 30 days. Soft-deleted content is hard-deleted after 30 days by the data retention worker. Federated-only identity records are retained as long as they are associated with active follows or proposals.
7. Security
Data is stored in an encrypted SQLite database. OAuth credentials are encrypted at rest. Sessions use HttpOnly, SameSite=Lax cookies. HTTPS is enforced with HSTS on production deployments.
8. Contact
For privacy enquiries, data access requests, or to exercise your rights, use the contact form and select the relevant category.