A few updates to our Terms of Service, Privacy Policy, and subprocessor list. None of these changes impact your rights to your own data or send that data anywhere new, so this change is effective today, but we are disclosing these changes for transparency.
Public profiles now have explicit terms
Public profiles and share links let you show curated subsets of your system to people outside it. The content licence in our Terms was written before that feature existed, and covered it only by general language about processing content "for features you've enabled". Now that the feature is live, it deserved to be explicitly named along with its implications rather than left implicit.
Terms §7.1 now says exactly what publishing involves:
- It applies only to content you deliberately added to a view and then published. Nothing else you store is covered, and nothing is published by default.
- It ends when you revoke permission.
- It transfers to nobody. We gain no right to reuse, relicense, or promote anything you publish.
Two things we cannot do for you, which are now stated on the page rather than assumed: revoking stops us serving your content, but it cannot reach copies other people already made; and a share link is a secret that anyone holding it can forward. If a link reaches someone you did not intend, rotate or revoke it.
Terms §4 also now records that publishing requires you to be 18 or older. The app has always enforced this but it was not documented in the terms.
Email now goes through Amazon SES
Transactional email (verification, password resets, notifications) previously went through Twilio SendGrid. It now goes through Amazon SES, in the same EU region as the rest of our infrastructure.
This represents one fewer company in the list of those who touch your data. Additionally, because SES runs in eu-west-1 alongside the rest of our production infrastructure, outbound email is now no longer an international transfer for EU users.
The full list is on the subprocessors page, which now has a historical changes section.
Fixed outdated information in mobile apps' privacy policies
Both mobile privacy policies still said the apps did not use push notifications, and were not updated when that feature shipped. Both have been updated with an overview and technical details including which providers are involved and what they can see.
The Android policy now also documents that the Play build carries Firebase Cloud Messaging while the open build has no push provider support. The iOS policy has also been corrected on two points about how session tokens are stored on the device. The detail is in §4.1 and §10.
Housekeeping
The Terms had several leftover lines that applied to the pre-release public beta environment. Production commitments and public-beta-specific caveats are now separated cleanly (§3b and §3c).
We also tidied up how we commit to notifying you about changes, as this had drifted between different documents and has still not been exercised live. There is now a single description: material changes that fundamentaly alter the promises made get an in-app banner and an email to account owners, with at least 14 days notice. Clarifications like this one get the page date updated, and a notification post like this when the changes are notable enough to justify one.
Questions, as always, to [email protected] or the Discord.