Privacy Notice
What personal data nrisimha.dev uses, why, who can access it, and how to request deletion.
Published for public beta: 17 August 2026.
Operator: the individual operator of nrisimha.dev, a non-profit community project. Public contact: [email protected]. The operator's legal name, country, and correspondence address are not yet published.
Data requests: [email protected].
This is a community site for events, communities, service, and news. Below is what is stored, why, and who can see it. We show no advertising, sell nothing, and do not track you across other sites.
What we store
| Category | What exactly | Why |
|---|---|---|
| Account | Email address, an encrypted form of your password, sign-in times, and the policy version you accepted with its date. Held by the Supabase authentication service | Signing in and account recovery |
| Profile | Username, display name, bio, avatar, preferred language, profile visibility setting, and — only if you add them — Telegram, a public email, WhatsApp, a website (each with its own visibility switch), and a saved city with its coordinates and time zone | Showing you in the community the way you chose |
| Content | Records (events, communities, services, news), drafts, comments, images, tags, saved records, Going responses, community memberships and join requests | Running the community |
| Chat | Messages, reactions, bookmarks, read markers, direct threads, room settings, blocks | Conversation inside the community |
| Reports and moderation | The report reason, what was reported, moderator notes, hidden and restricted states. A report about a chat message also stores a copy of that message's text as it was when reported | Handling reports |
| Notifications | Notification records, your notification settings, and — if you enable push — the delivery endpoint, your browser's keys, and a short browser description | Delivering what you asked for |
| Feedback | Your feedback text, its category, and your account | Improving the site |
| Technical protection | Rate limiting works on your IP address and keeps it briefly (about a minute) in Upstash. Error diagnostics go to Sentry with message text, form contents, and personal identifiers removed | Preventing abuse and fixing errors |
| View counter | A record's total view count, with no person attached | Showing an author that a record is read |
Provisionally, pending qualified review: steps necessary to create an account and provide requested features; legitimate interests in security, moderation, abuse prevention, aggregate counting, and privacy-filtered diagnostics; and consent for optional features and special-category data. This wording may change after the operator's identity and jurisdiction are confirmed.
Who can see what
- Everyone, including visitors with no account: published records and comments, community pages, and public profiles — username, display name, bio, avatar, and any contact you marked visible. A saved city, its coordinates, and time zone are not included.
- Members only: if you set your profile to members-only visibility, only signed-in people see it.
- Signed-in members only: a saved city, its coordinates, and time zone, if you added them.
- Chat: messages are visible to those with access to the room. A one-to-one conversation is readable only by its two participants — the database rules give administrators no way in. There is one exception, and it matters: if a participant reports a message, a copy of that message's text is stored and becomes visible to moderators.
- Moderators and administrators: reports, hidden content, restriction states, and moderator notes.
Information that can reveal religious belief
Taking part in a community, attending events, and messaging can indicate your religious beliefs. We do not ask you to declare a faith and do not label accounts as belonging to believers. Remember that what you publish is visible to everyone.
Participation can reveal religious beliefs. Signup therefore uses a separate explicit-consent statement, which can be withdrawn by writing to [email protected]. Withdrawal may require limiting or deleting the account. Whether this condition is sufficient still requires qualified review.
Who receives data
| Recipient | Role |
|---|---|
| Supabase | Database, authentication, image storage |
Vercel for nrisimha.dev and Timeweb in Russia for ru.nrisimha.dev; both sites use the same Supabase project | Serving the site |
| Sentry | Error diagnostics (message text and personal identifiers removed) |
| Upstash | Short-lived rate limiting |
| Your browser's push service | Delivering notifications, if you enabled them |
| Only if you chose Google sign-in | |
| YouTube, VK, RuTube, Vimeo, Zoom | Only if you clicked a video |
Storage regions and international transfers: The primary database, authentication, and Storage are in Supabase on AWS eu-west-1 (Ireland). nrisimha.dev is served through Vercel and ru.nrisimha.dev through Timeweb in Russia. Data can therefore cross borders.
How long we keep things
- Records, comments, and your profile are kept while the account exists.
- Deleting the account deletes the profile, records, comments, memberships, Going responses, and join requests. Your messages in shared rooms — community, event, and news — remain, with the sender detached, so your name no longer appears on them.
- A one-to-one conversation remains available to the other participant. Your side is shown as a deleted account, and the conversation becomes read-only.
- A push subscription is deleted when the delivery service reports that the endpoint no longer works.
- Reports and moderation decisions are kept as the history of how a case was handled.
- Backups:
Supabase daily physical backups are retained for 7 days; point-in-time recovery (PITR) is not enabled. Supabase Storage objects are not included in the database backup.
Your rights and how to use them
There is no export or delete button in the interface yet. Write to [email protected] and the request is handled manually: we acknowledge it, check that it comes from the account holder, and answer within one month where EU law applies.
Where the GDPR applies, you may request access, correction, erasure, restriction, portability, and object to processing; you may withdraw consent and complain to the competent data-protection authority. Because the operator's country is not yet published, no specific authority is named.
Automated decisions
We make no automated decisions about you. There are automated checks: content can be flagged by keyword for a person to review, and the publishing rules can refuse a submission. A human always decides a moderation outcome.
Age: Accounts are for adults aged 18 or older only. The site has no minors safeguarding programme; anyone under 18 should not create an account or submit personal data.
Security: report a problem to [email protected].
Russian users and data location
The primary Supabase database is in Ireland, not Russia. Hosting the ru.nrisimha.dev web application on a Russian server does not change that. Since 1 July 2025, Russian law generally prohibits initially collecting Russian citizens' personal data directly into a foreign database, subject to narrow exceptions. nrisimha.dev does not currently claim compliance with that localization requirement. Until a dedicated lawful data path or qualified advice is in place, Russian citizens should use the public informational pages without creating an account or submitting personal data.

