1. What We Collect and Why
What we collect and why — detailed per-category disclosure per GDPR Art 13/14, CPRA, ISO 29184 — full legal text to be drafted.
2. The Three Data Tiers
All personal and user-generated data falls into exactly one of three tiers. Each tier determines how your data is stored, how long it is retained, and what happens when you request deletion.
Persistent Data
Stored for the lifetime of your account or longer.
Deletable on Request
Deleted immediately upon confirmed request
- Account credentials and authentication tokens
- Profile information (contact, address, descriptions, images, social links)
- Mentoring profile (expertise, languages, bio, hourly rate)
- Session notes and mentoring session metadata
- Social graph (follows, followers, likes)
- RSVPs and event attendance records
- Notification preferences
- Intake form submissions
- Nostr identity: your public key and whether it was generated for you or brought your own (your secret key is never sent to us)
- Relay group membership records (which groups your public key belongs to, and when it joined)
- Other member data — contact-form messages, newsletter signups, and engagement/points activity
- Social timeline posts (no archive threshold — always fully deleted)
- Cloudflare R2 — uploaded media files
Community Record
Anonymizable but not deletable after archive threshold
- Published articles (archive: 3 months after publication)
- Article peer review comments (archive: follows article)
- Event records (archive: after event completion)
Third-Party Synced
Deletion initiated but subject to provider retention policies
- Stripe — email, payment method, transaction history (7-year legal hold)
- GoHighLevel — contact ID, email, name, newsletter list membership
- Google / Apple OAuth — email, name, profile image (received, not sent)
Moderation Record
Safety records retained independently of the accounts they concern. Not deletable on request: a member cannot erase reports made about them, and a reporter cannot retroactively withdraw a record that moderators relied on.
- Relay abuse reports (NIP-56) — the reporter's and target's public keys, plus a snapshot of the reported content. Retained even after the accounts involved are deleted.
Compliance Record
Records retained after account deletion to meet legal, audit, or operational obligations. Not user-deletable; kept under a legitimate-interest basis, not consent.
- Consent receipts — which policy version you accepted, when, and from what IP. Retained after account deletion as proof consent existed.
- Deletion audit log — a record that your account was deleted and what was removed. Kept as proof the deletion occurred.
- Screenname history — retained after deletion so federated servers get a stable 410 Gone for handles you no longer use.
Temporary Data
Retained only as long as necessary, then automatically purged
- Mentoring session signaling and WebRTC connection metadata
- Whiteboard state (purged 30 min after session ends)
- Real-time chat messages during mentoring sessions
- Session video/audio streams (not recorded server-side)
- OAuth tokens and transient authentication state
- IP addresses and user-agent strings (90-day analytics window)
- Email verification, magic-link, and email-change tokens (expire per config)
- Pending relay group join and leave requests (joins: until an admin acts; leaves: a 24-hour grace period)
Peer Data
Exchanged directly between participants, or propagated to servers we do not operate; not controlled by Pana MIA Club after transmission
In the Wind
Published to an open, unbounded set of servers we do not operate. Deletion requests are advisory only -- a remote server MAY honor them and MAY ignore them. Neither Pana MIA Club nor anyone else can guarantee retraction once content has propagated.
- Social posts, replies, likes, and follows federated via ActivityPub — a best-effort Delete is sent, but remote servers may ignore it
- Anything you publish to Nostr — group chat, profile metadata, RSVPs. We can remove it from our own relay; no one can remove it from Nostr at large.
Seen by Participants
Seen directly by the people you shared it with. We do not retain it; they may.
- Video and audio streams during mentoring sessions (WebRTC peer-to-peer)
- Whiteboard content visible to session participants
- Chat messages seen by the other participant before deletion
- Co-author content shared during article collaboration
- Profile information visible to other users
- Event RSVP and attendance information visible to organizers and attendees
- Information shared at in-person events (verbal, written, photos)
3. The Archive Threshold
Certain content becomes part of the community record after a defined period. All user-generated content is CC BY or CC BY-SA licensed. The CC license is irrevocable — once granted, downstream recipients retain their rights regardless of whether the licensor stops distributing.
Archive threshold details — when content becomes permanent, deletion vs anonymization options — full legal text to be drafted.
5. Your Content Is CC-Licensed
All content you publish on Pana MIA Club is licensed under Creative Commons (CC BY 4.0, CC BY-SA 4.0, or CC0 1.0, your choice). This means the grant survives even if the content is later removed from the platform. Under CC BY and CC BY-SA you may ask us to remove your name from archived content; CC0 requires no attribution in the first place, so we simply stop displaying it. See our Terms of Service for details.
6. Your Choices and Rights
User rights — access, delete, correct, port, opt out, anonymize (GDPR + CPRA + ISO 29184) — full legal text to be drafted.
7. How We Protect Your Data
Security measures — encryption at rest/transit, password hashing, WAF, environment variable segregation — full legal text to be drafted.
8. Global Privacy Control (GPC)
We honor the Global Privacy Control signal. When your browser sendsSec-GPC: 1, we treat it as a valid CPRA opt-out of sale/sharing and disable any non-essential analytics sharing.
9. Children's Privacy
Pana MIA Club is not directed at children under 18. We do not knowingly collect personal information from minors. If we discover that a user is under 18, their account will be terminated and their data deleted.
10. International Users
International users — jurisdiction-neutral framing per ISO 29184 — full legal text to be drafted.
11. How to Contact Us
For privacy inquiries, data access requests, or to report a suspected data breach:
Pana MIA Club, Corp.
Email: hola@pana.social
12. How We Notify You of Changes
Change notification — versioned updates, email + in-app notice, advance notice period — full legal text to be drafted.