Privacy policy
How CityVoice handles anonymous device identifiers, location, public content, files and privacy requests.
Who is responsible?
CityVoice is currently operated as a pre-launch project. The legal name, country and professional address of the data controller will be published here before commercial launch. Privacy requests can already be sent to privacy@cityvoice.world.
Data we process
CityVoice creates a random device_id on the server when an interactive feature needs it. It identifies a browser installation for moderation, voting and rate limiting. It is not linked to a real identity.
With your explicit browser permission, latitude and longitude are used to determine your country and suggest a city through CityVoice’s local PostGIS reference data. Your IP address is used for security, abuse prevention and rate limiting; it is not used to determine your city and is never displayed publicly.
Posts, replies and chat messages may contain text, tags and an optional photo or PDF. They are public by nature once published. The device_id, precise coordinates, IP address and internal risk signals are never public.
Payments and translation
Premium payment data held by Stripe, including transaction details and an optional billing email, is kept in a separate billing schema. It is never joined in the database to a device_id or published content. An activation code is verified separately and only the premium expiry is recorded beside the anonymous device.
When you request a translation, post text may be processed by LibreTranslate hosted on CityVoice infrastructure. No external translation provider receives that text.
Storage and retention
- device_id cookie: essential, HttpOnly, SameSite=Lax, retained for 2 years.
- cityvoice:ticker-seen local storage: remembers ticker items already opened; retained until browser storage is cleared.
- cityvoice:my-location session storage: location cache valid for 5 minutes and removed at the end of the browser session.
- cityvoice:recovery-key local storage: optional recovery secret created only on request and retained until you replace it, delete your history or clear browser storage.
- Consented location cache on the server: retained in Redis for 1 hour.
- IP rate-limit keys in Redis: retained between 10 seconds and 1 hour. Security/access logs containing an IP: retained for no more than 30 days.
- Public content: retained until deletion or moderation. Approved files follow the related content. Removed data leaves active systems within 30 days; encrypted backups expire within 30 days.
- Advertising and analytics storage: disabled by default and only activated according to the choice recorded by the Google CMP. The exact Google vendors and storage are displayed in “Privacy and cookie settings”.
Your rights and anonymous deletion
You may request access, a portable copy, correction where applicable, restriction, objection or deletion. The “My data” page uses the current HttpOnly device cookie to show and delete the related history.
You may also generate a one-time recovery key. Only its cryptographic hash is stored. Keep the key privately: it lets you recover or delete the history from another browser. It is separate from premium activation codes and cannot link payment data to content.
Public removal starts immediately after a verified deletion request. Technical erasure completes within 30 days, including the normal backup rotation. Minimal information may be retained longer only where required by law or strictly necessary to establish or defend legal claims. Contact privacy@cityvoice.world for help or to exercise a right.