Privacy
CUDump Privacy Policy
Draft notice: controller and authority details shown in brackets must be completed before public launch.
This policy explains what personal data CUDump processes, why it is used, who helps provide the service and what choices and rights may apply to you.
1. Controller
- Controller
- [FULL LEGAL NAME]
- Address
- [POSTAL ADDRESS]
- Privacy contact
- [LEGAL CONTACT EMAIL]
Further provider information is available in the Imprint.
2. Data we process
Account and profile
- email address, authentication and account identifiers, username, timestamps and account status;
- chosen emoji avatar, avatar background, bio and joined date.
Content and interactions
- posts, comments, replies, post type, manually selected location tags and hashtags;
- votes and reactions.
Ghost Mode
Ghost content and the private internal ownership relationship needed for authorization, security and moderation.
Moderation
Reports, report explanations, moderation actions, suspension or ban status, public reasons, internal moderator notes, audit records and audited Ghost-identity access.
Technical and security data
Error codes, random incident reference IDs, request route and status information, and technical server or application logs produced by CUDump and its infrastructure providers. CUDump does not use a post location tag as device geolocation and does not intentionally collect GPS location, device contacts, government IDs, payment data, health data or advertising profiles.
3. Purposes and legal bases
We process personal data for the following purposes and legal bases:
- Contract performance (Article 6(1)(b) GDPR): creating and managing your account, authenticating you, and providing the feeds, profiles, posts, comments, interactions and settings you request.
- Legitimate interests (Article 6(1)(f) GDPR): securing CUDump, preventing abuse, fraud and spam, moderating content, enforcing platform rules, maintaining service integrity, diagnosing technical errors, and retaining private Ghost ownership while it is needed for ownership controls, security and moderation. These interests support a safe and reliable community service.
- Legal obligations (Article 6(1)(c) GDPR): where processing is necessary to comply with a specific legal duty.
- Consent (Article 6(1)(a) GDPR): only where CUDump specifically asks for consent for an optional purpose. The Privacy Policy itself is a notice, not blanket consent.
Where a legitimate-interest basis is used, the need for the processing is weighed against the affected person's rights and interests.
4. Ghost Mode privacy
Ordinary users cannot see the real account behind Ghost content. Ghost content does not appear on the account's public profile and has no persistent public alias. CUDump privately keeps the ownership relationship to operate edit and deletion permissions, protect the service and conduct moderation.
Authorized administrators or the owner role may resolve Ghost ownership for a legitimate moderation investigation. Reveals are restricted and audited. Ghost activity does not contribute to Aura. Ghost Mode hides your public CUDump identity; it does not promise absolute anonymity. Read more at How Ghost Mode works.
5. Pseudonymous visibility
Active usernames, profiles and ordinary user content are visible to authenticated CUDump users. Ghost content hides the public author identity. A pseudonymous username can still be personal data and does not necessarily make a person anonymous under data-protection law.
6. Account and content deletion
When you delete your account, the authentication account is deleted, the active public profile disappears and the profile record is anonymized. The old username is released; identifying bio and custom avatar details are cleared; and votes and reactions made by the account are removed.
Normal posts and comments remain under a generated former_user_... identity to
preserve discussions. Ghost content remains Ghost and is not connected publicly to that
former-user label. You may delete individual content before deleting your account. You may
also make an additional erasure request through [LEGAL CONTACT EMAIL]; it will be assessed under
applicable law.
7. Moderation data
Reports and moderation records are processed to investigate reported behavior, protect platform safety, enforce rules, prevent repeated abuse and, where relevant, comply with law or establish, exercise or defend legal claims. Internal moderator notes and audit records are not publicly displayed. Rights of access may be limited where applicable law protects other people, confidential investigations, security information or legal claims.
8. Service providers
CUDump currently uses these infrastructure providers:
- Supabase Pte. Ltd. (Supabase) for authentication, PostgreSQL database, and application backend and data services.
- Vercel Inc. (Vercel) for hosting, deployment and runtime services.
These providers process data under their applicable service terms and data-processing arrangements. Their own websites may have separate privacy practices.
9. International transfers
Providers and their subprocessors may process personal data outside the European Economic Area. Where an international transfer requires safeguards, appropriate mechanisms are relied on as applicable, such as an adequacy decision and/or Standard Contractual Clauses. CUDump does not promise that all processing takes place in Germany.
10. Retention
- Active account information is kept while the account is active and as needed to provide the service.
- On account deletion, identifying authentication and profile data is deleted or anonymized through the account-deletion process described above.
- Retained anonymized discussion content may remain to preserve conversations unless removal is required or a valid request requires a different outcome.
- Moderation and security records are retained only as long as reasonably necessary for safety, enforcement, abuse prevention and legal claims.
- Technical logs are retained according to operational and security needs and provider retention settings.
Concrete periods for moderation records, reports, audit records and technical logs are not yet configured and must be defined before public launch. Retention decisions consider the purpose, sensitivity, security need and applicable legal duties.
11. Cookies and device storage
CUDump currently uses cookies that are necessary for authentication, session security and requested app flows, including a short-lived signup welcome-state cookie. Repository review found no non-essential advertising, analytics or cross-site tracking technology in the application. If that changes, this policy and any consent requirements will be reassessed before use.
12. Your rights
Depending on the circumstances, GDPR rights may include access, rectification, erasure, restriction, data portability, objection, and withdrawal of consent where processing is based on consent. These rights do not apply identically in every situation and may be subject to legal conditions or exemptions.
Send privacy requests to [LEGAL CONTACT EMAIL]. You may also complain to a competent supervisory authority. The authority relevant to the controller must be completed before launch: [COMPETENT DATA PROTECTION SUPERVISORY AUTHORITY].
13. Security
CUDump uses measures intended to protect personal data, including authentication, database-level access controls and Row Level Security, restricted administrative access, separation of Ghost public identity from private ownership, and server-only secrets. No online service can guarantee absolute security.
14. Changes and contact
This policy may be updated as the service or legal requirements change. Significant changes will be communicated where required. Questions can be sent to [LEGAL CONTACT EMAIL].