diff --git a/src/privacy.html b/src/privacy.html index b851cb06..c7beeddb 100644 --- a/src/privacy.html +++ b/src/privacy.html @@ -10,31 +10,119 @@

Last updated: January 3, 2026

Impro is a third-party web client for Bluesky. It is not affiliated with - Bluesky PBC. + Bluesky PBC. This policy describes the web client. The services you + connect to and any community plugins you enable have their own data + practices.

+ +

Data collection, hosting, and analytics

+

+ We do not collect or store personal data on our servers. This statement + does not mean that using Impro involves no third-party processing: + hosting, analytics, account services, and the features described below + involve requests to other providers. +

+

+ Impro is hosted on Cloudflare and uses Cloudflare Web Analytics, which + does not use cookies or track individual users. Cloudflare may process + technical data, such as country-level location and device type, as + described in Cloudflare's Privacy Policy. +

+ +

Authentication and account access

+

+ Impro uses Atproto OAuth to authorize access to your account. Session + credentials are stored in your browser's local storage and used to + make authenticated requests to your account's services. Impro requests + permissions for a full social client, including reading and publishing + posts, managing follows and blocks, accessing preferences and + bookmarks, and reading and sending chat messages. Review the + permissions shown when authorizing Impro. +

+

+ Where server-signed OAuth client assertions are enabled, your browser + also sends the authorization server's address to Impro's signing + endpoint. That request is used to obtain a client assertion; it does + not contain your account's access or refresh tokens. +

+ +

Browser storage and account services

- Data we collect: We do not collect or store any - personal data on our servers. + Impro stores session information, device settings, and some plugin data + in your browser. Clearing Impro's site data removes browser-held data; + it does not delete posts, messages, preferences, or other data held by + your account's services, or revoke server-side authorizations.

- Authentication: This app uses Atproto OAuth for secure - authentication. Session data is stored in your browser's local storage - and is only used to communicate with Bluesky's services. + Account actions and data requests are sent to the relevant services, + including your account host, the selected feed and profile service, + and the chat service. Bluesky-operated services are governed by + Bluesky's Privacy Policy. If you use another account host or select an + alternative service, that provider's practices also apply. +

+ +

Additional lookups and embedded content

+

+ Impro uses Microcosm's Constellation service to look up records linking + to a subject, including replies used to restore thread context. These + requests include the subject identifier and the type of link requested. + Impro also uses Microcosm's Slingshot service for identity resolution + and plugin-accessible record lookups. Those requests include the handle, + account identifier, or record identifiers being looked up.

- Hosting and analytics: This app is hosted on - Cloudflare. We use Cloudflare Web Analytics, which is privacy-focused - and does not use cookies or track individual users. Cloudflare may - process limited technical data (such as country-level location and - device type) as described in Cloudflare's Privacy Policy. + These requests go from your browser to the service, which receives the + query and connection information such as your Internet Protocol (IP) + address. They do not include your Bluesky session tokens.

- Your Bluesky data: All interactions with your Bluesky - account are governed by Bluesky's Privacy Policy. + Loading media and other external resources involves requests to their + providers. For example, playing an embedded YouTube video loads a + player from YouTube's privacy-enhanced domain. The provider's own + privacy practices apply when its content is loaded.

+ +

Community plugins

+

+ Community plugins are optional third-party code. Browsing the plugin + registry and downloading plugins involves requests to their hosting + providers, including GitHub or Tangled repositories. +

+

+ Plugins run in a sandbox, with network requests mediated by Impro's + permission system. Access to private account data, such as mutes, + bookmarks, notifications, and preferences, requires permission. + Plugins can also store data locally or in account preferences. +

+

+ A plugin with permission to access data and contact an external + destination may send that data to the destination. The sandbox does + not guarantee how a plugin uses permissions you grant. Review each + plugin's permissions and its developer's data practices before + enabling it. +

+ +

Optional push notifications

+

+ Push notifications require selecting a notification service and + enabling notifications. Setup registers your browser's push + subscription with the selected service. If the service requires a + separate authorization step, Impro sends it your account identifier, + a return address, and whether you requested chat previews. +

+

+ The notification service and your browser's push provider are + additional parties involved in delivery. Review the selected service's + permissions and privacy practices, particularly before enabling chat + previews. You can disable push notifications in Impro's settings. +

+ +

Contact

- Contact: - GitHub + For questions about this policy, contact the project through + GitHub. + GitHub issues are public; do not include passwords, session tokens, + private messages, or other sensitive account information.


Go Back -- 2.51.2 From c871c082a54fd2016a8b78c54e38f35f2e67656b Mon Sep 17 00:00:00 2001 From: Grace Kind Date: Fri, 11 Sep 2026 21:50:37 -0500 Subject: [PATCH 2/2] Update date --- src/privacy.html | 65 ++++++++++++++++++++++++------------------------ 1 file changed, 32 insertions(+), 33 deletions(-) diff --git a/src/privacy.html b/src/privacy.html index c7beeddb..c3dc254c 100644 --- a/src/privacy.html +++ b/src/privacy.html @@ -7,7 +7,7 @@

Privacy Policy

-

Last updated: January 3, 2026

+

Last updated: September 12, 2026

Impro is a third-party web client for Bluesky. It is not affiliated with Bluesky PBC. This policy describes the web client. The services you @@ -32,18 +32,18 @@

Authentication and account access

Impro uses Atproto OAuth to authorize access to your account. Session - credentials are stored in your browser's local storage and used to - make authenticated requests to your account's services. Impro requests + credentials are stored in your browser's local storage and used to make + authenticated requests to your account's services. Impro requests permissions for a full social client, including reading and publishing - posts, managing follows and blocks, accessing preferences and - bookmarks, and reading and sending chat messages. Review the - permissions shown when authorizing Impro. + posts, managing follows and blocks, accessing preferences and bookmarks, + and reading and sending chat messages. Review the permissions shown when + authorizing Impro.

Where server-signed OAuth client assertions are enabled, your browser also sends the authorization server's address to Impro's signing - endpoint. That request is used to obtain a client assertion; it does - not contain your account's access or refresh tokens. + endpoint. That request is used to obtain a client assertion; it does not + contain your account's access or refresh tokens.

Browser storage and account services

@@ -55,10 +55,10 @@

Account actions and data requests are sent to the relevant services, - including your account host, the selected feed and profile service, - and the chat service. Bluesky-operated services are governed by - Bluesky's Privacy Policy. If you use another account host or select an - alternative service, that provider's practices also apply. + including your account host, the selected feed and profile service, and + the chat service. Bluesky-operated services are governed by Bluesky's + Privacy Policy. If you use another account host or select an alternative + service, that provider's practices also apply.

Additional lookups and embedded content

@@ -77,9 +77,9 @@

Loading media and other external resources involves requests to their - providers. For example, playing an embedded YouTube video loads a - player from YouTube's privacy-enhanced domain. The provider's own - privacy practices apply when its content is loaded. + providers. For example, playing an embedded YouTube video loads a player + from YouTube's privacy-enhanced domain. The provider's own privacy + practices apply when its content is loaded.

Community plugins

@@ -91,38 +91,37 @@

Plugins run in a sandbox, with network requests mediated by Impro's permission system. Access to private account data, such as mutes, - bookmarks, notifications, and preferences, requires permission. - Plugins can also store data locally or in account preferences. + bookmarks, notifications, and preferences, requires permission. Plugins + can also store data locally or in account preferences.

A plugin with permission to access data and contact an external - destination may send that data to the destination. The sandbox does - not guarantee how a plugin uses permissions you grant. Review each - plugin's permissions and its developer's data practices before - enabling it. + destination may send that data to the destination. The sandbox does not + guarantee how a plugin uses permissions you grant. Review each plugin's + permissions and its developer's data practices before enabling it.

Optional push notifications

- Push notifications require selecting a notification service and - enabling notifications. Setup registers your browser's push - subscription with the selected service. If the service requires a - separate authorization step, Impro sends it your account identifier, - a return address, and whether you requested chat previews. + Push notifications require selecting a notification service and enabling + notifications. Setup registers your browser's push subscription with the + selected service. If the service requires a separate authorization step, + Impro sends it your account identifier, a return address, and whether + you requested chat previews.

- The notification service and your browser's push provider are - additional parties involved in delivery. Review the selected service's - permissions and privacy practices, particularly before enabling chat - previews. You can disable push notifications in Impro's settings. + The notification service and your browser's push provider are additional + parties involved in delivery. Review the selected service's permissions + and privacy practices, particularly before enabling chat previews. You + can disable push notifications in Impro's settings.

Contact

For questions about this policy, contact the project through - GitHub. - GitHub issues are public; do not include passwords, session tokens, - private messages, or other sensitive account information. + GitHub. GitHub + issues are public; do not include passwords, session tokens, private + messages, or other sensitive account information.


Go Back