Privacy policy
Last updated September 29, 2026. This policy explains what personal data Inspire Me collects, why, and the rights you have under the EU General Data Protection Regulation (GDPR).
Who is responsible
The data controller is [Site owner name — set this in Moderation → Settings].
What we collect
- Account data — username, email address, display name, bio, optional profile photo and a securely hashed password. Needed to run your account (Art. 6(1)(b) GDPR).
- Content you share — quotes, reflections, comments, uploaded photos, hearts, saves and follows. Needed to provide the service (Art. 6(1)(b)).
- Moderation records — reports you make or receive and moderator decisions, kept to keep the community safe (legitimate interest, Art. 6(1)(f)).
- Progress data — XP, streaks and badges earned from your activity (Art. 6(1)(b)).
- Visit count & subscription — how many visits you’ve made (to apply the free-visit allowance) and, if you subscribe, your subscription status, purchase email and Gumroad license key (Art. 6(1)(b)).
- Bot protection — sign-up uses a private proof-of-work check that runs in your browser. It sends nothing to third parties and stores nothing about you.
- Security data — to stop password-guessing we store a salted, one-way hash of your IP address for 15 minutes after a failed login. We never store raw IP addresses.
We don’t use analytics, advertising, tracking pixels or social-media plugins, and we never sell your data.
Cookies and local storage
We use only strictly necessary cookies, so no consent banner is required (ePrivacy Directive Art. 5(3)):
air_sess— keeps you signed in during a visit and protects forms from forgery. Deleted when you close your browser.air_rem— only if you tick “Keep me signed in”; lasts 30 days.
Your browser’s local storage remembers display preferences (dark mode, sounds, recent searches, drafts). It never leaves your device.
Services we use
- Web hosting — our hosting provider stores the site and its database on our behalf under a data processing agreement.
- AI features (Groq, Inc., USA) — when you use an AI feature (explain a quote, check an attribution, match your mood), when you post a comment (an AI moderator checks it against the guidelines), or when new content is screened for moderators, the relevant text is sent to Groq to generate an answer. We send only the text needed — never your email or account details. Transfers to the USA rely on the EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework.
- Payments (Gumroad, Inc., USA) — members get 69 free visits; after that a subscription is sold and billed by Gumroad. We never see your card. Gumroad tells us your purchase email, subscription ID and license key so we can unlock your account, and we check once a day that the subscription is still active. Transfers rely on the EU Standard Contractual Clauses.
- Fonts — fonts are stored on and served from our own server, so your browser doesn’t contact Google.
How long we keep data
- Account data and your content — until you delete them or your account.
- Read notifications — 90 days. Moderation logs and resolved reports — 1 year. Detailed activity history — 180 days (your XP total stays).
- Login-throttle hashes — 15 minutes. Session files — 7 days.
Your rights
You can access, correct, export, restrict or delete your data, object to processing based on legitimate interest, and complain to your local data protection authority. Most of this is self-service:
- Access & portability — “Download my data” in Settings gives you everything as a JSON file.
- Correction — edit your profile, quotes and comments at any time.
- Erasure — “Delete my account” removes your account and everything you shared, immediately and permanently.
Age
You must be at least 16 to create an account.
Security
Passwords are hashed with bcrypt/Argon2, forms are protected against forgery, sessions use HttpOnly cookies, and the database isn’t reachable from the web.