Privacy Policy

Responsible party

sebastiri
Email: mail@sebastiri.net

What data is collected

When you visit the website

The web server stores IP address, date/time, page visited, browser type, and referrer in log files. These are deleted automatically after 7 days. No analytics or tracking tools are used. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation).

When you create an account

Your email address, chosen name, likes, comments, and notification preference are stored in a database on this server. Your email is never shown publicly — only your name appears with comments. You can manage or delete your account at any time from the account page. Legal basis: Art. 6(1)(a) GDPR (your consent).

When you use the contact form

Your email, message, and the related photo title are sent to me via email. This data is not stored in any database and is deleted within 6 months of responding. Legal basis: Art. 6(1)(a) GDPR (your consent).

Email delivery

All emails (sign-in links, notifications, contact form) are sent through Mailjet (Mailjet SAS, Paris, France), which processes data exclusively within the EU. Your email is transmitted to Mailjet solely for delivery. Emails contain no tracking pixels or click tracking. Mailjet privacy policy.

Friend access

Some photos are only visible to users with friend access. New accounts are reviewed by sebastiri, who may grant friend status at their discretion. Your role is visible on your account page.

Passkeys

If you register a passkey (Face ID, Touch ID, fingerprint), a public key credential is stored on this server. The biometric data itself never leaves your device. You can remove passkeys from your account page.

Cookies and local storage

This website does not use cookies. An authentication token and a few preference flags are stored in your browser's local storage. No personal data is stored locally. You can clear this at any time through your browser settings.

External services

All website content (images, fonts, scripts) is served from this server. No external services are loaded when you visit the website. The only external service is Mailjet for email delivery (see above).

Hosting

Hosted by Uberspace (Jonas Pasche, Kaiserstr. 15, 55116 Mainz, Germany). All data is processed within Germany/EU.

Your rights

Under the GDPR you have the right to:

You can delete your account and all data from the account page. For other requests, contact mail@sebastiri.net. You also have the right to lodge a complaint with a data protection supervisory authority.