Privacy Policy

Version 0.2 Draft

The English-language version of this policy shall take precedence over any translations.

Privacy at a Glance

Every piece of data we handle falls into one of three tiers. Filter by tier to see what we collect, why, how long we keep it, and who it is shared with.

Account

Your login details — email, password, and the sign-in tokens that keep you logged in.

Deletable
Source:
You provide
Purpose:
Authentication and identity
Retention:
Account lifetime
Shared with:
OAuth providers
Profile

Your public directory listing: contact info, address, description, photos, and social links.

Deletable
Source:
You provide
Purpose:
Directory listing and community
Retention:
Account lifetime
Shared with:
Public / ActivityPub
Mentoring Profile

The mentor listing you fill out — your expertise, languages, short bio, and hourly rate.

Deletable
Source:
You provide
Purpose:
Mentor directory
Retention:
Account lifetime
Shared with:
Public
Session Notes

Notes you or your mentor write about a session, plus basic details like its topic.

Deletable
Source:
You provide
Purpose:
Mentoring records
Retention:
Account lifetime
Shared with:
None
Social Graph

Who you follow and the posts you've liked.

Deletable
Source:
Your recorded choices
Purpose:
Social features
Retention:
Account lifetime
Shared with:
ActivityPub peers
RSVPs

The events you've said you're attending.

Deletable
Source:
Your recorded choices
Purpose:
Event management
Retention:
Account lifetime
Shared with:
Organizers / attendees
Notification Preferences

Your choices about which alerts and emails we send you.

Deletable
Source:
You provide
Purpose:
Communication preferences
Retention:
Account lifetime
Shared with:
None
Intake Form Submissions

The answers you gave on the become-a-pana join form.

Deletable
Source:
You provide
Purpose:
Membership onboarding
Retention:
Account lifetime
Shared with:
None
Nostr Identity

Your public key for the community messaging network. Your secret key never leaves your device.

Deletable
Source:
You provide
Purpose:
Relay identity and NIP-05 handle
Retention:
Account lifetime
Shared with:
Public / Nostr relays
Relay Group Membership

Which community messaging groups your key belongs to, and when it joined.

Deletable
Source:
Your recorded choices
Purpose:
Relay group access control
Retention:
Account lifetime
Shared with:
Group members
Other Member Data

Smaller bits you've given us: contact-form messages, newsletter signups, and your activity points.

Deletable
Source:
You provide
Purpose:
Contact, newsletter, and engagement
Retention:
Account lifetime
Shared with:
None
Social Posts

Your posts, replies, and reposts on the community timeline.

Deletable
Source:
You provide
Purpose:
Social expression
Retention:
Always deletable
Shared with:
Public / ActivityPub
Uploads

Photos and files you've uploaded, stored on Cloudflare.

Deletable
Source:
You provide
Purpose:
Media hosting
Retention:
Follows content
Shared with:
Cloudflare R2 / Public
Articles

Articles you've published to the community.

Deletable
Community Record
Source:
You provide
Purpose:
Community knowledge
Retention:
Archive: 3 months
Shared with:
Public / ActivityPub
Article Reviews

Feedback you leave reviewing another member's article before it's published.

Deletable
Community Record
Source:
You provide
Purpose:
Editorial quality
Retention:
Follows article
Shared with:
Public
Events

Events you've created, including their details and description.

Community Record
Source:
You provide
Purpose:
Community events
Retention:
Archive: after event
Shared with:
Public
Payments

Your donation and membership payments, handled by Stripe.

3rd-Party Synced
Source:
You provide
Purpose:
Donations, memberships, merchandise
Retention:
Stripe: 7-year hold
Shared with:
Stripe / GoHighLevel
CRM / Newsletter

Your contact record in our newsletter/CRM system (GoHighLevel), including newsletter list membership.

3rd-Party Synced
Source:
You provide
Purpose:
Contact management and newsletter
Retention:
Account lifetime
Shared with:
GoHighLevel
OAuth Identity

Basic info (email, name, picture) we receive when you sign in with Google or Apple. Nothing is sent back to them.

3rd-Party Synced
Source:
OAuth provider
Purpose:
Authentication
Retention:
Account lifetime
Shared with:
Google / Apple
Abuse Reports

Reports members file about abusive messages on the relay. Kept even after an account leaves, so moderation records survive.

Moderation Record
Source:
A member reports
Purpose:
Safety and moderation
Retention:
Outlives account deletion
Shared with:
Moderators
Consent Receipts

A record that you accepted a given version of our policies — proof the consent happened.

Compliance Record
Source:
Your recorded choices
Purpose:
Proof of consent
Retention:
Outlives account deletion
Shared with:
None
Deletion Audit Log

A record that an account was deleted and what was removed — kept as proof the deletion took place.

Compliance Record
Source:
Automatic
Purpose:
Deletion audit trail
Retention:
Outlives account deletion
Shared with:
None
Screenname Redirects

Usernames you've used before, kept so links to a former handle still resolve on other servers.

Compliance Record
Source:
Automatic
Purpose:
Federation continuity
Retention:
Outlives account deletion
Shared with:
ActivityPub peers
Session Signaling

Behind-the-scenes connection info that sets up a live mentoring call. Discarded when the session ends.

Auto-Purged
Source:
Session activity
Purpose:
Real-time collaboration
Retention:
Session duration
Shared with:
Session participants
Whiteboard State

The shared drawing board during a mentoring session. Erased 30 minutes after it ends.

Auto-Purged
Source:
Session activity
Purpose:
Real-time collaboration
Retention:
Session + 30 min
Shared with:
Session participants
Session Chat

Chat messages typed during a live mentoring session.

Auto-Purged
Source:
Session activity
Purpose:
Real-time collaboration
Retention:
Session duration
Shared with:
Session participants
Session Video/Audio

The live video and audio of a session. We don't record it.

Auto-Purged
Source:
Session activity
Purpose:
Real-time collaboration
Retention:
Session duration
Shared with:
Session participants
OAuth Tokens

Temporary keys that keep your Google or Apple sign-in active.

Auto-Purged
Source:
OAuth provider
Purpose:
Authentication
Retention:
Token lifetime
Shared with:
Google / Apple
Analytics (IP, User-Agent)

Your IP address and browser type, kept briefly (90 days) to understand site traffic.

Auto-Purged
Source:
Automatic
Purpose:
Site analytics
Retention:
90 days
Shared with:
Cloudflare
Verification Tokens

Short-lived codes for signing in, verifying your email, or changing it. They expire quickly.

Auto-Purged
Source:
Automatic
Purpose:
Authentication
Retention:
Expires per config
Shared with:
None
Pending Group Requests

Requests to join or leave a Resilience Network group that are waiting on approval or a short grace period.

Auto-Purged
Source:
Your recorded choices
Purpose:
Join approval and leave debounce
Retention:
Admin action / 24h
Shared with:
Admins
Federated Social Content

Posts and follows that leave our servers to reach Mastodon and similar networks. Once out, we can ask other servers to delete them but can't force it.

In the Wind
Source:
You publish
Purpose:
Social federation
Retention:
Not recallable
Shared with:
ActivityPub peers (open set)
Nostr Events

Anything you publish to the Nostr network — group chats, profile info, RSVPs. We can remove it from our relay, but no one can remove it from Nostr everywhere.

In the Wind
Source:
You publish
Purpose:
Community relay and Nostr interoperability
Retention:
Not recallable
Shared with:
Nostr relays (open set)
Session Streams

The live video and audio of a mentoring call, sent directly between you and the other person, not through us.

Participant-Seen
Source:
Session activity
Purpose:
Real-time collaboration
Retention:
Not retained by us
Shared with:
Session participants
Whiteboard Content

What you draw on the shared board, visible to the others in your session.

Participant-Seen
Source:
Session activity
Purpose:
Real-time collaboration
Retention:
Not retained by us
Shared with:
Session participants
Seen Chat Messages

Session chat the other person already saw before it was deleted.

Participant-Seen
Source:
Session activity
Purpose:
Real-time collaboration
Retention:
Not retained by us
Shared with:
Session participants
Co-Author Content

Draft article content you share with a co-author while writing together.

Participant-Seen
Source:
You provide
Purpose:
Article collaboration
Retention:
Not retained by us
Shared with:
Co-authors
Visible Profile Info

The parts of your profile other members can see.

Participant-Seen
Source:
You provide
Purpose:
Community visibility
Retention:
Not retained by us
Shared with:
Other members
Event Attendance

Your RSVP and attendance, visible to the event's organizers and other attendees.

Participant-Seen
Source:
Your recorded choices
Purpose:
Event coordination
Retention:
Not retained by us
Shared with:
Organizers / attendees
In-Person Exchanges

Anything you share face-to-face at an event — spoken, written, or photographed by others.

Participant-Seen
Source:
Physical presence
Purpose:
Community events
Retention:
Not retained by us
Shared with:
People present

Plain-Language Summary

What we collect: Account info you provide (email, name, profile details), content you create (articles, posts, photos), and minimal automatic data (IP address, browser info) for 90 days.

Three data tiers: Your data is either Persistent (stored while your account is active), Temporary (auto-deleted after use), or Peer Networking (exchanged directly between users, outside our control after transmission).

Deletion: Most of your data is deleted immediately on request. Content that becomes community record (articles after 3 months, completed events) can be anonymized but not fully removed, because the CC license you chose is irrevocable. Social posts are always fully deletable. Two things are never deleted on request: abuse reports, which have to outlive the accounts they concern, and anything already published to a network we do not run.

Nostr and federation: If you join the Resilience Network, your public key and group membership live in our systems and are deleted with your account — but posts you published to Nostr are signed, permanent, and hosted by relays we have no relationship with. We can remove them from our relay. Nobody can remove them from Nostr at large. ActivityPub works the same way: we send a Delete, and remote servers may honor it or ignore it. Your secret key (nsec) is never sent to us and we cannot recover it for you.

Third parties: We share data with Stripe (payments), GoHighLevel (CRM and newsletter), Cloudflare (hosting and email), and OAuth providers (Google, Apple). Each provider may retain data per their own policies after we request deletion.

Your rights: You can access, correct, delete, or export your data. We honor Global Privacy Control (GPC) signals. No data is sold.

No minors: You must be 18 or older. Accounts belonging to minors are terminated and data deleted.

1. What We Collect and Why

What we collect and why — detailed per-category disclosure per GDPR Art 13/14, CPRA, ISO 29184 — full legal text to be drafted.

2. The Three Data Tiers

All personal and user-generated data falls into exactly one of three tiers. Each tier determines how your data is stored, how long it is retained, and what happens when you request deletion.

Persistent Data

Stored for the lifetime of your account or longer.

Deletable on Request

Deleted immediately upon confirmed request

  • Account credentials and authentication tokens
  • Profile information (contact, address, descriptions, images, social links)
  • Mentoring profile (expertise, languages, bio, hourly rate)
  • Session notes and mentoring session metadata
  • Social graph (follows, followers, likes)
  • RSVPs and event attendance records
  • Notification preferences
  • Intake form submissions
  • Nostr identity: your public key and whether it was generated for you or brought your own (your secret key is never sent to us)
  • Relay group membership records (which groups your public key belongs to, and when it joined)
  • Other member data — contact-form messages, newsletter signups, and engagement/points activity
  • Social timeline posts (no archive threshold — always fully deleted)
  • Cloudflare R2 — uploaded media files

Community Record

Anonymizable but not deletable after archive threshold

  • Published articles (archive: 3 months after publication)
  • Article peer review comments (archive: follows article)
  • Event records (archive: after event completion)

Third-Party Synced

Deletion initiated but subject to provider retention policies

  • Stripe — email, payment method, transaction history (7-year legal hold)
  • GoHighLevel — contact ID, email, name, newsletter list membership
  • Google / Apple OAuth — email, name, profile image (received, not sent)

Moderation Record

Safety records retained independently of the accounts they concern. Not deletable on request: a member cannot erase reports made about them, and a reporter cannot retroactively withdraw a record that moderators relied on.

  • Relay abuse reports (NIP-56) — the reporter's and target's public keys, plus a snapshot of the reported content. Retained even after the accounts involved are deleted.

Compliance Record

Records retained after account deletion to meet legal, audit, or operational obligations. Not user-deletable; kept under a legitimate-interest basis, not consent.

  • Consent receipts — which policy version you accepted, when, and from what IP. Retained after account deletion as proof consent existed.
  • Deletion audit log — a record that your account was deleted and what was removed. Kept as proof the deletion occurred.
  • Screenname history — retained after deletion so federated servers get a stable 410 Gone for handles you no longer use.

Temporary Data

Retained only as long as necessary, then automatically purged

  • Mentoring session signaling and WebRTC connection metadata
  • Whiteboard state (purged 30 min after session ends)
  • Real-time chat messages during mentoring sessions
  • Session video/audio streams (not recorded server-side)
  • OAuth tokens and transient authentication state
  • IP addresses and user-agent strings (90-day analytics window)
  • Email verification, magic-link, and email-change tokens (expire per config)
  • Pending relay group join and leave requests (joins: until an admin acts; leaves: a 24-hour grace period)

Peer Data

Exchanged directly between participants, or propagated to servers we do not operate; not controlled by Pana MIA Club after transmission

In the Wind

Published to an open, unbounded set of servers we do not operate. Deletion requests are advisory only -- a remote server MAY honor them and MAY ignore them. Neither Pana MIA Club nor anyone else can guarantee retraction once content has propagated.

  • Social posts, replies, likes, and follows federated via ActivityPub — a best-effort Delete is sent, but remote servers may ignore it
  • Anything you publish to Nostr — group chat, profile metadata, RSVPs. We can remove it from our own relay; no one can remove it from Nostr at large.

Seen by Participants

Seen directly by the people you shared it with. We do not retain it; they may.

  • Video and audio streams during mentoring sessions (WebRTC peer-to-peer)
  • Whiteboard content visible to session participants
  • Chat messages seen by the other participant before deletion
  • Co-author content shared during article collaboration
  • Profile information visible to other users
  • Event RSVP and attendance information visible to organizers and attendees
  • Information shared at in-person events (verbal, written, photos)

3. The Archive Threshold

Certain content becomes part of the community record after a defined period. All user-generated content is CC BY or CC BY-SA licensed. The CC license is irrevocable — once granted, downstream recipients retain their rights regardless of whether the licensor stops distributing.

Archive threshold details — when content becomes permanent, deletion vs anonymization options — full legal text to be drafted.

4. Who We Share Data With

Third-party sharing details — Stripe, GoHighLevel, Cloudflare (hosting, R2, email), OAuth providers, ActivityPub federation peers, Nostr relays — full legal text to be drafted.

5. Your Content Is CC-Licensed

All content you publish on Pana MIA Club is licensed under Creative Commons (CC BY 4.0, CC BY-SA 4.0, or CC0 1.0, your choice). This means the grant survives even if the content is later removed from the platform. Under CC BY and CC BY-SA you may ask us to remove your name from archived content; CC0 requires no attribution in the first place, so we simply stop displaying it. See our Terms of Service for details.

6. Your Choices and Rights

User rights — access, delete, correct, port, opt out, anonymize (GDPR + CPRA + ISO 29184) — full legal text to be drafted.

7. How We Protect Your Data

Security measures — encryption at rest/transit, password hashing, WAF, environment variable segregation — full legal text to be drafted.

8. Global Privacy Control (GPC)

We honor the Global Privacy Control signal. When your browser sendsSec-GPC: 1, we treat it as a valid CPRA opt-out of sale/sharing and disable any non-essential analytics sharing.

9. Children's Privacy

Pana MIA Club is not directed at children under 18. We do not knowingly collect personal information from minors. If we discover that a user is under 18, their account will be terminated and their data deleted.

10. International Users

International users — jurisdiction-neutral framing per ISO 29184 — full legal text to be drafted.

11. How to Contact Us

For privacy inquiries, data access requests, or to report a suspected data breach:

Pana MIA Club, Corp.
Email: hola@pana.social

12. How We Notify You of Changes

Change notification — versioned updates, email + in-app notice, advance notice period — full legal text to be drafted.

Related