LOUDERR

Privacy

Who operates LOUDERR

Mats Melbye

LOUDERR stores account and profile details; public Drops and media; private saves, direct messages, notifications, and recipient-scoped events; moderation and security evidence; and first-party product events used to evaluate the controlled test. If a member leaves the registration handle blank, LOUDERR creates a random handle that is not derived from the submitted name or email.

Google and Apple sign-in

When configured, Google or Apple authenticates the member and sends LOUDERR a signed identity response. LOUDERR validates that response and stores the provider name, the provider’s stable account subject, a verified email address, optional display name, and local sign-in timestamps. LOUDERR does not retain the provider access token, refresh token, authorization code, or ID token. The short-lived browser state, nonce, and Google code-verifier material are used only to complete or reject the sign-in attempt.

A verified provider email never silently merges accounts. If that email already belongs to a LOUDERR account, the member must sign in to that account and explicitly connect the provider in Security. Apple may supply a private relay email rather than the member’s ordinary address. Google and Apple process sign-in data under their own terms and privacy practices. Local disconnection is not currently offered; local account deletion removes the stored provider link but does not delete the Google or Apple account or prove provider-side erasure.

Language and translation

Automatic translation is currently disabled: no new translation jobs are created and no content is sent to a translation provider. Existing language preferences and cached derivatives are retained, while member-facing content is shown in its original language. If explicitly enabled later, public Drops, Chat messages, questions, responses, and polls can be sent to a configured translation provider and stored as labeled language derivatives. Original text remains the source of record. An English derivative can support shared search and staff review, but automated translation can be inaccurate and is not the sole authority for moderation.

Direct messages are stored by LOUDERR and are not currently end-to-end encrypted. Automated abuse checks can prevent delivery, and authorized staff can review reported or held messages. Editing a message retains earlier versions, which both participants and authorized report reviewers can view. Deleted or removed messages and their earlier versions are hidden from conversation search and participant history views.

Direct-message text is eligible for external translation only when the operator has enabled private translation and both active participants have opted in. Withdrawing either preference clears LOUDERR's cached private derivatives and returns the conversation to originals. It does not undo provider processing or prove provider-side erasure. Provider retention, training use, subprocessors, transfer locations, and deletion terms require formal operator and privacy review before this feature is enabled beyond controlled testing.

World and connected data

Connected features can store Mic entries and slots, questions, polls and votes, collaborations, integrity classifications, and lifecycle provenance. Mic entries retain integrity classifications and weights. Current Mic slots and bounded completed or removed slot history can be public with holder, Drop, timing, selection-reason, and aggregate-metric data; Mic queue entries are not publicly listed. Public structured question detail can include a capped, deterministic set of active, integrity-valid, full-weight response bodies from active verified users and their public profiles, with block and mute filtering. Member-specific viewer-response state, including the viewer’s own body, integrity, and counted state whether or not it is in the public eligible set, and collaboration-interest text are handled separately as participant-scoped data. Public status, Board history, Winner archives, and Time Capsules retain bounded records and provenance so shared results are not silently rewritten.

The World map uses an explicit, removable consent record for a user-provided coarse country and optional region or city label. A member can add, edit, or remove that record. Public local lenses are thresholded aggregates; LOUDERR does not claim to collect GPS or precise location for this feature.

Commerce and providers

When commerce is enabled, LOUDERR stores creator-account state and owned offers, including private fulfillment configuration; buyer purchases and entitlements; creator-sale snapshots; sponsor campaigns and exposures; and non-secret provider customer, connected-account, Checkout-session, payment-intent, and subscription identifiers. Those provider-issued IDs are non-credential identifiers but remain account-linked and are not public by default. Provider-hosted Checkout, billing, and payout onboarding send the member to the configured payment provider.

Configured identity providers receive data only as needed for sign-in. Configured payment, anti-bot, and safety providers receive data only as needed for payment or payout processing, anti-abuse checks, or safety evaluation. A configured translation provider receives only text and language metadata needed for the enabled public or consented-private translation contract. LOUDERR does not store payment-card data or raw webhook bodies; signed webhook events are represented by provider identifiers, state, and a payload digest.

Measurement and identifiers

Contextual advertising and Premium

The separately gated native-ad feature uses the current page topic, campaign budgets and first-party frequency controls, not a behavioral interest profile or private messages. Ad delivery and qualification records can be linked to the signed-in member for billing integrity and abuse prevention; advertisers receive campaign totals, not viewer identities. No third-party advertising pixel is added by this feature. Contextual delivery and first-party measurement still require formal privacy review before rollout.

Advertising preferences record an optional adult self-declaration. This is not verified age assurance or consent to behavioral advertising. Unknown-age accounts and guests receive no native ads in this version. You can retract the declaration without losing free organic participation. Premium records include checkout, subscription, paid-period and refund/dispute state needed to provide ad-free access and safely stop billing. Account export includes your own new billing and advertising state; deletion removes the age preference while restricted financial and abuse evidence can remain under the retention policy.

Measured events can include sessions, registration, login, qualified viewport impressions, dwell time, media progress, outbound clicks, account signals, reports, blocks, mutes, commerce interactions, and return sessions. API responses alone are not counted as impressions, and no invasive third-party tracker is enabled by default.

Sessions use opaque server-side records and HttpOnly cookies. Analytics use random first-party identifiers and server-hashed session keys. Stored session and security network values use keyed-pseudonymous hashes rather than raw IP addresses or raw user agents.

When a configured anti-bot check is invoked, its provider may receive the raw remote IP address with the challenge response for anti-abuse verification. That external disclosure is distinct from LOUDERR’s keyed-pseudonymous stored network values.

Export, deletion, and retention limits

A recently reauthenticated member can export account, profile, content, relationship, message, connected-feature, and commerce data. Commerce export can include owned offers with private fulfillment configuration, buyer purchases, creator-sale snapshots without buyer identity, and owned sponsor campaigns and exposures. It is minimized so another party’s private billing identifiers are not disclosed.

Account deletion revokes sessions, deletes local Google/Apple identity links and pending sign-in attempts, removes or replaces direct account identifiers, and retires the public account and its profile authority. It removes advertising-frequency records and unbilled advertising deliveries that are not linked to a safety report. Billed deliveries and reported advertising evidence can remain for financial reconciliation or safety handling. Financial, entitlement, audit, moderation, security, and sponsor-exposure evidence can remain pseudonymized under the stable internal user ID; that stable link remains inside the service.

Deletion also removes the member’s coarse-region consent record, retires public and connected authority, and scrubs question-response bodies and collaboration-interest text where supported. Provider Checkout and subscription state must first be safely reconciled or retired; if that cannot be confirmed, deletion fails closed instead of reporting a partial deletion.

Authored content can remain nonpublic for moderation or dispute handling. Stable-ID-linked participation, integrity classifications, financial and entitlement records, sponsor exposure evidence, moderation evidence, security events, and audit history can also be retained.

A monitored public privacy or legal contact channel is not configured for this controlled test. The exact retention, erasure, legal-hold, controller, operator, service-address, and contact rules are not finalized and require professional review before broader launch.

This draft does not establish compliance with any jurisdiction. Formal legal and privacy review is required before broader launch.

Return to LOUDERR