Privacy Policy
Effective date: 2026-05-16 · Last updated: 2026-05-16 · Version 1.0
1. Introduction
This Privacy Policy explains how haivl.org (“HaiVL,” “we,” “us”) collects, uses, shares, and protects your personal information when you use our Site.
By using the Site, you agree to this Privacy Policy. If you do not agree, do not use the Site.
This Policy complies with the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and applicable US federal and state privacy laws.
2. Information We Collect
2.1 Information You Provide
- Account information: username, email address, password (encrypted), language preference
- Profile information: avatar, bio, city (optional)
- Content: posts, comments, votes, uploads
- Communications: emails sent to us, support requests, feedback
2.2 Information Collected Automatically
- Device and connection data: IP address, browser type, operating system, device type, screen resolution
- Usage data: pages visited, time spent, links clicked, posts viewed, search queries
- Cookies and similar technologies: see Section 6
- Approximate location: derived from IP address (city/state level, not precise GPS)
- Referral data: how you arrived at the Site (search engine, social media link, direct, etc.)
2.3 Information from Third Parties
- OAuth providers: if you sign in with Google or Apple, we receive basic profile data (email, name) from those providers
- Ad networks: aggregate analytics from Google AdSense or other ad partners
2.4 Information We Do Not Collect
- Government-issued ID numbers (SSN, driver’s license, passport)
- Financial account numbers or payment card data
- Precise GPS location
- Biometric data
- Health or medical information
- Children under 13 (if we learn we have collected such data, we will delete it)
3. How We Use Your Information
We use your information to:
- Operate and maintain the Site
- Create and manage your account
- Display your content to other users
- Personalize your experience (feed algorithm, channel recommendations)
- Communicate with you (account notices, moderation actions, support responses)
- Detect and prevent fraud, spam, abuse, and security threats
- Comply with legal obligations
- Enforce our Terms of Service and Community Guidelines
- Analyze Site usage to improve our service
- Display relevant advertising via third-party ad networks (where applicable)
4. How We Share Your Information
We share information only in the following circumstances:
4.1 Public Content
Your username, profile picture, posts, comments, and votes are publicly visible. Search engines may index this content. Do not post information you don’t want public.
4.2 Service Providers
We share data with third-party service providers who help us operate the Site:
- Cloudflare — hosting, CDN, image storage, DDoS protection
- Google Tag Manager — tag management (may load Google Analytics and similar usage-analytics tags)
- Google AdSense (post-launch) — advertising
- Email service providers — transactional emails
- OAuth providers — Google and Apple for sign-in
- Error tracking — Sentry for technical error logs
These providers are contractually required to protect your data and use it only for the services they provide to us.
4.3 Legal Requirements
We may disclose information when required by:
- Subpoena, court order, or other legal process
- Government investigation
- To protect rights, property, or safety of HaiVL, our users, or the public
- To enforce our Terms
We will resist overbroad requests and notify affected users where legally permitted.
4.4 Business Transfers
If HaiVL is acquired, merged, or sells assets, user data may transfer as part of that transaction. We will notify users in advance.
4.5 Aggregated Data
We may share aggregated, de-identified data (e.g., “10,000 users visited last month”) that cannot reasonably identify individuals.
4.6 We Do Not Sell Your Personal Information
We do not sell personal information to third parties. We do not share personal information for cross-context behavioral advertising in ways that would constitute “sale” or “sharing” under CCPA.
5. Your Rights
5.1 All Users
You have the right to:
- Access information we have about you
- Correct inaccurate information
- Delete your account and associated data
- Export your data in machine-readable format
- Opt out of non-essential communications
To exercise these rights: privacy@haivl.org
We respond to verified requests within 30 days. We may require verification of identity before processing.
5.2 California Residents (CCPA / CPRA)
In addition to the rights above, California residents have specific rights:
- Right to know: what personal information we collect, use, disclose, and sell/share
- Right to delete: request deletion of personal information we collected
- Right to correct: request correction of inaccurate personal information
- Right to opt out: opt out of sale or sharing of personal information (we do not sell or share, so this is automatic for you)
- Right to limit use of sensitive personal information: we do not collect sensitive PI as defined by CCPA
- Right to non-discrimination: we will not discriminate against you for exercising your rights
To submit a CCPA request: privacy@haivl.org with subject line “CCPA Request”
We respond to verified CCPA requests within 45 days, extendable to 90 days for complex requests.
5.3 Authorized Agents
You may designate an authorized agent to make requests on your behalf. We require written authorization and verification.
6. Cookies and Tracking
We use cookies and similar technologies for:
- Essential: authentication, security, basic functionality (cannot be disabled)
- Analytics: usage statistics via tags managed in Google Tag Manager
- Advertising (post-launch): Google AdSense uses cookies to serve relevant ads
You can control cookies through your browser settings. Disabling essential cookies will break login and posting functionality.
We honor Global Privacy Control (GPC) signals where applicable.
We do not use cross-site tracking technologies beyond standard ad network cookies disclosed above.
7. Data Retention
- Account data: retained while your account is active. Deleted within 30 days of account deletion request.
- Content: retained as long as it remains on the Site. Deleted content removed from public view immediately, fully purged within 30 days.
- Logs: technical logs retained 90 days for security and debugging.
- Backups: data may persist in backups for up to 90 days after deletion.
- Legal holds: data subject to legal process may be retained as required.
8. Data Security
We use industry-standard security measures including:
- HTTPS encryption for all traffic
- Password hashing (bcrypt or similar)
- Rate limiting on authentication endpoints
- Cloudflare DDoS protection and WAF
- Regular security updates of dependencies
No system is 100% secure. If we become aware of a data breach affecting your information, we will notify you and applicable authorities as required by law.
9. International Users
The Site is operated from the United States. If you access the Site from outside the US, your information will be transferred to and processed in the US. By using the Site, you consent to this transfer.
We do not specifically target users outside the US. If you are in the European Economic Area (EEA), United Kingdom, or other regions with comprehensive privacy laws, your local laws may grant additional rights. Contact us at privacy@haivl.org for information specific to your jurisdiction.
10. Children’s Privacy
The Site is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, contact us at privacy@haivl.org and we will delete it.
For users between 13 and 17, parental or guardian consent is required for account creation.
11. Third-Party Links and Content
The Site may contain links to third-party websites and embed third-party content (e.g., YouTube videos). We are not responsible for the privacy practices of third parties. Review their privacy policies separately.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via:
- Updated “Last Updated” date
- Email notification to registered users (for significant changes)
- On-site notice
Continued use after changes constitutes acceptance.
13. Contact Us
Privacy questions or requests:
- Email: privacy@haivl.org
- Subject line for formal requests: “CCPA Request” or “Privacy Request”
HaiVL
We respond to all legitimate privacy requests within 30 days (45 for CCPA, 90 for complex CCPA requests).