Privacy Policy
Last updated 10 September 2026
src/lib/legal.ts is filled in, every field marked below is missing and this document protects nobody. Do not take real signups yet.What veyl collects, why, on what legal basis, and what you can do about it. Written specifically for this service rather than adapted from a template, because a policy that does not match the software it describes is worthless to you and a liability to us.
1.Who is responsible
The controller of your personal data, meaning the party that decides why and how it is used, is:
Operator: [NOT YET PROVIDED: registered name]
Registration: [NOT YET PROVIDED: CUI and ONRC number]
VAT number: not registered for VAT.
Registered address: [NOT YET PROVIDED: registered address], Romania
Email: [NOT YET PROVIDED: contact email]
Reports about content or accounts: [NOT YET PROVIDED: abuse email]
Data protection requests: [NOT YET PROVIDED: privacy email]
We have not appointed a Data Protection Officer. One is only required under GDPR art. 37 where an organisation is a public body, monitors people systematically on a large scale, or handles sensitive data at scale, and none of those describe this service. Requests go to the address above and are handled directly.
2.What we hold, and why
Your email address, a bcrypt hash of your password, and your chosen username. We need these to give you an account at all, so the legal basis is performing our contract with you (GDPR art. 6(1)(b)). Your password itself is never stored: bcrypt cannot be reversed, so even a complete copy of our database would not reveal it.
Whatever you choose to put on your page: display name, bio lines, links, colours, effect settings, and the files you upload. Same basis, and it is entirely up to you what goes there.
A session record when you log in, so that we know it is still you on your next page load. Same basis. It expires after 30 days.
A short-lived, single-use token when you verify your email address or reset your password. Same basis.
A counter of failed logins and other sensitive attempts, keyed to a salted one-way hash of the caller's IP address rather than the address itself. This is what stops somebody trying a million passwords against your account. The basis here is our legitimate interest in keeping the service secure (art. 6(1)(f)), which GDPR recital 49 names specifically. These counters expire within minutes.
We do not currently take payments, so we hold no purchase or billing data of any kind.
When you sign up, a bot check runs on the form. It is provided by Cloudflare Turnstile and looks at signals from your browser to decide whether you are a person. It sets no advertising cookie, does not follow you between sites, and we never see what it looked at, only whether it passed. The basis is our legitimate interest in not having the site overrun by automated signups (art. 6(1)(f)), which would take every good username before a real person could.
We do not collect anything else. There is no advertising profile, no data broker, no enrichment from other sources.
3.People who visit your page
We count views on each profile, and how many distinct people those views came from. Nobody visiting a page is identified.
To tell one visitor from another without knowing who they are, we take the visitor's IP address and browser identifier, combine them with a secret we hold and with the specific profile being viewed, and store only a one-way hash of the result. The IP address itself is never written to disk.
Salting with the profile id has a consequence worth stating plainly: the same person visiting two different profiles produces two completely unrelated hashes. This data therefore cannot be used to follow anyone around the site, and we could not reconstruct one person's browsing history from it even if we wanted to.
We record the hostname a visitor arrived from, for example 'discord.com', so you can see where your traffic comes from. Never the full address, which would leak the contents of a private server or a search query.
Visit records are deleted automatically after 90 days.
The legal basis is our legitimate interest, and yours as a page owner, in knowing whether the page is being seen (art. 6(1)(f)). We weighed that against the visitor's interests and designed the measurement so it cannot identify them, which is what makes the balance come out this way rather than requiring their consent.
We use no advertising trackers, no analytics pixels, and no third-party scripts on profile pages.
That includes Discord presence, if a page has it switched on. The status is fetched by our servers and passed on with the page, so a visitor's browser never contacts Discord or any other outside service. It costs us a little more to do it that way, and it is the difference between a promise and a nearly-true promise.
4.Cookies
We set one cookie, and only once you log in. It holds a random session identifier and nothing else. No personal data is stored inside it. It is marked HttpOnly, so scripts running in the page cannot read it, and Secure, so it is never sent unencrypted.
We set no advertising or tracking cookies, and our visit counting happens on our server without storing anything on the visitor's device.
That is why there is no cookie banner. Under Legea 506/2004, which implements the EU ePrivacy Directive in Romania, consent is needed to store or read information on someone's device unless it is strictly necessary to provide a service they asked for. A login cookie for a logged-in user is exactly that exception. Sites that show a banner do so because they are also running things that fall outside it.
5.Your page is public
This is the point of the service, but it should be said explicitly: anything you put on your profile can be seen by anyone with the address, without an account, and can be indexed by search engines.
Your email address is never shown on your page and is never given to visitors.
Uploaded avatars, backgrounds and audio are served from a public file address. Anyone who knows that address can open the file directly, whether or not they came through your page. Do not upload anything you would not want to be public.
Uploaded files are checked against their actual contents rather than their filename, and are stored under randomly generated names.
If you switch on Discord presence, your Discord user ID and your current status appear on your page for anyone to see. A Discord user ID is already public, and your status is only whatever Discord is showing about you anyway, but it is your choice: it is off unless you turn it on, and turning it off removes it immediately. We never store the status itself.
When you delete a file, or your account, the stored file is deleted too. Copies already cached by the delivery network fall out shortly afterwards.
6.Who else can see it
We use a small number of companies to run the service. They act only on our instructions, under a written data processing agreement, and may not use your data for their own purposes.
Vercel Inc.: Runs the site and serves the pages. Code runs in Frankfurt, Germany. Static files are delivered from a worldwide network of caches. Company established in the United States.
Neon Inc.: The database: accounts, profiles, links, visit counts. Servers in Frankfurt, Germany. Company established in the United States.
Cloudflare, Inc.: Stores uploaded images and audio, delivers those files, and runs the bot check on the signup form. Stored on Cloudflare's global network, which may include locations outside the European Union. Company established in the United States.
Resend (Plus Five Five, Inc.): Sends account emails: address verification and password resets. Processed in the United States. Only your email address and the contents of that email are involved.
Lanyard: Reads your Discord status, but only if you turn Discord presence on. We send your Discord user ID and nothing else, and only then. Requested by our servers, never by the browser of anyone viewing your page, so visitors are not exposed to it at all.
We may also disclose data where a court or a competent authority lawfully requires it. If that happens and we are permitted to tell you, we will.
We do not sell your data. We do not share it for advertising. We do not use it to train machine learning models, ours or anybody else's.
7.Sending data outside the EU
Your account, your page and your visit statistics live in a database in Frankfurt, Germany, and the code that serves the site runs there too.
Two things do leave the EU, and we would rather say so than round it off. Files you upload are stored on a global network and may be held outside the European Union. Account emails, meaning address verification and password resets, are sent through a provider in the United States, which sees your email address and the contents of that message.
Separately, the companies operating all of this are established in the United States, and their staff can access the systems for support and maintenance. That access is itself a transfer under Chapter V of the GDPR even where the data does not move.
Those transfers rely on the European Commission's adequacy decision for the EU to US Data Protection Framework where the provider is certified under it, and on the Commission's Standard Contractual Clauses where it is not. Copies of the clauses we rely on are available on request.
8.How long we keep things
Your account and everything on your page: until you delete it. We do not expire dormant accounts.
An account that never confirms its email address: kept for now. We may start removing these, and if we do it will be described here first.
Login sessions: 30 days, or immediately when you log out or change your password.
Email verification and password reset tokens: they expire quickly and are destroyed as soon as they are used once.
Visit records: 90 days, then deleted automatically.
Security counters: minutes.
A username you released: held for 30 days, then the record is deleted.
We hold no payment records, because we take no payments.
9.Your rights
You have the right to see a copy of the data we hold about you, to have anything wrong corrected, to have it deleted, to restrict what we do with it, to receive it in a portable machine-readable format, and to object to processing we carry out on the basis of legitimate interest.
We also record the moment you accepted the Terms and which version you accepted, because a checkbox that is not recorded proves nothing to either of us. The basis is our legitimate interest in being able to show what was agreed.
Two of these you can exercise yourself, immediately, without asking us. You can edit or remove anything on your page from the dashboard, and you can delete your account from Settings. Deletion is permanent and removes your profile, your links, your uploaded files, your sessions and your login. We keep no backup copy of a deleted account.
For a copy of your data, or for it in a portable format, write to us and we will send it. There is no self-service button for this yet, which the law permits: what matters is that you get your data within the time limit, not the mechanism you use to ask.
For anything you cannot do yourself, write to [NOT YET PROVIDED: privacy email]. We will reply within one month, and will tell you if we need longer, which the GDPR allows in complex cases by up to two further months. There is no charge.
We may need to confirm it is really you before acting on a request, which is a requirement rather than an obstacle: the alternative is handing your data to whoever asks for it.
One limit worth knowing: your username is held for 30 days after you delete your account, so that nobody can take it immediately and impersonate you. During that window we hold the name and a reference to the account that had it. Everything else is already gone.
10.Automated decisions
We do not make decisions about you by automated means that have a legal or similarly significant effect, so the rights in GDPR art. 22 do not arise.
Some things are automated but do not fall into that category: usernames are checked automatically against a list of blocked and impersonating names at signup, and uploads are checked automatically for file type. Every decision to remove content or suspend an account is made by a person, and comes with a reason and a route to appeal.
11.Children
You must be at least 16 to have an account. 16 is the age set by GDPR art. 8 for a person to act for themselves in relation to an online service in Romania.
We do not knowingly hold data about anyone younger. If you believe a child has an account here, tell us and we will remove it.
We do not ask for a date of birth, because collecting more personal data in order to verify age is its own privacy problem. We act on what is reported to us.
12.Security
Passwords are hashed with bcrypt at a deliberately slow cost setting. Login attempts and other sensitive actions are rate limited. Changing your email address or deleting your account requires your password again, even while you are already logged in. Changing your password signs out every other device.
Traffic is encrypted in transit. Session cookies cannot be read by scripts. Uploads are validated by their real contents, not their filename.
No service can promise it will never be breached, and one that does is not being honest with you.
If a breach happens and it is likely to put your rights at risk, we will tell the Romanian supervisory authority within 72 hours of becoming aware of it, as GDPR art. 33 requires. If the risk to you is high, we will tell you directly and without undue delay, by email to the address on your account, describing what happened, what data was involved, and what you should do. We will not wait until we understand everything before telling you.
13.Complaining about us
If you are unhappy with how we handle your data, please tell us first at [NOT YET PROVIDED: privacy email].
You also have the right to complain to a supervisory authority at any time, whether or not you contact us first. In Romania that is the National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul General Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, dataprotection.ro.
If you live in another EU country, you may complain to the authority there instead.
14.Changes to this policy
If we change how we use your data in a way that materially affects you, we will email you before it takes effect, not afterwards.
The date at the top of this page always shows when it last changed.