Privacy Policy
Last updated
This policy explains what Kommet collects when you sign in, why we collect it, where it is stored, and how to have it deleted. Kommet is a platform for commissioning artwork from independent artists.
Before publishing: replace this note with your legal entity name, registered address, the contact address for privacy requests, and the governing jurisdiction. Have the finished policy reviewed by a lawyer — the sections below describe the software accurately but are not legal advice.What we collect
Kommet has no password of its own. You sign in through an identity provider — Google, and, where offered, Microsoft, Apple, or Discord. When you do, we receive and store:
- Your name, email address, and profile picture URL, as supplied by that provider.
- A provider account identifier — the stable ID your provider uses for you. This, not your email, is what links your account across sign-ins.
- OAuth tokens issued by the provider, used to complete sign-in and to confirm the account still exists.
We request only the openid, profile, and email scopes. We cannot read your mail, files, contacts, or calendar, and we never receive your password.
If you sign in with Apple using Hide My Email, we receive only the relay address Apple generates, and that is all we store.
How we use it
To identify you across visits, to display your name and picture on your account, and to contact you about your commissions. We do not sell personal data, and we do not use it for advertising or profiling.
Sessions and cookies
Signing in sets a small number of strictly necessary cookies. They are HttpOnly and Secure, so they cannot be read by scripts in your browser or sent over an unencrypted connection.
- A session cookie holding an opaque identifier. It contains none of your personal data — it points to a session record on our server.
- A CSRF token and a short-lived callback URL, used to protect the sign-in exchange and return you to the right page.
We set no advertising or analytics cookies. Signing out deletes the server-side session record immediately.
Where it is stored, and who else sees it
Account data is stored in a PostgreSQL database hosted by Neon in the European Union (AWS, Frankfurt). The application runs on Cloudflare Workers, which serves requests from the location nearest you and processes them in transit.
These providers process data on our behalf as service providers. Your identity provider necessarily learns that you signed in to Kommet. Beyond that, we share personal data only where the law requires it.
Retention and deletion
We keep your account record until you ask us to delete it. Expired sessions are removed automatically. On deletion, your user record and every linked provider account and session are permanently removed.
Your rights
You may request a copy of your data, ask us to correct it, or ask us to delete it. If you are in the EU, EEA, or UK, you also have the right to object to processing, to request restriction, and to lodge a complaint with your data protection authority. Contact us using the address above and we will respond within the period the law requires.
You can revoke Kommet's access at any time from your provider's own settings — for Google, at Third-party apps with account access. Revoking access stops future sign-ins but does not by itself delete data we already hold; ask us for deletion as well.
Children
Kommet is not directed at children, and we do not knowingly collect data from anyone under the age required to consent in their country. If you believe a child has given us data, tell us and we will delete it.
Changes
If we change this policy we will update the date at the top of this page, and tell you directly if the change materially affects how we handle your data.