diff --git a/src/privacy.html b/src/privacy.html index b851cb06..c7beeddb 100644 --- a/src/privacy.html +++ b/src/privacy.html @@ -10,31 +10,119 @@
Last updated: January 3, 2026
Impro is a third-party web client for Bluesky. It is not affiliated with - Bluesky PBC. + Bluesky PBC. This policy describes the web client. The services you + connect to and any community plugins you enable have their own data + practices.
+ ++ We do not collect or store personal data on our servers. This statement + does not mean that using Impro involves no third-party processing: + hosting, analytics, account services, and the features described below + involve requests to other providers. +
++ Impro is hosted on Cloudflare and uses Cloudflare Web Analytics, which + does not use cookies or track individual users. Cloudflare may process + technical data, such as country-level location and device type, as + described in Cloudflare's Privacy Policy. +
+ ++ Impro uses Atproto OAuth to authorize access to your account. Session + credentials are stored in your browser's local storage and used to + make authenticated requests to your account's services. Impro requests + permissions for a full social client, including reading and publishing + posts, managing follows and blocks, accessing preferences and + bookmarks, and reading and sending chat messages. Review the + permissions shown when authorizing Impro. +
++ Where server-signed OAuth client assertions are enabled, your browser + also sends the authorization server's address to Impro's signing + endpoint. That request is used to obtain a client assertion; it does + not contain your account's access or refresh tokens. +
+ +- Data we collect: We do not collect or store any - personal data on our servers. + Impro stores session information, device settings, and some plugin data + in your browser. Clearing Impro's site data removes browser-held data; + it does not delete posts, messages, preferences, or other data held by + your account's services, or revoke server-side authorizations.
- Authentication: This app uses Atproto OAuth for secure - authentication. Session data is stored in your browser's local storage - and is only used to communicate with Bluesky's services. + Account actions and data requests are sent to the relevant services, + including your account host, the selected feed and profile service, + and the chat service. Bluesky-operated services are governed by + Bluesky's Privacy Policy. If you use another account host or select an + alternative service, that provider's practices also apply. +
+ ++ Impro uses Microcosm's Constellation service to look up records linking + to a subject, including replies used to restore thread context. These + requests include the subject identifier and the type of link requested. + Impro also uses Microcosm's Slingshot service for identity resolution + and plugin-accessible record lookups. Those requests include the handle, + account identifier, or record identifiers being looked up.
- Hosting and analytics: This app is hosted on - Cloudflare. We use Cloudflare Web Analytics, which is privacy-focused - and does not use cookies or track individual users. Cloudflare may - process limited technical data (such as country-level location and - device type) as described in Cloudflare's Privacy Policy. + These requests go from your browser to the service, which receives the + query and connection information such as your Internet Protocol (IP) + address. They do not include your Bluesky session tokens.
- Your Bluesky data: All interactions with your Bluesky - account are governed by Bluesky's Privacy Policy. + Loading media and other external resources involves requests to their + providers. For example, playing an embedded YouTube video loads a + player from YouTube's privacy-enhanced domain. The provider's own + privacy practices apply when its content is loaded.
+ ++ Community plugins are optional third-party code. Browsing the plugin + registry and downloading plugins involves requests to their hosting + providers, including GitHub or Tangled repositories. +
++ Plugins run in a sandbox, with network requests mediated by Impro's + permission system. Access to private account data, such as mutes, + bookmarks, notifications, and preferences, requires permission. + Plugins can also store data locally or in account preferences. +
++ A plugin with permission to access data and contact an external + destination may send that data to the destination. The sandbox does + not guarantee how a plugin uses permissions you grant. Review each + plugin's permissions and its developer's data practices before + enabling it. +
+ ++ Push notifications require selecting a notification service and + enabling notifications. Setup registers your browser's push + subscription with the selected service. If the service requires a + separate authorization step, Impro sends it your account identifier, + a return address, and whether you requested chat previews. +
++ The notification service and your browser's push provider are + additional parties involved in delivery. Review the selected service's + permissions and privacy practices, particularly before enabling chat + previews. You can disable push notifications in Impro's settings. +
+ +- Contact: - GitHub + For questions about this policy, contact the project through + GitHub. + GitHub issues are public; do not include passwords, session tokens, + private messages, or other sensitive account information.