INDIENEW / TRUST & SUPPORT

Privacy Policy

What information we process, why we process it and how you can manage your information.

Updated September 11, 2026

Draft policies · not yet effective. Business contact address and production data hosting details remain to be completed. Paid subscriptions are closed; paid terms describe the proposed launch policy. An effective date will be published separately.

1. Scope and responsible operator

This policy explains information handling for the IndieNew website, community and Plus. The responsible operator is xiangzihao, an individual in China; privacy email: xluk2771670458@gmail.com; business contact address: [to be completed]. We determine the purposes of processing platform accounts, content and on-platform analytics. Third-party product websites and Paddle transaction processing have their own policies.

2. Information you provide

Accounts: email, username, display name, password hash, email-verification status and optional avatar, bio and website. If you use an available Google, GitHub or Apple sign-in option, we process the provider identifier and authorized basic profile, which may include email, name and avatar. The current account store does not persist those providers’ access tokens.

Content: product drafts and published versions, screenshots, comments and replies, favorites, reports, notifications, moderation records, and Plus copy, assets, plans and retrospectives. The promotion demonstration is paused; previously submitted region, audience and budget details may remain stored. Support requests also involve the contact details and issue information you provide.

3. Visits, analytics and security information

Browser requests transmit IP addresses, request information and browser headers for delivery, security and rate limiting. Product analytics receive page and referrer URLs and extract fields such as source domain, campaign tags, event type and time. The analytics database does not store raw IP addresses, full User-Agent strings or full referrer URLs. Do not place personal information in campaign-link parameters.

Analytics use a random first-party visitor cookie whose digest deduplicates product visits; it is not directly linked to login accounts. Login state may be used to exclude a maker’s own visits. We count page views, campaign and outbound clicks, and favorite changes and provide aggregate reports to authorized makers, without visitor-identifier exports. A random identifier is not a guarantee of anonymity.

The service generates security rate-limit digests, error and moderation logs. Production hosting or proxy services may separately process access logs; providers, regions and retention periods must be confirmed before this policy takes effect. The analytics-database limits above do not mean the entire infrastructure never processes IP addresses.

4. Purposes and grounds

Information is used to create and secure accounts, provide content and Plus features, save input, send essential account emails, moderate misuse, respond to requests and meet legal obligations. On-platform analytics provide makers with product-performance summaries. We do not sell personal information or supply private copy to advertisers or for general-purpose AI model training.

We process personal information on applicable grounds such as necessity to perform the service contract, legal obligations or valid consent. Where applicable law permits reliance on legitimate interests, we assess necessity and your rights; that concept does not replace consent required by Chinese law or cookie rules. Consent to optional processing must be withdrawable.

5. Cookies and browser storage

Authentication: session cookies maintain sign-in for up to 7 days; authentication may also use short-lived anti-CSRF and third-party sign-in state cookies. Preferences: makerove-locale and makerove-theme remember language and theme for up to 1 year.

Analytics: makerove-visitor is a random visitor cookie lasting up to 180 days for deduplication. Attribution context lasts 30 minutes and session storage assists source recognition; link redirects may also set the visitor cookie. These serve analytics and are not necessary authentication cookies merely because they are first party.

Local storage restores unsubmitted product, Plus or promotion form input; session storage also holds short-lived navigation context. You can clear or restrict browser storage, which may remove unsaved input or affect sign-in, preferences and metrics. The current version has no separate on-site analytics consent control. Before serving regions requiring consent or an opt-out mechanism, the corresponding controls must be provided; browser settings do not replace required on-site controls.

6. Public content and service providers

Approved published products, maker profiles and public comments may be viewed, linked and indexed by search engines. Email addresses, password hashes and private workspaces do not become public merely through registration. Avoid placing information you wish to keep private in public fields.

Necessary providers include production hosting and database services [provider and region to be completed] and SMTP account-email services [provider and region to be completed]. When Alibaba Cloud Content Moderation is enabled, text and images requiring checks are sent to that service; the current integration uses its Shanghai region alongside human review. Authorized operators and reviewers may access data for their respective duties.

A third-party sign-in provider is used when you choose that login method. After Paddle integration, Paddle will process payment, tax, billing and anti-fraud data under its own policy. IndieNew intends to receive order and customer identifiers, contact email, amount, currency and subscription status needed to manage access, without directly collecting full card numbers or security codes. No live payment data is currently collected.

Where disclosure is legally required, necessary to protect lawful rights or part of a business transfer, information will be handled to the necessary extent with legally required notices. Changes to recipients and processing arrangements will be reflected in this policy.

7. Retention and deletion

Accounts, products and workspace content are retained as needed to provide the service, taking account of deletion requests, disputes and legal retention requirements. Account suspension is not permanent deletion; self-service permanent account deletion is not yet available. Submit a request through the contact page for handling under applicable law after identity verification.

Raw analytics events have a cleanup rule for data older than 180 days, requiring scheduled execution in production; this does not claim automatic deletion is already running. Copy versions, plans and retrospective snapshots do not expire with raw events. Unreferenced images have a cleanup rule after 24 hours, also dependent on maintenance execution.

Specific backup, access-log and future transaction-record retention periods are [pending production arrangements]. Following an approved deletion request, information no longer needed will be deleted or anonymized. Legally retained data will have restricted use, and backups will follow the confirmed rotation schedule.

8. Storage regions and international processing

The operator is in China. Actual production server, database, backup and email-processing regions are [to be completed]; do not infer that all data stays in China or the EU. Third-party sign-in, international access and the intended Paddle integration may involve cross-border processing.

Where applicable law requires it, necessary notices, separate consent or other valid transfer arrangements will be completed before the relevant processing, identifying recipients, purposes, information categories and rights channels. This draft does not claim that standard contracts, certification or transfer security assessments have been completed.

9. Your rights and security

Under applicable law, you may request information, access, copies, correction or deletion, restrict or object to particular processing, withdraw consent, and where applicable request portability or complain to a competent authority. Withdrawal does not invalidate prior lawful processing. We may verify identity without requesting unrelated information.

You can edit your profile in settings and use available content and Plus exports. Some requests currently require manual handling; subscription cancellation and refunds follow their respective policies. We will respond within applicable legal deadlines and explain any refusal and available remedies.

We use password hashing, protected session cookies, access checks, input limits and moderation. No system is absolutely secure; data incidents requiring legal notification will be handled and notified accordingly. The service is not directed to people under 18; contact us if you identify such an account or information.

10. Updates and contact

An effective date will be published after operator and production details are completed. Material changes will be notified on the website or by email where appropriate, with fresh consent where required. Use the privacy email published on our contact page for requests.