Skip to content

Test mode: data may occasionally be reset.

Privacy Policy

Last updated: June 2026

cppidioms.com ("we", "us", "the site") is operated as a personal project. This policy explains what personal data we collect, why, and your rights under the GDPR (EU) and CCPA (California).

1. Data we collect

  • Email address — to identify your account and send the activation link.
  • Display name — a unique nickname you choose, visible publicly.
  • Bio — optional free-text you write about yourself, visible publicly if set.
  • Avatar URL — provided by Google or GitHub if you use social login (a public URL, not stored locally).
  • OAuth provider ID — a numeric identifier from Google or GitHub so we can link your social account.
  • Consent timestamp — the date and time you accepted this policy.
  • Last login timestamp — for account security.
  • Comments — content you post in idiom discussions, attributed to your account.
  • Watch and notification preferences — which idioms, categories, and people you choose to follow, and how (in-app, immediate email, or daily digest) and when you want to hear about it.

We do not collect passwords in plain text, payment information, location data, or usage analytics beyond what is inherent in serving HTTP requests (server access logs with IP addresses, used only for operational troubleshooting and security monitoring, never for tracking or analytics).

2. Why we process it

  • Account management and authentication (legal basis: contract / legitimate interest).
  • Sending account-related email — activation, password reset, and notifications you've opted into (legal basis: contract).
  • GDPR consent record-keeping (legal basis: legal obligation).

We do not sell, rent, or share your personal data with third parties for marketing purposes.

3. Cookies

We set one session cookie (cppidioms_token) after you sign in. It is HttpOnly, SameSite=Lax, and expires after 7 days. No tracking or advertising cookies are used.

4. Third-party services

If you use Google Sign-In or GitHub Sign-In, those providers may set their own cookies and process your data under their own privacy policies. We only receive the data listed in §1.

We use SMTP2GO to deliver account emails (activation links, password resets, notifications). Sending you an email necessarily means SMTP2GO processes your email address and the message content on our behalf.

5. Your rights (GDPR / CCPA)

  • Access — you can view the data we hold about you on your account settings page.
  • Rectification — update your display name and bio in account settings.
  • Erasure — delete your account from the account settings page. This immediately disables login and scrubs your email, display name, avatar, and bio. Content you've contributed (comments, idiom edit history) is kept so it doesn't break for other readers, but is de-identified — no longer attributed to your name or account. We will also honour emailed erasure requests.
  • Portability — download all the data described in §1 as a JSON file, any time, from account settings.
  • Objection / restriction — contact us at the address below.

California residents: we do not sell personal information. No opt-out required under CCPA.

6. Data retention

We retain personal data for as long as your account is active. Deleting your account immediately de-identifies it, per §5's Erasure entry above — it does not delete every row referencing it, since your comments and idiom edit history stay useful (and correctly attributed to "deleted user" rather than your name) for other readers.

7. Contact

Questions or requests: privacy@cppidioms.com

8. Changes to this policy

If we make material changes we will update the "Last updated" date above and notify active users by email.