Legal

Privacy Policy

Draft — not yet in effect. A working draft pending legal review, describing how the Service is built to handle data. Items in [brackets] are placeholders to be completed.

Effective date: [DATE] · Last updated: [DATE]

This policy explains what the Subter identity directory (the “Service”), operated by [Company], collects and how it is used. A plain-language overview is at Your data & privacy.

What we collect

What we do not collect

How we use it

To operate the directory (host and serve your published identity), authenticate you, process subscriptions, enforce the publish-paid / resolve-free model, and secure the Service. We do not sell your data or use it for advertising. The internal link between your account and your published identity is not exposed publicly. [Legal bases, where applicable].

Service providers

We rely on [our authentication provider] for accounts and authentication, [Stripe] for payments, and [our hosting provider] for hosting. These process data on our behalf under their own terms. [Full subprocessor list / DPA references].

Public information

Anything you publish is public and free for anyone to fetch, cache, and re-share. We cannot retract copies others have already downloaded.

Retention & deletion

Deleting your account removes your identity, key event log, and published document from the Service. Account and billing records may be retained as required for legal and accounting purposes. [Retention periods].

Your rights & contact

Depending on where you live, you may have rights to access, correct, or delete your personal data [GDPR / CCPA specifics]. To exercise them, or for any privacy question, contact tubers@subter.app. Children: the Service is not directed to children under [age].

See also the Terms of Service · Help.