Privacy Policy

Privacy Policy — SCARY.NETWORK

Draft for legal review (Israel Privacy Protection Law incl. Amendment 13; GDPR where applicable). Not legal advice.

Last updated: September 5, 2026

1. Controller

Diamond Rubini, Haifa, Israel, privacy@scary.network.

2. What we collect and why

DataPurposeLegal basisRetention
Email, password (hashed), display name, handleAccount, login, securityContractUntil account deletion
Profile bio, location text, pronouns, avatarPublic profile (you choose visibility)ContractUntil deleted
Fear profile (subgenres, dread threshold, triggers)Personalised feed, recommendations, content warningsConsent (optional; can be cleared anytime)Until cleared or account deletion
Posts, comments, reactions, ratings, stories, séance messages, uploadsProviding the serviceContractUntil deleted; backups ≤30 days
Follows, blocks, coven membershipsSocial features and safetyContract; legitimate interest (safety)Until account deletion
Push subscription (endpoint, keys)Web push notificationsConsentUntil you revoke
Stripe customer/subscription IDs, plan, statusBlood Pact membership, tipsContract; legal obligation (accounting)7 years after last transaction
Reports, moderation actions, audit log (keyed IP hash)Safety, abuse prevention, securityLegitimate interest; legal obligationReports 2 years; audit 365 days
Consent recordsProof of consentLegal obligationAccount lifetime + 3 years
Rate-limit counters, verification tokens (hashed)SecurityLegitimate interestMinutes to 24 hours

We do not collect precise location, government IDs, or payment card numbers (cards are entered on Stripe-hosted pages only).

3. Cookies

Strictly necessary cookies only: WordPress session/security cookies, scary_age_ok (18+ confirmation), scary_a11y (accessibility preferences). We set no analytics or advertising cookies. See the Cookie Policy for details and how to withdraw consent for any optional tools that may be added in future.

4. Who receives data

  • Stripe (payments) — DPA in place; see stripe.com/privacy.
  • Browser push services (Google, Apple, Mozilla) — receive encrypted payloads they cannot read.
  • Cloudflare Turnstile (bot protection, if enabled) — processes your IP and browser signals.
  • Hosting provider — IONOS (dedicated server, HestiaCP).
  • Authorities where legally required.

We do not sell personal data and do not serve ads.

5. International transfers

Data is stored in EU. Transfers to Stripe (US/EU) rely on Standard Contractual Clauses. Israeli users: transfers comply with the Privacy Protection (Transfer of Data to Databases Abroad) Regulations.

6. Your rights

Access, rectification, deletion, portability (export from Settings → Privacy), objection, restriction, withdrawal of consent, and complaint to the Israeli Privacy Protection Authority or your EU supervisory authority. Most actions are self-service in Settings; otherwise write to privacy@scary.network. We respond within 30 days.

7. Security

TLS, hashed passwords (bcrypt/argon2), optional TOTP two-factor authentication, malware scanning of uploads, quarantine of unscanned files, rate limiting, security headers, keyed IP hashing in logs, encrypted TOTP secrets. Breaches are handled per the Israeli Data Security Regulations and Amendment 13 notification duties, and GDPR Art. 33/34 where applicable.

8. Children

The Network is for adults only (18+). We do not knowingly process data of minors; report suspected minors to privacy@scary.network.

9. Changes

We will announce material changes in-app and by email. Continued use after the effective date means acceptance.

10. Database registration (Israel)

Database registration status: to be determined by legal counsel.