Privacy Policy
Last updated: August 2026 · Applies to all Woope users globally, with specific provisions for EU/EEA residents under GDPR.
🇪🇺 GDPR Summary - Your rights at a glance
- ✓ You can download a copy of your data at any time via Settings
- ✓ You can delete your account via Settings
- ✓ We never sell your data or show you ads
- ✓ We store data in Supabase EU region where available
- ✓ Push notifications are opt-in only
- ✓ You can contact us at support@woope.eu for any data request
- ✓ You can complain to the Czech UOOU (uoou.cz) if needed
1.Introduction
Woope ("we", "us", "our") is a social platform for people who build, learn and share their work. It is operated by Arnex Development Studio, which is the data controller for the personal data described here.
This Policy describes what Woope actually does with your data - it is written from the application's database schema and source code, not from a template. Where something is retained, shared or made public, it is because a specific feature does that, and the feature is named.
Woope runs on infrastructure in the European Union and is operated from the Czech Republic. We process personal data under the General Data Protection Regulation (GDPR) and applicable Czech law.
Data controller: Arnex Development Studio Contact: support@woope.eu
2.What Data We Collect
Account data:
- -Email address - required to sign up, sign in, verify your account and receive the emails you have not switched off
- -Password - stored only as a hash by our authentication provider. Woope never sees or stores your password itself
- -Username and display name
- -Date of birth - collected at sign-up to check the minimum age (see Children's Privacy). It is shown to other people only as a day and month, and only if you switch "Show birthday" on
- -Preferred language
- -If you sign in with Google: your Google account's email address and basic profile information, passed to us by Google at sign-in
Profile data (all optional, all provided by you):
- -Bio, current focus, location, website
- -Avatar and profile banner images
- -Interests you select
- -A public contact email, separate from your sign-in address, shown only if you switch "Show contact" on
- -Profile colours and any avatar frame you have bought
Content you create:
- -Posts, comments and replies
- -Discussions and discussion replies
- -Projects, project updates, milestones, gallery images and collaborator links
- -Portfolio pages, including skills, experience, services, testimonials and FAQ entries
- -Communities you create or join, and community announcements, rules and wiki pages
- -Quizzes you write, and quiz attempts and trophies you earn
- -Direct messages, including image, file and voice-message attachments
- -Reactions, woops, follows, saves, shares and reposts
- -Private notes and progress goals in your Private Space - visible only to you
- -Achievements you unlock - visible only to you
Security data:
- -Whether two-factor authentication is on, and the authenticator factors enrolled on your account. The shared secret behind a factor is held by our authentication provider; Woope never stores it
- -Sessions and sign-in timestamps, managed by our authentication provider
- -A short history of account-security events: two-factor turned on or off, an authenticator added or removed, password changed, an email change requested, other sessions signed out, and password confirmations. This history is visible only to you, in Settings, and deliberately contains no IP address, device or location information
- -Anti-abuse counters: rate-limit records keyed by a hash rather than by an identifier, and records of content flagged as spam
Notification data:
- -Your per-category notification preferences
- -Web push subscriptions, if you enable push notifications - the endpoint URL your browser issues, its encryption keys, and the browser identification string sent when you subscribed
Usage data:
- -A "last active" timestamp, used to show whether you are online
- -Which days you were active, which drives your activity calendar and streaks
- -View counts on posts, projects, discussions and portfolios
- -Product analytics events, if and only if you accept analytics cookies
Woopies (the in-app points):
- -Your balance, how you earned or spent it, transfers to and from other people, and any loans
Moderation data:
- -Reports you file, and reports filed about you
- -Moderation actions taken on your account, and the moderator actions log
Data we deliberately do not collect:
- -We do not fingerprint your device or browser
- -We do not store your IP address in any application table, with one narrow exception described in the next section
- -We do not buy data about you from anyone, and we do not run advertising trackers
3.IP Addresses and Device Information
This deserves its own section, because the honest answer is neither "never" nor "always".
Portfolio view counts: when someone who is not signed in looks at a public portfolio page, we compute a keyed hash of their IP address so the same visitor refreshing the page is not counted twice. The address itself is never written down, and the hash is keyed with a secret that only our servers hold, so it cannot be turned back into an address by anyone who obtains a copy of the table. These records are deleted after 90 days; only the aggregate counts survive. The visitor's browser identification string is checked against a list of known bots and then discarded, not stored.
Push notifications: if you turn them on, the browser identification string from the moment you subscribed is stored alongside the subscription, so you can tell your devices apart if you subscribe on more than one. It is deleted when you turn push off or delete your account.
Infrastructure logs: our hosting provider and our database provider record standard request information, including IP addresses, in their own operational logs. That is infrastructure we do not control the contents of, and it is retained under their own log policies.
Session and device lists: Woope does not show you a list of the devices you are signed in on, and does not keep one. Building that feature would mean storing the IP address and browser of every sign-in - a location and device history the product does not otherwise keep. Instead, Settings offers "sign out other sessions", which achieves the same security outcome without the record.
4.Legal Basis for Processing (GDPR)
Contract performance (Art. 6(1)(b)): everything needed to give you the service you signed up for - your account, your profile, the content you publish, your messages, the notifications tied to activity on your own content.
Legitimate interests (Art. 6(1)(f)): keeping the platform working and safe. This covers anti-spam and rate limiting, moderation and reports, view counts and the trending and recommendation ranking built from public engagement, and account-security records. Our interest here is a functioning, non-abusive platform, and each of these is limited to what that requires.
Consent (Art. 6(1)(a)): push notifications, optional marketing email, analytics cookies, and any optional profile field you choose to fill in. You can withdraw any of these at any time in Settings, without losing access to anything else.
Legal obligation (Art. 6(1)(c)): responding to lawful requests, and keeping records we are required to keep.
5.How We Use Your Data
- -To create your account, sign you in, and keep the session alive
- -To check that you meet the minimum age at sign-up
- -To show your profile, posts, projects, portfolio and public activity to the people your privacy settings allow
- -To deliver direct messages to the people you send them to
- -To send the notifications you have not switched off - in the app, by push if you enabled it, and by email per category
- -To count views, woops and other engagement, and to rank what appears in the feed, in Explore and in trending
- -To award and track Woopies, levels, streaks, badges, trophies and achievements
- -To translate content when you press Translate on it
- -To detect and act on spam, abuse and impersonation, and to handle reports
- -To let you see, and act on, changes to your own account security
6.What Is Public and What Is Not
Public by default - visible to anyone on the internet, including people without an account:
- -Your username, display name, avatar, banner, bio, current focus, location, website and interests
- -Your posts, comments, discussions and discussion replies
- -Public projects, project updates and portfolio pages
- -Public communities and their content
- -Your follower and following counts, badges, level and reputation
- -Your Woopies balance
Public only if you switch it on:
- -Your birthday, shown as a day and month, never the year
- -Your public contact email
Visible only to you:
- -Private notes and progress goals in your Private Space
- -Achievements you have unlocked
- -Your account security history
- -Your notification preferences and privacy settings
- -Your email address as used for signing in
Visible only to the people involved:
- -Direct messages and their attachments, visible to the participants in that conversation
- -Private community content, visible to that community's members
If you set your profile to private, your profile and your activity are visible only to followers you have approved, and following you becomes a request rather than an action. Content you had already published to a public community or project stays where you published it.
Everything above is enforced by the database, not only by the interface: a request that bypasses the app entirely is subject to the same rules.
7.Who Else Processes Your Data
We do not sell your personal data, and we do not share it with advertisers. The services below are the complete list of external providers Woope's code actually talks to.
Supabase - database, authentication and file storage. Effectively all application data described in this Policy is stored here. Acts as our processor. Our project runs in the EU (Paris) region.
Vercel - hosting and request routing for the application itself. Acts as our processor. Standard request metadata is handled by the platform.
Resend - delivery of transactional and notification email. Receives the recipient address and the content of the email being sent. Acts as our processor.
Google (Gemini API) - only when you press Translate on a piece of content. Receives the text being translated and the source and target languages. It does not receive your identity, your email, your IP address or any authentication token. Direct messages cannot be routed through this feature.
Google (Sign in with Google) - only if you choose to sign in that way. The exchange is between you and Google; we receive your email address and basic profile information from it.
Google (Analytics and Tag Manager) and Vercel Analytics and Speed Insights - product analytics. These load only after you accept analytics cookies, and not at all if you decline or ignore the cookie banner.
Your browser vendor's push service (for example Google, Mozilla or Apple, depending on your browser) - if you enable push notifications. Receives the encrypted notification payload and the subscription endpoint. This is how the Web Push standard works; there is no way to deliver a push notification without it.
We may disclose data if we are legally required to, or where it is necessary to protect the safety of users or the integrity of the platform.
8.How Long We Keep Things
While your account exists, your account data, profile, content and settings are kept. Some records have a shorter fixed life regardless, and these are enforced automatically by a scheduled job rather than being an intention:
- -Rate-limit records: 2 days
- -Birthday notification records: 30 days
- -Content view records and portfolio view records: 90 days - the aggregate counts survive, the individual records do not
- -Translation request records: 90 days
- -Analytics events: 180 days
- -Spam detection records: 180 days
- -Woopies earning records, daily activity records and account security history: 1 year
- -Moderator action log: 3 years
When you delete your account, immediately:
- -Your username is replaced with an anonymous identifier, and your display name, avatar, banner, bio, current focus, website, location and birthday are cleared
- -Your email address is removed from your profile row
- -Your profile is set to private and all "who can contact me" settings are set to nobody
- -Your private notes, interests, saved collections, notification preferences, push subscriptions, profile customisation, security history and your own notification inbox are deleted
- -Your blocks in both directions are removed
- -Your password is replaced with an unusable value and the account is permanently locked out of signing in
What is kept, and why:
- -Content you published - posts, comments, discussions, projects, communities - stays, attached to the now-anonymous profile. Deleting it would remove other people's replies, break communities and projects other members depend on, and cascade through to data that is not yours
- -Direct messages stay, because a conversation belongs to both participants and deleting your half would destroy the other person's record of it
- -Reports, moderation actions and anti-abuse records stay, so a banned account cannot be reset by deleting and re-creating it
- -Woopies transactions stay as a ledger of transfers involving other people
- -The underlying authentication record is not hard-deleted, because doing so would cascade into all of the above
If you want something specific removed beyond this, write to support@woope.eu and we will look at it individually.
9.Your Rights Under GDPR
Right of access (Art. 15) and portability (Art. 20): Settings, under Your data, has "Download my data". It produces a machine-readable JSON file containing your account details, profile, posts, comments, discussions, projects, messages, follows, community memberships, notifications, preferences, Woopies history, badges, achievements and reports you filed. You will be asked to confirm your password first, because the file is everything at once.
Right to rectification (Art. 16): edit your profile, or write to us.
Right to erasure (Art. 17): Settings, under Delete my account. Read the previous section first - it says exactly what is erased and what is not.
Right to restriction (Art. 18) and to object (Art. 21): write to support@woope.eu. Processing based on our legitimate interests, such as ranking and analytics, is the usual subject of an objection.
Right to withdraw consent (Art. 7(3)): turn push notifications off in Settings, change your email preferences per category, or change your cookie choices from the link in the footer. Withdrawing consent does not affect anything done before you withdrew it.
Right to complain: you can complain to the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.cz) or to the supervisory authority where you live.
Write to support@woope.eu to exercise any of these. We aim to respond within one month, as GDPR requires.
11.How We Protect Your Account
- -Passwords are hashed by our authentication provider. Neither we nor anyone with access to our database can read them
- -Two-factor authentication is available, using a standard authenticator app. When it is on, a code is required in addition to your password - and this is enforced by the database, not only by the interface, so a session that has not passed the check cannot reach your messages, private notes or notification settings
- -Turning two-factor authentication off requires your password and a current code from your authenticator. There is no email link that switches it off, because anyone who reached your inbox could use it
- -Changing your password or email, signing out other sessions, exporting your data and deleting your account all require you to confirm your password first
- -Password attempts on those confirmations are rate limited
- -All traffic is encrypted in transit. The application sends a strict content security policy and blocks itself from being embedded in another site
- -Access to your data is enforced at the database level by row-level security, so a request that skips the application is subject to the same rules
- -Uploaded files are restricted by type and size, and are stored with server-generated names so an upload cannot become a page
No system is completely secure. If a breach affects your rights and freedoms, we will notify you and the supervisory authority within 72 hours, as GDPR requires.
12.Children's Privacy
You must be at least 13 to have a Woope account. We ask for your date of birth at sign-up in order to check this, and the check is repeated on our servers rather than being left to the browser.
If an account is found to belong to someone under 13, it is removed.
If you are 13 or 14, we ask for a parent's or guardian's email address and their account stays inactive until that person approves it by email. This is enforced, not just requested: in the Czech Republic and several other EU countries, consent-based processing for someone under 15 (under 16 in some other EU countries) requires the authorisation of whoever holds parental responsibility, and Woope's minimum age of 13 is below that threshold. The parent or guardian's email is used only to send that one approval link and is not used for anything else. If you are 15 or older, no additional permission is required to use Woope itself, though local law may still require it for certain optional features depending on where you live.
If you believe a child under 13 has an account, write to support@woope.eu.
13.Where Your Data Is
Our database, authentication and file storage run in Supabase's EU region (Paris). The application itself is hosted by Vercel.
Supabase, Vercel, Resend and Google are US-headquartered companies. Where personal data is transferred outside the European Economic Area in the course of their providing these services, that transfer relies on the European Commission's Standard Contractual Clauses and, where applicable, on the EU-US Data Privacy Framework. Each provider publishes its own transfer documentation.
14.Changes to This Policy
We update this Policy when what the application does changes - not on a schedule. The "Last updated" date at the top of the page changes with it, and we will tell you in the app or by email about anything material.
Continuing to use Woope after a change means you accept the revised Policy.
15.Contact and Complaints
Email: support@woope.eu Contact page: woope.eu/contact We aim to answer data requests within one month.
You can also complain to the Czech supervisory authority:
Úřad pro ochranu osobních údajů (UOOU)
Web: uoou.cz
This Privacy Policy was last updated in August 2026. For data requests or questions, contact support@woope.eu. To report a concern to the Czech supervisory authority, visit uoou.cz.