Privacy Policy
The short version
We do not sell your personal information, run advertising trackers, or load third-party analytics. We collect what we need to run MyProtocol and keep it safe, and you can ask us to access, correct, export, or delete your data at any time.
1. Information we collect
MyProtocol LLC, a Connecticut limited liability company, operates MyProtocol and is the controller for the personal information described in this Privacy Policy.
We collect the following categories of information:
- Account information. Your name, email address, and any optional profile details you choose to add, such as a bio, links, avatar, or stated credentials.
- Content you create. The protocols, community notes, comments, discussions, and replies you publish. This content is public by design and is visible to others.
- Activity on the platform. The protocols you save, the creators you follow, and the collections you build.
- Device and technical data. Your IP address, browser and device information, and a device fingerprint (a hashed identifier). When you request a page, our hosting provider processes the requested URL with this technical data to deliver and secure the site. We do not maintain an account-linked history of the protocol pages you view. When you submit content, we also record basic interaction signals from the form, such as time on the page and counts of typing, pasting, and mouse activity. We collect these for security and abuse-prevention, not for advertising.
- Verification data. If you verify a phone number, we store a hashed version of it for abuse-prevention and treat that value as personal information. We do not store the number itself.
2. How we use your information
We use the information we collect to:
- Provide, maintain, and operate the Platform.
- Keep the Platform safe by detecting spam, fraud, ban evasion, and other abuse.
- Screen submitted content for safety and detect duplicate submissions.
- Send account and activity notifications.
- Monitor and enforce our Terms & Conditions and Community Guidelines.
- Comply with legal obligations.
We do not use your saves, creator follows, collections, or technical request logs to build advertising or behavioral profiles.
3. How your information is shared
We do not sell your personal information, and we do not share it for advertising, cross-context behavioral targeting, or profiling.
We share information with the service providers that help us operate the Platform (listed in the next section), under contracts that limit them to providing their service to us.
Your public profile, published protocols, community notes, and any public collections are visible to other users and may be indexed by search engines.
We may also disclose information where required by law, to protect rights and safety, or in connection with a merger, acquisition, financing, or asset sale.
4. Service providers we work with
We rely on the following providers to run the Platform. Each receives only the data it needs for its function:
- Vercel for application hosting and delivery. It processes your IP address, browser information, and requested URL in technical request logs used to deliver and secure the site.
- Supabase for authentication, database, and file storage.
- Google and Meta (Facebook) for optional social sign-in. If you choose one of these options, that provider processes the sign-in and provides your email address and basic profile information to Supabase.
- Resend to deliver account and notification emails to your address.
- Cloudflare Turnstile for bot and spam protection on forms. Its widget and verification service process a verification token, your IP address, and technical browser and device signals used to assess whether a request is automated.
- OpenAI to screen submitted text for safety and to detect duplicate content. See the next section.
- Google Safe Browsing, when enabled, receives links you submit and checks them against known malware and phishing. If the service is not configured or is unavailable, this check is skipped.
- Twilio only if phone verification is offered and you choose to use it, in which case it receives your number to deliver the verification code.
5. Content processed by AI
When you submit text for publication, including a protocol, community note, comment, discussion, or reply, we send the text to OpenAI to screen it for safety and to check it against existing content for duplicates. OpenAI processes this text as our service provider under a data processing agreement and does not use it to train its models. We do not send your saves, creator follows, or collections to OpenAI or any other AI provider.
6. Cookies and tracking
We use essential cookies to maintain your session and authentication state, and functional storage to remember preferences such as your display settings.
We do not use third-party analytics, advertising cookies, ad pixels, or cross-site tracking. The only device-level identifier we collect is the abuse-prevention fingerprint described in Section 1. You can manage cookies through your browser settings, though disabling essential cookies may prevent you from signing in.
7. Data security
We use encrypted HTTPS connections, password hashing through Supabase Auth, database row-level security that blocks direct public table access, and access controls for administrative systems. No method of transmission or storage is fully secure.
8. Data retention
We keep your account information for as long as your account is active. We retain each other category of data only as long as we need it for the purpose it was collected, plus any period required by law. For security and audit records we use the fixed windows below, enforced by automated cleanup jobs.
Anti-abuse telemetry, such as the hashed IP addresses in our rate-limiting and submission logs, is kept for up to 90 days. Registration-abuse logs, the device fingerprint stamped on votes, and our automated content-scan results are kept for up to 12 months. Internal records of content deletion (for example, when a creator deletes a protocol) are kept for up to 2 years.
When you ask us to delete your account, it is deactivated immediately, you can restore it for 30 days, and we complete the permanent deletion within 45 days of your request. A small set of records survives that deletion, each on its own clock. If your account was banned or restricted for abuse when it was deleted, we keep its abuse-prevention fingerprint and hashed phone number for up to 2 years so that a banned account cannot simply be recreated. We keep the record of your acceptance of our Terms and Conditions (the version and date, and the email and username on the account at the time) for 6 years after deletion, the period during which a contract dispute could still arise. If you accepted our creator terms, we keep that acceptance record (the version, date, IP address, browser details, and the email and username on the account at the time) for the same 6-year period. We keep content-moderation records, including copyright notices, for as long as your account exists and for 5 years after it is deleted. After these periods the records are deleted.
After we remove your information from our active systems, residual copies may remain in routine backups for a limited period, currently about one week, before they are overwritten in the normal course. We cannot recall copies that other people have saved or shared, and search engines may show cached pages until they refresh.
9. Your rights and choices
Depending on where you live, you may have some or all of the following rights. We honor these requests regardless of where you live, to the extent we reasonably can:
- Know and access. Learn what categories of personal information we hold about you and request a copy.
- Delete. Request deletion of your account and personal data. You can also delete your account yourself at any time from your account page; it is deactivated immediately, you can restore it for 30 days, and we complete the permanent deletion within 45 days of your request.
- Correct. Ask us to fix inaccurate information.
- Export. Receive your data in a portable format.
- Opt out of sale or sharing. We do not sell your personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of. If that ever changes, we will update this policy and provide a clear opt-out first.
- Limit the use of sensitive information. We do not use sensitive personal information, including health-interest data, for any purpose that would require us to offer this choice.
- Non-discrimination. We will not deny you service, charge you a different price, or give you a lesser experience for exercising any of these rights.
To make a request, email privacy@myprotocol.com. We may need to verify your identity first, and we will respond within the timeframe required by applicable law.
10. Consumer health data
Because the protocols you save, the creators you follow, and the collections you build can reveal an interest in a health or wellness topic, some of this activity may count as consumer health data under laws such as Washington’s My Health My Data Act. We use this data to provide and secure the Platform. We do not sell it or share it for advertising or profiling. For the full details, including rights specific to consumer health data, see our Consumer Health Data Privacy Notice.
11. Children's privacy
MyProtocol is for adults. You must be 18 or older to use it, and it is not directed to children. We do not knowingly collect personal information from anyone under 18, and, consistent with the Children’s Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from children under 13. If we learn that we have, we will delete it promptly.
12. Changes to this policy
We may update this Privacy Policy from time to time and will update the “Last updated” date when changes are posted. For material changes, we may provide additional notice (for example, in-product notices or email where available). Continued use of MyProtocol after the effective date of changes is subject to the updated policy.
13. Contact
MyProtocol LLC is the controller responsible for this Privacy Policy. If you have questions or wish to exercise your data rights, please email privacy@myprotocol.com.
