Privacy Policy
Privacy Policy — SCARY.NETWORK
Draft for legal review (Israel Privacy Protection Law incl. Amendment 13; GDPR where applicable). Not legal advice.
Last updated: September 5, 2026
1. Controller
Diamond Rubini, Haifa, Israel, privacy@scary.network.
2. What we collect and why
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Email, password (hashed), display name, handle | Account, login, security | Contract | Until account deletion |
| Profile bio, location text, pronouns, avatar | Public profile (you choose visibility) | Contract | Until deleted |
| Fear profile (subgenres, dread threshold, triggers) | Personalised feed, recommendations, content warnings | Consent (optional; can be cleared anytime) | Until cleared or account deletion |
| Posts, comments, reactions, ratings, stories, séance messages, uploads | Providing the service | Contract | Until deleted; backups ≤30 days |
| Follows, blocks, coven memberships | Social features and safety | Contract; legitimate interest (safety) | Until account deletion |
| Push subscription (endpoint, keys) | Web push notifications | Consent | Until you revoke |
| Stripe customer/subscription IDs, plan, status | Blood Pact membership, tips | Contract; legal obligation (accounting) | 7 years after last transaction |
| Reports, moderation actions, audit log (keyed IP hash) | Safety, abuse prevention, security | Legitimate interest; legal obligation | Reports 2 years; audit 365 days |
| Consent records | Proof of consent | Legal obligation | Account lifetime + 3 years |
| Rate-limit counters, verification tokens (hashed) | Security | Legitimate interest | Minutes to 24 hours |
We do not collect precise location, government IDs, or payment card numbers (cards are entered on Stripe-hosted pages only).
3. Cookies
Strictly necessary cookies only: WordPress session/security cookies, scary_age_ok (18+ confirmation), scary_a11y (accessibility preferences). We set no analytics or advertising cookies. See the Cookie Policy for details and how to withdraw consent for any optional tools that may be added in future.
4. Who receives data
- Stripe (payments) — DPA in place; see stripe.com/privacy.
- Browser push services (Google, Apple, Mozilla) — receive encrypted payloads they cannot read.
- Cloudflare Turnstile (bot protection, if enabled) — processes your IP and browser signals.
- Hosting provider — IONOS (dedicated server, HestiaCP).
- Authorities where legally required.
We do not sell personal data and do not serve ads.
5. International transfers
Data is stored in EU. Transfers to Stripe (US/EU) rely on Standard Contractual Clauses. Israeli users: transfers comply with the Privacy Protection (Transfer of Data to Databases Abroad) Regulations.
6. Your rights
Access, rectification, deletion, portability (export from Settings → Privacy), objection, restriction, withdrawal of consent, and complaint to the Israeli Privacy Protection Authority or your EU supervisory authority. Most actions are self-service in Settings; otherwise write to privacy@scary.network. We respond within 30 days.
7. Security
TLS, hashed passwords (bcrypt/argon2), optional TOTP two-factor authentication, malware scanning of uploads, quarantine of unscanned files, rate limiting, security headers, keyed IP hashing in logs, encrypted TOTP secrets. Breaches are handled per the Israeli Data Security Regulations and Amendment 13 notification duties, and GDPR Art. 33/34 where applicable.
8. Children
The Network is for adults only (18+). We do not knowingly process data of minors; report suspected minors to privacy@scary.network.
9. Changes
We will announce material changes in-app and by email. Continued use after the effective date means acceptance.
10. Database registration (Israel)
Database registration status: to be determined by legal counsel.