Privacy Policy

Effective August 2, 2026 · Blossom Interactive LLC (the "Data Controller")

This Privacy Policy explains how Blossom Interactive LLC ("YourSpace", "we") collects, uses, discloses, and protects information when you use joinyourspace.org and the YourSpace applications (the "Service"). It is designed to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), Canada's PIPEDA, Brazil's LGPD, Japan's APPI, South Korea's PIPA, Singapore's PDPA, South Africa's POPIA, Australia's Privacy Act and APPs, India's DPDPA 2023, Virginia's VCDPA, Colorado's CPA, Connecticut's CTDPA, Utah's UCPA, Texas's TDPSA, and similar laws worldwide.

1. Information we collect

Information you provide: account email, handle, display name, password hash, optional avatar/banner/bio, content you post, messages you send, reactions, polls, reports you file, interests you select, and payment information you submit to our payment processors (we never see your full card number).

Information collected automatically: device type, operating system, browser, IP address, approximate location derived from IP (country/region only), session timestamps, language, crash logs, minimal analytics required to operate the Service, and — only if you enable push notifications — a device push token (see Section 4).

Information from third parties: if you sign in with Google, we receive the basic profile fields (name, email, avatar) you authorize. If you embed third-party content (YouTube, Vimeo, Twitch, Spotify, GIPHY/Klipy), those providers may set their own cookies inside their embed frames.

We do not knowingly collect precise GPS location, biometric data, government IDs, contacts, calendar, microphone, or camera input. Camera and photo permission are only requested when you choose to upload media, and only the file you select is sent.

2. How we use information & legal bases (GDPR / UK GDPR)

  • To provide, maintain, and secure the Service, performance of a contract.
  • To detect, prevent, and respond to fraud, abuse, harassment, CSAM, and security incidents, legitimate interests and legal obligation.
  • To send transactional emails (password resets, security alerts, billing receipts), performance of a contract.
  • To comply with court orders, subpoenas, and law-enforcement requests, legal obligation.
  • To process payments, subscriptions, and Sparks transactions through our payment processors, performance of a contract.
  • To personalize your feeds, recommendations, notifications, and the News tab using your interests and on-platform behavior, legitimate interests; you can modify or reset these signals at any time from Settings → Interests.
  • To send optional product updates, consent, which you can withdraw at any time.

We do not use your personal information to train third-party AI models. We do not sell your personal information (as that term is defined under CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, and TDPSA).

3. Automated decision-making & ranking

We use automated systems to rank threads, surface recommendations, and personalize the News tab based on the interests you select and your on-platform engagement (upvotes, follows, saves, dwell time). These systems do not produce legal or similarly significant effects on you within the meaning of GDPR Article 22. You can adjust your interests, reset your personalization vector, or opt out of personalization entirely from Settings. Per EU DSA Article 27, we publish the main parameters used to rank content in our Transparency Center.

To improve relevance, the public text of posts (title and body, never direct messages, drafts, or private content) is sent to Google's Gemini embedding model via our hosting provider's AI gateway to compute a numeric content-similarity vector. Your personal interest vector is derived on our servers from posts you have engaged with and is never sent to third parties. We do not use your content to train third-party AI models.

3a. YourSpace AI assistant

YourSpace AI is an optional in-app assistant available from the search bar and the dedicated /ask page. When you submit a prompt, the text of that prompt (and the prior turns of the same conversation) is sent to Google's Gemini family of large language models via our hosting provider's AI gateway so a response can be generated. We do not include your account email, password, payment information, direct messages, or other YourSpace data in that request unless you paste it into the prompt yourself.

Conversation history is stored only in your browser's local storage on the device you used. We do not keep a server-side copy of your chats, and you can wipe all conversations at any time from Settings → Clear AI history. We do not use your prompts, responses, or YourSpace content to train any AI model. Google processes prompts as a data processor for the limited purpose of returning a response, subject to its Gemini API terms.

Outputs are AI-generated and may be inaccurate, incomplete, or out of date. YourSpace AI is not a doctor, lawyer, therapist, accountant, or any other licensed professional. For medical, legal, financial, or mental-health questions please consult a qualified human professional.

3b. Automated media safety

Media you upload (images, video thumbnails, and clip frames) is scanned by automated machine-vision classifiers to detect nudity, sexual content, and graphic imagery so it can be blurred, age-gated, or removed. Scanning happens through our hosting provider's AI gateway as a data processor; results are stored as a safety label on the post and are not used to build advertising profiles or to train third-party AI models. You can appeal a moderation decision from the notice shown in the app.

4. How we share information

We share personal information only with the following categories of recipients, each acting as a processor under written data-processing agreements:

  • Cloud infrastructure: our cloud application platform (Lovable), which hosts the Service, our database, authentication, file storage, and server functions.
  • AI processing: Google LLC (Gemini large language and vision models), accessed through our hosting provider's AI gateway, to generate feed-similarity embeddings, power the optional YourSpace AI assistant, and scan uploaded media for safety labels. We do not use your data to train any AI model.
  • Payments & subscriptions: Stripe (web checkout and subscription billing), RevenueCat (native in-app purchase and subscription management on iOS and Android, acting as a layer over Apple App Store and Google Play Billing), and Apple/Google themselves for IAP settlement. We receive a confirmation, plan, and renewal status — never your full card number.
  • Push notifications: OneSignal (our notification delivery provider), which delivers alerts through Apple Push Notification service (APNs) on iOS and Firebase Cloud Messaging (FCM) on Android. A device push token and, if you enable previews, the sender's name and a short preview are shared for delivery. You can disable previews or notifications entirely in Settings or in your device settings.
  • Embedded content providers: YouTube, Vimeo, Twitch, Spotify, and Klipy/GIPHY for link previews and embeds you choose to include in a post. These providers may set their own cookies within their embed frames; see Section 5.
  • Anti-abuse, transactional email, and error reporting providers engaged to operate and secure the Service.
  • Law enforcement and government authorities when required by a valid legal request and after careful review; we publish a yearly transparency report.
  • NCMEC and equivalent child-protection authorities for suspected child sexual exploitation material, as required by 18 U.S.C. § 2258A.
  • A successor entity in connection with a merger, acquisition, or sale of assets, subject to this Policy.

The current list of named subprocessors is maintained in our Transparency Center. We never sell, rent, or trade your personal information to data brokers or advertisers.

5. Cookies & similar technologies

We use only essential cookies and local storage required for authentication, session persistence, your sign-in "remember me" preference, and security (CSRF protection). We do not use third-party advertising or analytics trackers. EU/UK/Brazil/California users will see a consent banner before any non-essential cookie is set. See our full Cookie Policy.

6. Security

We protect data with TLS 1.2+ in transit, AES-256 at rest, hashed passwords with per-user salt, row-level access control on our database, role-segregated service accounts, hardware-backed key storage for production secrets, mandatory two-factor authentication (TOTP via Google Authenticator, Authy, 1Password, or Microsoft Authenticator) available to all users from Settings → Privacy, and routine third-party penetration testing.

Direct messages (one-to-one and group): end-to-end encrypted with ECDH P-256 + AES-GCM 256. For one-to-one chats, you and the other person exchange keys directly. For group chats, every member holds the current group key, and the group rotates to a new epoch whenever someone joins or leaves so past messages stay readable only to members who were present at the time. Encryption and decryption happen only on your devices, and we cannot read the contents of E2EE messages. To bring your encrypted chats to a new device, you can either (a) enter a one-time 6-digit pairing code generated on a device that is already set up, the keys are transferred over an end-to-end encrypted ECDH handshake using ephemeral keys and AES-GCM 256, never seen by our servers, or (b) set an optional backup passcode that wraps your private key with AES-GCM 256 using a PBKDF2-SHA256 key (310,000 iterations) derived on your device. The passcode itself never touches our servers and we cannot recover it for you.

Space chats: Spaces are public rooms designed to be discoverable, so Space chats are encrypted in transit with TLS 1.2+ and at rest with AES-256, but are not end-to-end encrypted. The server can technically access message content for moderation, abuse detection, and legal compliance. We apply the same access controls and audit logging to this data as we do to posts and other user content.

No system is perfectly secure; we will notify affected users and regulators of any qualifying personal-data breach within 72 hours as required by GDPR Article 33.

7. Data retention

We keep personal data only as long as necessary for the purposes described above. Account data is kept while your account is active. Server access logs are kept for 30 days. Moderation reports are kept for 12 months. After account deletion, residual data in encrypted backups is overwritten on the regular backup rotation (≤35 days). Data we are required by law to retain (e.g., tax records for paid transactions under IRS, HMRC, or comparable rules) is retained for the statutory period (up to 7 years).

8. Your rights

Depending on where you live, you have some or all of the following rights:

  • Access, request a copy of the personal data we hold about you.
  • Rectification, correct inaccurate or incomplete data from your profile editor.
  • Deletion / right to be forgotten, purge your account immediately from joinyourspace.org/delete-account.
  • Portability, receive your data in a structured, machine-readable JSON format on request.
  • Object or restrict processing based on legitimate interests.
  • Withdraw consent at any time where processing is based on consent.
  • Opt out of personalization for feeds, recommendations, and news.
  • Non-discrimination, we will not penalize you for exercising any privacy right.
  • Lodge a complaint with your local data-protection authority. EU users may also contact our Article 27 representative listed below.

To exercise any right, email privacy@joinyourspace.org. We respond within 30 days (extendable by 60 days for complex requests, as permitted by GDPR Article 12(3) and equivalent laws).

9. Minors

The Service is restricted to users aged 18 and older worldwide. We do not knowingly collect, use, or disclose personal information from anyone under 18. If we learn that we have collected personal information from a person under 18, we will delete the account and associated data promptly. Parents or guardians who believe a minor has provided us with personal information may contact privacy@joinyourspace.org. Because the Service is adults-only, we do not rely on parental-consent frameworks such as COPPA verified parental consent.

10. International transfers

YourSpace is operated from the United States. When personal data is transferred from the EEA, the UK, Switzerland, or other jurisdictions with cross-border data-transfer rules to the U.S., we rely on the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, the Brazilian ANPD International Transfer SCCs, and equivalent mechanisms, and we apply supplementary technical and organizational safeguards as described in our Transfer Impact Assessment, available on request.

11. California (CCPA/CPRA) notice

In the preceding 12 months we have collected the categories of personal information listed in Section 1 for the business purposes in Section 2 and disclosed them only to the service providers in Section 4. We have not sold or shared personal information for cross-context behavioral advertising, and we do not have actual knowledge of selling or sharing the personal information of consumers under 16. California residents may exercise the rights in Section 8 by emailing privacy@joinyourspace.org. California residents may also designate an authorized agent and may appeal a denial under Cal. Civ. Code § 1798.130(a)(3)(B)(iii).

12. Contact, EU representative & DPO

Data Controller: Blossom Interactive LLC, USA · privacy@joinyourspace.org

EU Representative under GDPR Art. 27 and UK Representative under UK GDPR Art. 27: appointed and disclosed on request to EU regulators and the UK ICO. Brazilian ANPD point of contact: dpo-br@joinyourspace.org. India DPDPA 2023 Grievance Officer: grievance-in@joinyourspace.org. Full details on our Imprint.

13. Changes

We may update this Policy. Material changes will be announced in-app at least 14 days before they take effect, and we may also send an email notice where we consider it appropriate.