./privacy
What we keep, and how to make us stop
Short, in plain words, and it stays that way. Last changed when this site launched.
01
What we store
- If you RSVP: your name, email, optionally what you make and a note. That is so we can count chairs and email you once before the event.
- If you have a card and claim it: a handle, a display name, an argon2id hash of your password, optionally an email, plus whatever you choose to put on your profile and post to the feed.
- A session cookie, so the site knows it is you. It is not used for tracking and there is no third party in it.
02
What we do not do
- No analytics scripts, no advertising pixels, no third-party trackers, no fingerprinting. There is no cookie banner on this site because there is nothing to consent to.
- We do not sell, rent, share or "partner" your data with anyone. There is nobody to sell it to who we would want to be in a room with.
- We do not email you anything you did not ask for. One reminder per event you RSVPd to, and that is the whole programme.
03
Who can see your profile
- The member directory and the feed are behind the login. They are not indexed by search engines and are not visible to anyone without an account.
- Accounts only exist for people who were handed a physical card at an event, which is a much stronger door than an email confirmation.
- Anything you post is visible to every other member. Assume the room can read it, because the room can.
04
Getting rid of it
- Email hello@localahole.network from the address on your account, or ask any organiser in person, and we will delete your account, your posts and your RSVPs. No retention window, no exit survey, no "are you sure" three times.
- Ask for an export and you get a JSON file of everything attached to you.
- Deleting your account does not un-issue your physical card. Come get a fresh one if you change your mind.
05
The honest bits
- This site is hosted on commercial infrastructure, which means our hosting provider and database provider technically process this data on our behalf. Their names are in the deployment notes and we will tell you who they are if you ask.
- We are a small studio, not a security company. We have done the things that matter — hashed passwords, hashed card codes, session tokens the database cannot read back, no third-party scripts — and we would rather tell you where the limits are than imply there are none.
- If you find a hole, email security@localahole.network. We will fix it, credit you if you want, and buy you a drink at the next one.