The controller of personal data processed through this Service is:
No Data Protection Officer is appointed. For any privacy-related question or request please use the contact email above.
Providing an email address is a contractual requirement. It is necessary in order to conclude the purchase, because the contract, the invoice and any moderation notice are delivered to it. Without an email address the purchase cannot be completed. The name and the URL are entirely optional: leaving them out has no effect on the purchase.
A published message may itself contain personal data of other people. Where it does, we act as the controller of that data as part of hosting the public wall. Anyone whose personal data appears in a published message may ask for it to be removed through the form at /Report.
We process personal data to perform the contract you enter when you buy characters (GDPR Art. 6(1)(b)), to comply with tax and bookkeeping obligations (Art. 6(1)(c)), to comply with our obligations as a hosting service provider under Regulation (EU) 2022/2065, the Digital Services Act (Art. 6(1)(c)), and where relevant to defend against content reports or chargebacks (Art. 6(1)(f)).
Our payment processor, Stripe, receives your email and purchase details so it can process the payment. Stripe is headquartered in the United States and may process your personal data there; these transfers are covered by Standard Contractual Clauses under GDPR Article 46 and by Stripe’s participation in the EU–US Data Privacy Framework.
Content moderation is performed with the help of Anthropic (Claude API). Only the text of your proposed message and, if provided, your chosen display name are sent to Anthropic for classification, never your email, IP address, or payment details. Anthropic states that inputs submitted through the API are not used to train its models. Anthropic is US-based; transfers are covered by Standard Contractual Clauses (GDPR Article 46).
Our VPS hosting provider is based in the European Union. Server logs may include IP addresses for a limited retention period (typically 14 days). We use only strictly-necessary cookies for session management. We do not use advertising or tracking cookies, and we do not sell your data.
For audience measurement we run Umami, a privacy-friendly analytics tool, on our own server infrastructure in the European Union. It is self-hosted and cookieless: it records aggregate page-view data such as page, referrer, approximate country, browser and device type. It does not track you across other websites, does not build profiles, and is not used for advertising. No data from it is transferred to any third-party analytics company.
The site loads no third-party fonts or scripts. Fonts and JavaScript that were previously served from Google Fonts and from the Cloudflare cdnjs network are now hosted on our own server, so your IP address is not disclosed to Google or to Cloudflare when you view the site.
Before payment, every submission is screened automatically by Claude Haiku 4.5, a model provided by Anthropic, which classifies the text against the content rules in our Terms of Service. A submission that is flagged is refused: no contract is concluded, no publication takes place and no charge is made.
This is not a decision producing legal effects concerning you or similarly significantly affecting you within the meaning of Art. 22 GDPR, because nothing is concluded and nothing is charged. You may revise the text and submit it again as often as you wish. If you believe a submission was flagged wrongly, write to thedevinczi@gmail.com and a human will review the decision.
When you submit a notice about published content through the form at /Report, we store your name, your email address, the explanation you give, the location of the content you report and your IP address. We process this data to comply with our legal obligation as a hosting service provider under Regulation (EU) 2022/2065 (the Digital Services Act), GDPR Art. 6(1)(c), and on the basis of our legitimate interest in handling and documenting disputes about published content, GDPR Art. 6(1)(f). Reports and the decisions taken on them are kept for 3 years.
Purchase records are kept for as long as required by Polish tax law (currently 5 years from the end of the tax year). After that, personal identifiers may be removed while the published message remains on the wall in its historical place.
Where a checkout is started but never paid, the email address and IP address collected at that point are deleted automatically within 48 hours by a scheduled background job.
Under the GDPR you have the right to:
Requests can be sent to thedevinczi@gmail.com.
Note: once a message has been published on the wall it is public and cannot be retroactively un-published from archives, caches, or copies held by third parties. We can however remove your personal identifiers (name, URL, email) from our own records on request.