1. Scope and responsible operator
This policy explains information handling for the IndieNew website, community and Plus. The responsible operator is xiangzihao, an individual in China; privacy email: xluk2771670458@gmail.com; business contact address: [to be completed]. We determine the purposes of processing platform accounts, content and on-platform analytics. Third-party product websites and Paddle transaction processing have their own policies.
2. Information you provide
Accounts: email, username, display name, password hash, email-verification status and optional avatar, bio and website. If you use an available Google, GitHub or Apple sign-in option, we process the provider identifier and authorized basic profile, which may include email, name and avatar. The current account store does not persist those providers’ access tokens.
Content: product drafts and published versions, screenshots, comments and replies, favorites, reports, notifications, moderation records, and Plus copy, assets, plans and retrospectives. The promotion demonstration is paused; previously submitted region, audience and budget details may remain stored. Support requests also involve the contact details and issue information you provide.
3. Visits, analytics and security information
Browser requests transmit IP addresses, request information and browser headers for delivery, security and rate limiting. Product analytics receive page and referrer URLs and extract fields such as source domain, campaign tags, event type and time. The analytics database does not store raw IP addresses, full User-Agent strings or full referrer URLs. Do not place personal information in campaign-link parameters.
Analytics use a random first-party visitor cookie whose digest deduplicates product visits; it is not directly linked to login accounts. Login state may be used to exclude a maker’s own visits. We count page views, campaign and outbound clicks, and favorite changes and provide aggregate reports to authorized makers, without visitor-identifier exports. A random identifier is not a guarantee of anonymity.
The service generates security rate-limit digests, error and moderation logs. Production hosting or proxy services may separately process access logs; providers, regions and retention periods must be confirmed before this policy takes effect. The analytics-database limits above do not mean the entire infrastructure never processes IP addresses.
4. Purposes and grounds
Information is used to create and secure accounts, provide content and Plus features, save input, send essential account emails, moderate misuse, respond to requests and meet legal obligations. On-platform analytics provide makers with product-performance summaries. We do not sell personal information or supply private copy to advertisers or for general-purpose AI model training.
We process personal information on applicable grounds such as necessity to perform the service contract, legal obligations or valid consent. Where applicable law permits reliance on legitimate interests, we assess necessity and your rights; that concept does not replace consent required by Chinese law or cookie rules. Consent to optional processing must be withdrawable.
5. Cookies and browser storage
Authentication: session cookies maintain sign-in for up to 7 days; authentication may also use short-lived anti-CSRF and third-party sign-in state cookies. Preferences: makerove-locale and makerove-theme remember language and theme for up to 1 year.
Analytics: makerove-visitor is a random visitor cookie lasting up to 180 days for deduplication. Attribution context lasts 30 minutes and session storage assists source recognition; link redirects may also set the visitor cookie. These serve analytics and are not necessary authentication cookies merely because they are first party.
Local storage restores unsubmitted product, Plus or promotion form input; session storage also holds short-lived navigation context. You can clear or restrict browser storage, which may remove unsaved input or affect sign-in, preferences and metrics. The current version has no separate on-site analytics consent control. Before serving regions requiring consent or an opt-out mechanism, the corresponding controls must be provided; browser settings do not replace required on-site controls.
7. Retention and deletion
Accounts, products and workspace content are retained as needed to provide the service, taking account of deletion requests, disputes and legal retention requirements. Account suspension is not permanent deletion; self-service permanent account deletion is not yet available. Submit a request through the contact page for handling under applicable law after identity verification.
Raw analytics events have a cleanup rule for data older than 180 days, requiring scheduled execution in production; this does not claim automatic deletion is already running. Copy versions, plans and retrospective snapshots do not expire with raw events. Unreferenced images have a cleanup rule after 24 hours, also dependent on maintenance execution.
Specific backup, access-log and future transaction-record retention periods are [pending production arrangements]. Following an approved deletion request, information no longer needed will be deleted or anonymized. Legally retained data will have restricted use, and backups will follow the confirmed rotation schedule.
8. Storage regions and international processing
The operator is in China. Actual production server, database, backup and email-processing regions are [to be completed]; do not infer that all data stays in China or the EU. Third-party sign-in, international access and the intended Paddle integration may involve cross-border processing.
Where applicable law requires it, necessary notices, separate consent or other valid transfer arrangements will be completed before the relevant processing, identifying recipients, purposes, information categories and rights channels. This draft does not claim that standard contracts, certification or transfer security assessments have been completed.
9. Your rights and security
Under applicable law, you may request information, access, copies, correction or deletion, restrict or object to particular processing, withdraw consent, and where applicable request portability or complain to a competent authority. Withdrawal does not invalidate prior lawful processing. We may verify identity without requesting unrelated information.
You can edit your profile in settings and use available content and Plus exports. Some requests currently require manual handling; subscription cancellation and refunds follow their respective policies. We will respond within applicable legal deadlines and explain any refusal and available remedies.
We use password hashing, protected session cookies, access checks, input limits and moderation. No system is absolutely secure; data incidents requiring legal notification will be handled and notified accordingly. The service is not directed to people under 18; contact us if you identify such an account or information.
10. Updates and contact
An effective date will be published after operator and production details are completed. Material changes will be notified on the website or by email where appropriate, with fresh consent where required. Use the privacy email published on our contact page for requests.