Privacy policy
1. Who we are
Wordfolk is the controller of the personal data described here, meaning we decide why and how it is used.
This policy explains what we collect when you use Wordfolk, why we have it, who else sees it, how long we keep it, and what you can ask us to do about it. It is written to be read rather than to be defensible, so where we do something that is less than ideal, it says so.
One thing Wordfolk does not do, stated plainly because it is the usual reason a directory collects data: we do not track you for advertising. Some pages carry a sponsored image, always labelled as such: there is no ad network embedded in these pages, we pass nothing about you to the sponsor, and we build no advertising profile of you. Our fonts are served from our own servers. Blog icons and sponsored images come from our image host, listed below, and a few forms load the bot check; apart from those, a page loads nothing from another company.
We may use a measurement tool to understand which pages are read and which links are followed. If and when we do, it will be described in this policy and in the cookie policy before it starts, and if it needs your consent we will ask for it rather than assume it.
2. What we collect
What you give us
- Account details. Your name, email address and a password, which is stored only as a hash. Optionally a short bio and a choice from a fixed set of illustrated avatars. There is no image upload anywhere on Wordfolk.
- Submissions. The name, address, description and category of any blog you submit. The blog's public page shows your display name as the person who submitted it. A guest-post listing additionally carries a contact name and email address for the blog's owner: the contact name is shown to everyone, and the email address only to signed-in members.
- Messages. Anything you send through the contact form, and the name and email you send it with.
- Reports. Which listing or comment you reported, the reason, and an optional note.
- Comments. What you write on a blog's page, when you wrote it, and when you last edited it. Comments are public and show your name and avatar.
- Newsletter signups. Just the email address.
What we record as you use the site
- Sign-in sessions. Each session stores the IP address and browser user-agent it was created from, so that a session can be recognised and, if necessary, revoked.
- Server logs. Each request to the site is logged with the time, the page asked for, the browser user-agent and an IP address cut down to its network prefix, so that faults and abuse can be diagnosed. One-time codes in a link, such as a password reset or an email confirmation, are blanked out before the line is written.
- Saves and endorsements. Which blogs you saved, and which you endorsed. Saves are private to you; an endorsement contributes to a public count.
- Outbound clicks. When you follow a link to a listed blog, or a sponsored link, we count the visit. We do not store your IP address for this. We store a keyed hash of it, combined with the date and the link you followed, which lets us count each visitor once per link per day. Because the date and the link are part of the hash, the same person produces a different value on another day or for another link, so these records cannot be joined into a history of what you clicked. The key is a secret we hold; the hash is not designed to be reversed, and we never attempt to.
- Search terms. What is typed into the site's search box is recorded with the number of results it found and the time, and nothing that links it to you or your account, so that we can see what people look for and do not find.
- Administrative records. Actions that change something meaningful (a submission approved, a category renamed, an account created or closed) are written to an audit log. See the retention section, because this one behaves differently from everything else.
What we deliberately do not collect
No date of birth, no card details, no advertising identifiers, and no data bought from anyone else. We ask for a phone number or postal address in one place only: a formal copyright notice or counter-notice has to include them, as the content removal policy explains, and a counter-notice's contact details are passed to whoever sent the original notice so that they can respond.
3. Why we use it, and our lawful basis
Under UK and EU data protection law we have to name a lawful basis for each use. Ours are:
| What we do | Why | Lawful basis |
|---|---|---|
| Run your account and keep you signed in | You cannot submit, save or buy without one | Performance of a contract |
| Verify your email address | To confirm the address is yours, and to keep out throwaway accounts | Performance of a contract |
| Review and publish your submissions | It is the service you asked for | Performance of a contract |
| Take payment for a Featured placement | You bought one | Performance of a contract |
| Send service emails you turned on | You chose to receive them | Consent, withdrawable at any time |
| Send the newsletter | You signed up and confirmed your address | Consent, withdrawable at any time |
| Count outbound clicks | So listed blogs and sponsors can be shown how much traffic they get | Legitimate interests |
| Rate-limit requests and run the bot check | To keep the site up and spam out | Legitimate interests |
| Keep the administrative audit log | To be able to explain and undo a moderation decision | Legitimate interests |
| Keep payment records | Tax and accounting law requires it | Legal obligation |
Where we rely on legitimate interests, we have weighed them against your rights, and you can object; see your rights below.
We do not sell personal data, we do not share it for advertising, and we do not profile you.
4. Cookies and local storage
Wordfolk sets cookies only to keep you signed in. There are no advertising cookies and nothing that follows you to another site, which is why you have not been asked to accept anything: strictly necessary cookies need no consent. If we later set a cookie that does need it, we will ask first.
The full detail, including cookie names, lifetimes, and what the site keeps in your browser's local storage, is in the cookie policy.
5. Who we share it with
We share personal data only with the providers that make the service work. Each of them acts on our instructions, and none may use your data for its own purposes.
| Kind of provider | What it does for us | What it receives |
|---|---|---|
| Hosting and database | Stores the data behind the site | Everything described in this policy that is stored at all |
| Email delivery | Sends our emails, and holds the newsletter list | Your email address, your name, and the content of the message being sent |
| Payments | Takes payment for Featured placements, as merchant of record | Your name, email address, and the details of the placement being bought. Card details go to it directly and never reach us |
| Bot protection | Runs the check on our public forms | The check's own token and your IP address |
| Image hosting | Stores and serves blog icons and sponsored images | The address of a submitted blog, so its icon can be fetched. When your browser loads one of these images, the host receives your IP address and browser details, as any web server does |
That list is complete: there is no sixth kind of provider left off it. We describe them by what they do rather than by name, which is what data protection law asks for and which keeps the specifics of a small operation's infrastructure out of a public page. If you want to know which company sits behind any row, ask us and we will tell you. We will also tell you before adding a new one that handles personal data.
Beyond that list, we disclose personal data only where the law requires it, where it is necessary to establish or defend a legal claim, or where we are investigating a serious breach of our terms. If Wordfolk is ever sold or transferred, personal data would move with it, and we would tell you first.
6. How long we keep it
We keep personal data for as long as we need it for the purpose we collected it, and no longer, except where the law requires otherwise.
| What | How long |
|---|---|
| Account details | Until you close your account |
| Sign-in sessions, with IP address and browser | Until 7 days after you last used the site, then deleted |
| Blogs and guest-post listings you submitted | Indefinitely, but detached from you when you close your account |
| Saved and endorsed blogs, and notifications | Until you close your account, then deleted |
| Payment records | At least 7 years, as tax and accounting law requires |
| Reports you filed about a listing | Indefinitely, detached from you when you close your account |
| Reports you filed about a comment | Until the comment is removed, detached from you when you close your account |
| Server access logs, with a shortened IP address | Up to 30 days, then deleted |
| Search terms, with nothing linking them to you | Indefinitely |
| Outbound click counts | Indefinitely. Stored as a keyed hash that changes every day and differs for every link, so the records cannot be joined into a history of what you clicked |
| Administrative audit records | Indefinitely; see the note below |
The audit log, stated honestly
Our administrative audit log is append-only: nothing in it is ever edited or deleted automatically, and there is no scheduled job that trims it. Records of moderation decisions, and of account events such as sign-up and closure, therefore survive the closure of the account they refer to. For an account event the record includes the email address the event concerned.
We keep it that way because a moderation decision has to remain explainable after the fact, including once the account involved is gone. It is a genuine limit on what closing an account achieves, so it belongs here rather than in a footnote. If you ask us to erase your data, we remove your name from those records by hand; ask us and we will confirm when it is done.
7. What closing your account does
You can close your account from your account settings. We email you a confirmation link first, and nothing is deleted until you follow it.
What closing your account removes
- Your name, email address, bio and avatar choice.
- Your password.
- Every sign-in session, including the IP addresses and browsers they recorded.
- Your saved blogs, your endorsements, and your notifications.
- Your comments, along with any replies other people made to them.
What it does not remove
- Blogs and guest-post listings you submitted that we published. They stay in the directory and are detached from you, so nothing connects them to your account any more. A guest-post listing also carries the owner contact details that were submitted with it, which are part of the listing rather than part of your account. If you want a listing taken down as well, ask us; see content removal.
- Payment records. Tax and accounting law requires us to keep these; they are detached from your account.
- Reports you filed. Detached from you, so the moderation history survives.
- Administrative audit records, as described above.
Backups are kept for a limited period and overwritten in rotation, so data can persist there briefly after deletion. We do not restore a backup to recover deleted personal data.
There is no self-service data export. We would rather say so than imply otherwise: if you want a copy of your data, email us and we will put one together by hand.
8. Your rights
If UK or EU data protection law applies to you, you have the right to:
- Access: get a copy of the personal data we hold about you.
- Rectification: have anything inaccurate corrected. Your name and bio you can edit yourself; your email address can be changed from settings, and we confirm the change by email first.
- Erasure: have your data deleted, subject to the records described above that we are required or entitled to keep.
- Restriction: ask us to stop using your data while a dispute about it is resolved.
- Portability: receive the data you gave us in a machine-readable form.
- Objection: object to any use we base on legitimate interests.
- Withdraw consent: turn off any email at any time from your notification settings, or unsubscribe from the newsletter using the link in it. Withdrawing consent does not affect anything sent beforehand.
Exercise any of these by emailing us. We do not charge for it, and we will respond within one month. We may ask you to confirm your identity first, so that we do not hand your data to somebody else.
You are not subject to any automated decision-making that produces legal effects, because we do not do any.
9. California privacy rights
If you live in California, the CCPA gives you the right to know what personal information we collect and why, to request a copy of it, to request its deletion, to correct it, and not to be discriminated against for exercising any of those rights. The sections above describe the categories we collect and the purposes we use them for.
We have not sold or shared personal information for cross-context behavioural advertising, and we do not intend to. There is nothing to opt out of: sponsored images here are not targeted at you, and nothing about you is passed to a sponsor.
To make a request, email us. You can use an authorised agent, in which case we will ask for proof of their authority.
10. Children's data
Wordfolk is not intended for children. You must be at least 16 to hold an account, and we do not knowingly collect personal data from anyone younger.
We do not ask for a date of birth, so this is a rule rather than a check. If you believe a child has given us personal data, tell us and we will delete it and close the account.
11. How we protect it
The measures that affect you directly, described at the level a reader needs:
- Traffic between your browser and the site is encrypted, and so is the connection to where the data is stored.
- Passwords are stored only as hashes. Nobody here can read yours, and we will never ask you for it.
- Session cookies are set so that scripts in the page cannot read them, and are marked secure in production.
- An email address has to be verified before it can be used to sign in, and disposable-mailbox domains are refused.
- Sign-in, sign-up and password reset are rate-limited, and public forms carry a bot check.
- Access to anything private is checked on the server before a page is built, rather than hidden in the browser after the fact.
We deliberately stop short of describing our infrastructure in detail here. A precise account of how a site is built is more useful to somebody attacking it than to somebody reading a privacy policy, and the specifics change. If you are assessing us as a supplier and need more than this, write to us and we will answer properly.
No service can promise perfect security. If we discover a breach that puts your rights at risk, we will tell the relevant authority within 72 hours and tell you without undue delay.
12. Changes to this policy
We may update this policy as the service changes or the law does. The date at the top shows when the current version took effect.
If a change materially affects how we use personal data you have already given us, we will tell signed-in members by email before it takes effect rather than relying on you to re-read this page.
13. Contact
Privacy questions, or any request under the rights above: hello@wordfolk.app.