Sociory

Privacy Policy

Effective date: July 9, 2026

This Privacy Policy explains how Sociory ("Sociory," "we," "us," or "our") collects, uses, and shares information when you use Sociory and its associated services (the "Service"). It is written to comply with applicable data protection law, including the EU General Data Protection Regulation ("GDPR") where applicable.

1. Information We Collect

CategoryExamples
Account information Email address, password (stored only as a salted hash), chosen handle, optional display name
Content you create Posts, articles, comments, uploaded files, and other content you create, and their associated metadata (title, type, visibility). Images you embed in posts, comments, or articles are uploaded to our file servers before the post is saved — including on posts you mark as private or unlisted. The resulting image URL is unguessable but is not separately access-controlled; the post's own visibility setting still restricts who can see the post and its image link
Organization & identity data Organizations and identities you create or join, and your membership/role within them
Private messages The content of direct and group messages you send and receive, conversation membership, and your messaging preferences (who can message you, people you have blocked from messaging you)
Security & login data IP address and timestamp at login/signup, retained briefly for abuse detection (see "Retention" below)
API key metadata Key name and assigned scopes (the raw key itself is shown to you once and never stored)
Cookies A single strictly-necessary session cookie used to keep you signed in
Aggregate usage data Anonymous, non-identifying counts of actions taken on the Service (e.g. signups, content created) used for internal product analytics — not linked to your account or identity

2. How We Use Information

We do not sell your personal information.

3. Legal Basis for Processing (GDPR)

4. Cookies

We use a single session cookie that is strictly necessary to keep you signed in across Sociory's services. It is not used for advertising or cross-site tracking, and is exempt from cookie-consent requirements under the ePrivacy Directive as a strictly-necessary cookie.

5. How We Share Information

We do not share your personal information with third parties except:

6. Data Retention

7. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, export, or request deletion ("erasure") of your personal information, and to object to or restrict certain processing. To exercise any of these rights, contact us using the details below. We will verify your request and respond within the time required by applicable law.

When you request erasure, we will remove or irreversibly anonymize your identifying information (such as your email, password, and display name) from our systems, retaining only the minimum necessary to keep previously published content functional (e.g. replacing your handle on existing content with a generic placeholder).

8. International Data Transfers

Our infrastructure may be located outside of your country of residence, including outside the European Economic Area. Where this involves a transfer of personal data from the EEA, we will rely on appropriate safeguards as required by applicable law.

9. Children's Privacy

The Service is not directed to anyone under 18, and we do not knowingly collect personal information from anyone under that age. If you believe a child has provided us with personal information, please contact us so we can delete it.

10. Security

We use measures such as encrypted password storage, encrypted connections (HTTPS), and access controls to protect your information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Private messages are private between the participants of a conversation, but they are not end-to-end encrypted: they are protected in transit by HTTPS and by access controls on our systems, and our operations personnel can technically access message content, which we do only for handling abuse reports, security incidents, or legal obligations. We are deliberately transparent about this rather than overstating the privacy of messages.

Images attached to private messages are stored separately from post images and are access-controlled: they can only be retrieved by a validated participant of the conversation they were sent in, or by Sociory staff for the same limited purposes described above.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Effective date" above. Your continued use of the Service after changes take effect constitutes acceptance of the revised Policy.

12. Contact Us

For questions about this Privacy Policy or to exercise your privacy rights, contact us at privacy@sociory.com.