Privacy notice
Last updated 24 September 2026
Draft for legal review. This text has not yet been checked by a lawyer.
1. Who is responsible for your data
The people who run corddit decide how your personal data is used and are responsible for it as the personal information controller under the Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations.
Our Data Protection Officer can be reached at privacy@corddit.com.
2. Public by design
corddit is a public site. Your username, and everything you post in forums, comments and chat, can be read by anyone, including people without an account and search engines. Do not post anything you want to keep private.
3. What we collect
- Account details: email address, username, password and your confirmation that you are 18 or over. We store only a hashed version of your password, never the password itself.
- Content you post: posts, comments, chat messages, images (up to 4 per post and 1 per chat message), hubs you create, and chat messages you promote into posts. Your browser shrinks and re-encodes images before upload, which removes hidden metadata such as the GPS location in phone photos.
- Notifications: replies, mentions and promotions addressed to you, whether you have read them, and your email notification choices.
- Activity: your votes and saved posts.
- Reports: reports you file, including the reason and any details you add.
- Account records: when your account was created and updated, and moderation decisions about your account or content.
- Technical data: IP address and browser user agent, held in the security logs of our hosting providers.
We do not use advertising, analytics or tracking tools.
4. Why we use it and our lawful criteria
| Purpose | Lawful criterion |
|---|---|
| Creating and running your account, showing your content, votes and saved posts, real-time chat | Needed to fulfil our contract with you (these terms) |
| Sending service emails, such as password resets, notifications and report updates | Needed to fulfil our contract with you |
| Keeping the service secure, preventing spam, bots and abuse, applying rate limits | Our legitimate interests |
| Handling reports, moderating content, suspending accounts and keeping safety records | Our legitimate interests and compliance with a legal obligation |
| Reporting illegal content and responding to lawful requests from Philippine authorities | Compliance with a legal obligation |
Where we rely on legitimate interests, our interest is keeping corddit safe and usable for everyone. You can object to this use. See section 8.
5. Who we share it with
We use these service providers (personal information processors). They act on our instructions only.
| Provider | What they do | Where |
|---|---|---|
| Supabase | Database, authentication, real-time chat and image storage | AWS Singapore (ap-southeast-1) |
| Vercel | Web hosting and edge network. Server functions run in Singapore. | Global, including the United States |
| Resend | Sending service and notification emails | United States |
| Sentry | Error reports so we can fix faults. We configure it not to collect cookies, IP addresses or email addresses. | United States |
| Cloudflare Turnstile | Optional anti-bot check. It processes your IP address and browser signals. | Global |
We may also share data with Philippine law enforcement, courts, regulators or other authorities where the law requires it, or where it is needed to protect someone from serious harm. We do not sell your data.
Links, previews and videos
When you post a link, our server visits that page to build a preview (title, description and image). The site you linked does not learn who you are from this. When other people view the preview, its image loads from the linked site, which can see their IP address. YouTube, TikTok and Instagram players load only after someone presses play; YouTube uses its privacy-enhanced mode. After that, the provider's own privacy policy applies.
6. Transfers outside the Philippines
Our providers process data outside the Philippines, in Singapore, the United States and elsewhere. We remain responsible for your data when a provider processes it for us, in the Philippines or abroad. We use contracts that require each provider to protect your data to a standard comparable to the Data Privacy Act. You can ask us for details at privacy@corddit.com.
7. How long we keep it
- Account data and content: until you delete it or delete your account.
- Snapshots of removed content held in reports: 12 months after the report is resolved.
- Reports you filed: kept after you delete your account, with your identity removed, as safety records.
- Images: deleted from storage within 24 hours of the post, message or account being deleted. Uploads you never post are deleted after 24 hours.
- Notifications: until you delete your account.
- Error reports: up to 90 days in Sentry.
- Provider security logs: in line with the provider retention periods, typically up to 90 days.
- Backups: deleted data rolls off backups within 30 days.
When you delete your account, we permanently delete your profile, posts, comments, chat messages, images, notifications, votes and saved posts. Hubs you created stay, without your name. Reports you filed stay, with your identity removed.
8. Your rights
Under the Data Privacy Act of 2012 you have the right to:
- Be informed: know whether and how we process your personal data.
- Access: get a copy of your personal data and details of how we use it.
- Object: object to processing, including processing based on our legitimate interests.
- Erasure or blocking: have your data suspended, withdrawn, blocked, removed or destroyed.
- Damages: be compensated for damage caused by inaccurate, incomplete, outdated, false or unlawfully obtained data, or unauthorised use of your data.
- Data portability: get your data in a structured, commonly used electronic format.
- Rectification: have inaccurate data corrected.
- File a complaint: complain to the National Privacy Commission. See section 12.
You can do much of this yourself in Settings: change your username, email and password, edit or delete your content, download your data as a JSON file, and delete your account.
For anything else, email our Data Protection Officer at privacy@corddit.com. We may need to confirm your identity. We aim to respond within 15 working days, in line with National Privacy Commission guidance. If we need more time, we will tell you why, and we will not take more than a further 15 working days.
9. Cookies and local storage
We use only what is strictly necessary to run corddit:
| Name | Type | Purpose |
|---|---|---|
| sb-...-auth-token | Cookie, set when you log in | Keeps you signed in |
| Theme preference | Local storage in your browser | Remembers the light or dark theme you chose |
| Recently visited hubs | Local storage in your browser | Shows the hubs you visited recently. It never leaves your device. |
We do not use advertising or analytics cookies. If we ever add them, we will ask for your consent first.
10. Age limit
You must be 18 or over to use corddit. If we find that an account belongs to someone under 18, we will remove it. If you believe someone under 18 has an account, email privacy@corddit.com.
11. Security and personal data breaches
We encrypt data in transit, hash passwords and restrict access to personal data. No online service is completely secure. If a personal data breach occurs and the law requires notification, we will notify the National Privacy Commission and the people affected within 72 hours of becoming aware of it.
12. Complaints
If you are unhappy with how we handle your data, contact our Data Protection Officer first at privacy@corddit.com. You also have the right to complain to the National Privacy Commission at privacy.gov.ph or by email to complaints@privacy.gov.ph.
13. Changes to this notice
We will update this notice when our practices change. The date at the top shows the latest version. See also our terms of use.