Pocket Trash

Date: · v1.1

Pocket Trash is a personal, independently operated, non-commercial hobby project based in Ontario, Canada. This voluntary Privacy Policy explains how Pocket Trash ("we," "us," or "our") collects, uses, discloses, retains, and deletes personal information when you use the Pocket Trash website and related services (the "Service").

For privacy questions, complaints, or requests, contact the Privacy Officer at privacy@pocket-trash.app.

For maker, content, or intellectual-property reports, contact Maker and Rights Requests at rights@pocket-trash.app.

Information we collect

Information you provide

We collect information that you provide through the Service, including:

  • account and profile information received through our authentication provider, such as your account identifier, username, email address, and profile details;
  • settings and preferences associated with your account;
  • collection names, collection-item details, product and catalog contributions, descriptions, tags, and other information you enter;
  • images, resource files, resource metadata, and other material you upload; and
  • messages and information you send when you request support, report content, make a privacy request, or contact us.

Do not upload personal information about another person unless you have permission or another lawful basis to do so.

Information collected when you use the Service

We collect technical and activity information needed to operate and protect the Service, including:

  • authentication and session information;
  • resource download records;
  • server, browser, and application diagnostics;
  • security events and identifiers, which may include a hashed account identifier; and
  • IP address, device, browser, request, and network information processed by our hosting, security, authentication, logging, and content-delivery providers.

Information stored on your device

The Service uses authentication cookies required to keep you signed in. It may store your theme, language, and pen preferences in browser storage.

The Service does not currently use advertising or behavioural analytics.

How we use information

We use personal information to:

  • create and secure accounts;
  • provide collections, catalog features, resources, uploads, downloads, and account settings;
  • show content according to the visibility you select;
  • respond to support, privacy, maker, content, and intellectual-property requests;
  • diagnose failures, prevent abuse, and protect users and the Service;
  • comply with legal obligations and apply our Terms of Service; and
  • maintain records needed for security, legal claims, and service administration.

We will seek consent when applicable law requires it for a new purpose.

Public and private content

You control the visibility settings that the Service provides for collections, collection items, resources, and related files or images.

Other people can view or download content while you mark it public. Changing content to private or deleting it stops normal access through the Service, but cannot recall copies that another person downloaded or copied while it was public.

Private content remains available to you and to service providers that process it for us. The operator may access it when needed to provide support, investigate abuse, protect the Service, or comply with law.

When we disclose information

We disclose information to these service providers so they can process it for us:

  • Clerk: authentication, account, and session services;
  • Neon: database hosting;
  • Bunny: file storage and content delivery;
  • Axiom: application logging and diagnostics;
  • Vercel: web hosting and delivery;
  • Cloudflare: network, security, and delivery services; and
  • Railway: application hosting and related infrastructure.

We may also disclose information:

  • when you direct us to make content public;
  • when law, legal process, or a valid government request requires disclosure;
  • when needed to protect a person's safety, investigate fraud or abuse, or defend legal rights; or
  • as part of a reorganization or transfer of the Service, subject to applicable law and appropriate safeguards.

We do not sell personal information or share it for cross-context behavioural advertising.

International processing

Pocket Trash and its service providers process personal information outside Canada. Foreign laws may allow courts, law enforcement, or national-security authorities to access information in those locations.

Current infrastructure includes Neon in AWS US East; Bunny origin replication in Singapore, Los Angeles, and Stockholm; Axiom in AWS US East; Cloudflare global processing; Vercel global edge processing; and Railway in US East. Clerk manages its own processing locations.

Retention

We keep active account data and private content while your account remains open or until you delete the content. Public content remains available until you change its visibility, delete it, or we remove it. Product and shared catalog contributions may remain after account erasure with account attribution removed.

A confirmed erasure request makes the account read-only and cannot be cancelled. We aim to complete active-system erasure within 30 calendar days after identity verification, or sooner where law requires it.

The approved retention limits for copies outside active application storage are:

  • Neon point-in-time history: up to 6 hours;
  • Bunny CDN cache: removed through exact purge, with a 30-day automatic ceiling;
  • Bunny request logs: 3 days with IP anonymization;
  • Axiom events already emitted: 30 days;
  • Cloudflare logs and traces: no more than 7 days;
  • Vercel runtime logs: 1 hour on the current plan;
  • Clerk application logs: 30 days; and
  • Clerk deletion processing: up to 3 days.

We keep a minimal erasure receipt containing no raw account ID, email, name, content, or object path. We delete the receipt 30 days after active-system completion and after every provider exception expires. We may retain other information only when law requires it or when the minimum record is needed to protect legal rights.

Deleting content and accounts

You can delete supported content through the Service. You can request complete account erasure from your account settings or by contacting privacy@pocket-trash.app. An authorized administrator can start the same workflow after verifying a request.

Once you confirm the request, you cannot cancel it and your account becomes read-only except for the request status page. Pocket Trash deletes account-owned database records, uploaded files, images, download records, pending feedback, and other account-linked active-system data. Pocket Trash then revokes sessions and deletes the Clerk identity last.

Pocket Trash preserves shared product, catalog, and taxonomy content that other users rely on only after removing account attribution. Anonymous aggregate counts may also remain. Complete erasure cannot recall copies that another person downloaded while content was public.

Provider-managed backup, cache, and log copies expire within the limits listed above. Pocket Trash reports a failure instead of marking the request complete when an active-system deletion or verification check fails.

Your privacy choices and rights

Depending on where you live, you may have the right to:

  • ask for access to personal information we hold about you;
  • ask us to correct inaccurate information;
  • withdraw consent where we rely on consent;
  • ask us to delete information;
  • object to or restrict certain processing;
  • receive information in a portable form; or
  • complain to a privacy regulator.

Send requests to privacy@pocket-trash.app. We may ask for information needed to verify your identity and protect your account. We will respond within the period required by applicable law.

You may change content visibility and supported account settings through the Service. You can control browser cookies and storage through your browser, but blocking required authentication storage may prevent sign-in.

Safeguards

We use administrative, technical, and organizational safeguards designed for the nature of the information we hold. These include access controls, managed infrastructure, authentication protections, monitoring, and procedures for deletion and security incidents.

No online service can eliminate every security risk. Contact privacy@pocket-trash.app if you believe your account or information is at risk.

Children

The Service is not directed to children under 13, and we do not knowingly collect their personal information. Contact privacy@pocket-trash.app if you believe a child under 13 has provided personal information. We will investigate and delete it where required.

Changes to this Policy

We may update this Policy when our practices, providers, or legal obligations change. We will post the updated version with a new effective or last-updated date. When required by applicable law, we will provide additional notice before a material change takes effect.

Contact and complaints

Contact the Pocket Trash Privacy Officer at privacy@pocket-trash.app.

You may also complain to the privacy regulator with authority where you live. We invite you to contact us first so we can address your concern.

For maker, content, or intellectual-property reports, contact Maker and Rights Requests at rights@pocket-trash.app.