Privacy Policy
Effective date: July 9, 2026
This Privacy Policy explains how Sociory ("Sociory," "we," "us," or "our") collects, uses, and shares information when you use Sociory and its associated services (the "Service"). It is written to comply with applicable data protection law, including the EU General Data Protection Regulation ("GDPR") where applicable.
1. Information We Collect
| Category | Examples |
|---|---|
| Account information | Email address, password (stored only as a salted hash), chosen handle, optional display name |
| Content you create | Posts, articles, comments, uploaded files, and other content you create, and their associated metadata (title, type, visibility). Images you embed in posts, comments, or articles are uploaded to our file servers before the post is saved — including on posts you mark as private or unlisted. The resulting image URL is unguessable but is not separately access-controlled; the post's own visibility setting still restricts who can see the post and its image link |
| Organization & identity data | Organizations and identities you create or join, and your membership/role within them |
| Private messages | The content of direct and group messages you send and receive, conversation membership, and your messaging preferences (who can message you, people you have blocked from messaging you) |
| Security & login data | IP address and timestamp at login/signup, retained briefly for abuse detection (see "Retention" below) |
| API key metadata | Key name and assigned scopes (the raw key itself is shown to you once and never stored) |
| Cookies | A single strictly-necessary session cookie used to keep you signed in |
| Aggregate usage data | Anonymous, non-identifying counts of actions taken on the Service (e.g. signups, content created) used for internal product analytics — not linked to your account or identity |
2. How We Use Information
- To create and maintain your account and authenticate you across Sociory's services;
- To provide, operate, and maintain the Service, including storing and serving content you create;
- To deliver private messages between you and the other participants of your conversations, and to review conversations that a participant reports to us for abuse;
- To send transactional emails, such as email verification and password reset messages;
- To detect, investigate, and prevent fraud, abuse, and security incidents;
- To understand aggregate usage trends and improve the Service;
- To comply with legal obligations.
We do not sell your personal information.
3. Legal Basis for Processing (GDPR)
- Contractual necessity — your email, password, and handle are required to create and operate your account, and message content is stored and delivered as the core function of the messaging feature you choose to use;
- Consent — your display name and any other optional, free-text information you choose to provide;
- Legitimate interest — short-term login/IP logging for fraud and abuse prevention;
- Legal obligation — where we are required to retain or disclose information by law.
4. Cookies
We use a single session cookie that is strictly necessary to keep you signed in across Sociory's services. It is not used for advertising or cross-site tracking, and is exempt from cookie-consent requirements under the ePrivacy Directive as a strictly-necessary cookie.
5. How We Share Information
We do not share your personal information with third parties except:
- With service providers who process data on our behalf solely to operate the Service (for example, our transactional email provider, used only to deliver verification and password-reset emails);
- With the other participants of a private conversation, who see the messages you send into it — and, if any participant reports a conversation for abuse, with our moderation review of that conversation;
- When you choose to make content public or unlisted, which makes that content (and, if you opt in, your public author handle) visible to anyone with access to it;
- When required to comply with applicable law, legal process, or to protect the rights, property, or safety of Sociory, our users, or the public;
- In connection with a merger, acquisition, or sale of assets, subject to this Policy continuing to apply to your information.
6. Data Retention
- Account information is retained for as long as your account is active.
- Private messages are retained until you remove them: an "unsend" (available for a short window after sending) removes a message for all participants, and "delete for me" removes it from your own view. Because a conversation belongs to all of its participants, deleting your account anonymizes your identity on past messages rather than removing them from other participants' copies.
- Login/IP records used for abuse detection are retained for 30 days and then automatically deleted.
- Expired sessions are purged automatically.
- Anonymous, aggregate usage events are retained for up to 90 days before being deleted, with daily summary totals retained longer in fully aggregated form.
- Email verification and password reset links expire and are purged automatically once used or expired.
7. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, export, or request deletion ("erasure") of your personal information, and to object to or restrict certain processing. To exercise any of these rights, contact us using the details below. We will verify your request and respond within the time required by applicable law.
When you request erasure, we will remove or irreversibly anonymize your identifying information (such as your email, password, and display name) from our systems, retaining only the minimum necessary to keep previously published content functional (e.g. replacing your handle on existing content with a generic placeholder).
8. International Data Transfers
Our infrastructure may be located outside of your country of residence, including outside the European Economic Area. Where this involves a transfer of personal data from the EEA, we will rely on appropriate safeguards as required by applicable law.
9. Children's Privacy
The Service is not directed to anyone under 18, and we do not knowingly collect personal information from anyone under that age. If you believe a child has provided us with personal information, please contact us so we can delete it.
10. Security
We use measures such as encrypted password storage, encrypted connections (HTTPS), and access controls to protect your information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Private messages are private between the participants of a conversation, but they are not end-to-end encrypted: they are protected in transit by HTTPS and by access controls on our systems, and our operations personnel can technically access message content, which we do only for handling abuse reports, security incidents, or legal obligations. We are deliberately transparent about this rather than overstating the privacy of messages.
Images attached to private messages are stored separately from post images and are access-controlled: they can only be retrieved by a validated participant of the conversation they were sent in, or by Sociory staff for the same limited purposes described above.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Effective date" above. Your continued use of the Service after changes take effect constitutes acceptance of the revised Policy.
12. Contact Us
For questions about this Privacy Policy or to exercise your privacy rights, contact us at privacy@sociory.com.