Privacy Policy
Last updated: 4 October 2026
Palinilap is a website for writing palindromes and sharing them with other writers. This page explains which personal data we collect, why, how long we keep it and what rights you have. We collect only what the service needs to work. We do not sell data, show ads or use tracking or analytics tools.
1. Who is responsible
The data controller is the publisher of Palinilap named in the Legal notice. You can reach us about anything on this page at contact@palinil.app.
2. What we collect and why
| Data | Why | Legal basis (GDPR) |
|---|---|---|
| Email address | To sign you in (we email you a one-time login link) and to send messages about your account and payments. | Contract (Art. 6(1)(b)) |
| Handle, display name, profile details you add (bio, avatar, colours, zodiac sign and similar) | To show your profile and your posts to other writers. | Contract |
| Everything you write or do on the site: palindromes, posts, replies, reactions, likes, follows, bookmarks, collections, polls, battles, collaborations, PM Imp messages | This is the service itself. Posts and profiles are public. PM Imp messages are shown only to their recipient and are kept in server memory, not on disk. | Contract |
| Subscription status and a Stripe customer reference | To know which plan you have. We never see or store your card details: Stripe handles the payment. | Contract; legal obligation for accounting records (Art. 6(1)(c)) |
| IP address | To limit abuse (rate limits) and, when you react to a post without an account, to stop the same visitor reacting again and again. A guest reaction is stored with the IP address it came from. Other visitors never see it. | Legitimate interest in keeping the site usable and fair (Art. 6(1)(f)) |
| Your unsaved drafts in the writing studio when you are not signed in | So your work survives a page reload. Stored under a random identifier, not linked to your identity. | Contract / your request |
| Technical server logs (time, error messages, sometimes an email address in a login or payment log line) | To keep the service running and investigate errors or abuse. | Legitimate interest |
3. Cookies and local storage
We use only what the site needs to work, so no consent banner is required:
- auth: keeps you signed in. Deleted when you sign out.
- sid: links your browser to your writing studio session.
- Local storage in your browser keeps your preferences (theme, font, layout and similar). It never leaves your device unless a setting says it syncs to your account.
We do not use advertising, analytics or social media tracking cookies. Fonts are served from our own server.
4. Who else receives data
We share data only with the service providers that run parts of Palinilap for us, under data processing agreements:
- Hetzner Online GmbH (Germany): hosts the server and stores all data, inside the European Union.
- Stripe (Stripe Payments Europe, Ireland, and Stripe, Inc., USA): processes payments. Stripe receives your email address and payment details. Transfers to the USA are covered by the EU-US Data Privacy Framework and standard contractual clauses.
- Resend (Resend, Inc., USA): delivers our emails (your email address and the message). Transfers are covered by standard contractual clauses.
When a post contains a link, our server fetches that page once to build a preview. Only our server contacts that site, never your browser, and no data about you is sent.
5. How long we keep data
- Account data: as long as your account exists.
- When you delete your account (Settings), your account, email, profile, follows, likes, bookmarks, notifications, the link between you and your reactions, and your login sessions are erased at once (reaction counts stay, without names). Your public posts and replies stay on the site but are no longer linked to you: the author name is removed.
- A frozen account (Panama Nap) that is not resubscribed within 60 days is deleted the same way.
- Payment records: kept by Stripe and by us for as long as accounting law requires (up to 10 years in France).
- Rate-limit data: minutes to hours. Server logs: at most 30 days.
6. Your rights
You can ask to access, correct, delete or receive a copy of your data, to restrict its use or to object to it (Articles 15 to 21 GDPR). Write to contact@palinil.app; we answer within one month. You can delete your account yourself at any time in Settings.
You can also complain to a data protection authority. In France this is the CNIL (www.cnil.fr).
7. Age
Palinilap is for people aged 16 and over. We do not knowingly collect data from younger children.
8. Security
All traffic is encrypted (HTTPS). Login uses one-time links instead of passwords, so there is no password of yours to leak. Access to the server is restricted to the publisher.
9. Changes
If we change this policy in a way that matters, we will say so on the site before the change applies. The date at the top shows the current version.