Data we handle
We process your sign-in email and authentication records; public profile and contributions; private settings, signals, follows, reports, and notifications; and security records needed to rate-limit abuse. Report identities, private moderation notes, contact consent, and private messages are not public.
Why and how long
We use data to authenticate you, operate requested features, moderate abuse, secure the service, and meet legal obligations. Public contributions may be retained with the author detached after account deletion; private account data is deleted according to the documented operator matrix unless an approved legal or security hold applies. No production retention schedule has been approved, so we do not publish invented time periods. Exact periods require legal and operational approval before launch.
Analytics and logs
Northneed writes allowlisted server-side page-view logs for legal pages and selected public product views. Those entries are limited to an allowed event name and page context. There are no advertising cookies, cross-site tracking, or fingerprinting. In addition, ordinary Vercel request and log metadata may exist, including metadata generated while serving requests, subject to provider configuration and retention.
Processors and operational readiness
Supabase hosts authentication and application data; Vercel may host the application and process ordinary request and log metadata. Authorized maintainers may access data only for operations, safety, and legal obligations. Provider terms, processing regions, retention approval, legal review, and an evidenced restore drill remain external production-launch gates. Repository backup checks do not prove provider configuration, and having a backup does not mean a restore has passed. These gates do not block ordinary public browsing in the project preview, but they must be completed before a production launch is claimed.
Your controls
Data export
Signed-in owners can download a machine-readable copy of account data from Settings after fresh authentication checks.
Account deletion
Owners can submit an authenticated deletion request from Settings. Authored public content and necessary moderation audit history may be retained with account identity detached, so the UI does not falsely claim immediate erasure. Processing and verification remain an operator step.
Security and questions
We use access controls and narrow account-bound operations, but no online service can promise absolute security. Use the contact page or email attias.itay.ai@gmail.com for privacy requests; do not post personal information publicly.