Privacy Policy
Last updated: April 2026
1. Who We Are
This CommonPub instance is operated by its administrator (the "data controller"). CommonPub is powered by CommonPub, an open-source, self-hosted platform. Each instance is independently operated and responsible for its own data processing.
2. What Data We Collect
When you create an account, we collect:
- Account data: email address, username, password (stored as a secure hash)
- Profile data: display name, bio, headline, location, website, avatar, banner image, social links, skills, pronouns, timezone (all optional)
- Content: projects, articles, comments, and other content you create
- Activity data: likes, follows, bookmarks, hub memberships, learning path enrollments
- Messages: direct messages you send to other users on this instance
We also automatically collect:
- Session data: IP address and browser user agent when you log in, stored for the duration of your session (up to 7 days)
- Theme preference: your light/dark mode choice, stored in your browser's local storage
3. How We Use Your Data
- Providing the service: displaying your profile, publishing your content, delivering notifications
- Authentication: verifying your identity when you log in
- Security: protecting against unauthorized access, abuse, and spam
- Email notifications: sending notification digests and alerts you've opted into (configurable in settings)
4. Legal Basis for Processing
We process your data under the following legal bases (GDPR Article 6):
- Contract performance (Art. 6(1)(b)): processing necessary to provide you with the service you signed up for
- Legitimate interest (Art. 6(1)(f)): session security, rate limiting, and preventing abuse
5. Cookies
We use a small number of cookies to provide and improve the service:
- Session cookie (
better-auth.session_token): strictly necessary — authenticates your login session. HttpOnly, secure, 7-day expiry. - Consent cookie (
cpub-consent): strictly necessary — stores your cookie consent choice. - Color scheme (
cpub-color-scheme): functional — remembers your light/dark mode preference. Set only with your consent.
We do not use any advertising or tracking cookies. Your instance operator may add analytics cookies — these require your explicit consent. For the full list of cookies and to manage your preferences, visit our Cookie Policy.
6. Federation and ActivityPub
This instance participates in the ActivityPub federation protocol. When you publish content or interact publicly, the following data may be shared with remote instances:
- Your username, display name, avatar, and bio
- Your published content (projects, articles, explainers)
- Your public interactions (likes, follows, comments on federated content)
Your email address, location, social links, timezone, and other private profile fields are never shared via federation.
Important: Once your data is federated to remote instances, this instance cannot guarantee its deletion on those servers. Remote instances operate independently and may retain cached copies of your public data even after you delete your account here.
7. Third-Party Services
We load icon fonts from Font Awesome via the Cloudflare CDN (cdnjs.cloudflare.com). This means your browser makes requests to Cloudflare's servers, which are subject to Cloudflare's privacy policy.
We do not use any analytics services, advertising networks, or tracking technologies.
8. Data Retention
- Account data: retained until you delete your account
- Session data: automatically expires after 7 days of inactivity
- Content: retained until you delete it or delete your account
- Audit logs: retained per the instance operator's policy
9. Your Rights
Under the GDPR and similar data protection laws, you have the right to:
- Access: view the data we hold about you (via your profile and settings)
- Rectification: update or correct your data (via your profile settings)
- Erasure: delete your account and all associated data (via account settings)
- Portability: download your data in a machine-readable format (via account settings)
- Restriction and objection: contact the instance administrator
To exercise these rights, visit your account settings or contact the instance administrator.
10. Contact
For privacy-related inquiries, contact the administrator of this CommonPub instance.