Privacy Policy
Last updated: January 2026
1. Who We Are
People of Cornwall is a community storytelling platform operated as a not-for-profit project dedicated to preserving Cornish heritage and memories. We are the data controller responsible for your personal data.
Contact: hello@peopleofcornwall.com
2. What Data We Collect
We collect and process the following personal data:
- Account Information: Name, email address, and profile picture (provided via Google Sign-In)
- Profile Information: Display name and bio that you choose to share
- Content: Stories, comments, and images you upload
- Technical Data: Browser type, IP address, and pages visited (for site functionality and security)
3. Legal Basis for Processing (GDPR)
Under the UK GDPR, we process your data based on:
- Consent: When you create an account and submit stories, you consent to us storing and displaying your content
- Legitimate Interest: For platform security, fraud prevention, and improving our services
- Contract: To provide you with the platform services you've signed up for
4. How We Use Your Data
- To provide and maintain the People of Cornwall platform
- To display your stories and contributions publicly (as you've agreed)
- To send you notifications about your stories (approvals, comments)
- To moderate content and ensure community guidelines are followed
- To improve the platform based on usage patterns
5. Data Sharing & Third Parties
We share your data with the following third-party services that help us run the platform:
- Supabase (Database & Authentication) — stores your account and content. Data is stored in the EU. Privacy Policy
- Google (Sign-In) — we use Google OAuth for authentication. We only receive your name, email, and profile picture. Privacy Policy
- OpenAI (AI Features) — if you use AI features, your story content may be processed by OpenAI to generate summaries or images. Privacy Policy
- Vercel (Hosting) — hosts our website. Privacy Policy
- Resend (Email) — sends transactional emails about your stories. Privacy Policy
We never sell your personal data to third parties.
6. International Data Transfers
Some of our service providers (OpenAI, Vercel) may process data outside the UK/EU. Where this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the UK ICO.
7. Data Retention
- Account data: Retained while your account is active, plus 30 days after deletion request
- Published stories: Retained indefinitely as part of the community archive, unless you request deletion
- Comments: Retained while the story exists or until you delete them
- Technical logs: Automatically deleted after 90 days
8. Your Rights Under GDPR
Under the UK GDPR, you have the following rights:
- Right of Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure ("Right to be Forgotten"): Request deletion of your account and data
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Receive your data in a machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time
To exercise these rights, email us at hello@peopleofcornwall.com. We will respond within 30 days.
9. How to Delete Your Account
You can request account deletion through your Profile Settings page, or by emailing us. Upon deletion:
- Your profile will be immediately removed
- Your stories will be either deleted or anonymised (your choice)
- Your comments will be anonymised
- All data will be permanently deleted within 30 days
10. Cookies
We use only essential cookies required for the platform to function:
- Authentication cookies: To keep you logged in securely
- Theme preference: To remember your light/dark mode choice
We do not use advertising cookies, tracking cookies, or any third-party analytics that track you across websites. Because we only use essential cookies, we do not require a cookie consent banner under UK GDPR.
11. Children's Privacy
People of Cornwall is not intended for children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
12. Security
We implement appropriate technical and organisational measures to protect your data:
- All data transmitted over HTTPS encryption
- Passwords handled securely via Google OAuth (we never see your password)
- Database access restricted to authorised personnel only
- Regular security reviews of our systems
13. Complaints
If you're unhappy with how we've handled your data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
ico.org.uk/make-a-complaint
14. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of significant changes by email or by posting a notice on the platform.
15. Contact Us
For any privacy-related questions or to exercise your rights:
Email: hello@peopleofcornwall.com