Privacy
Early-stage privacy notice
This notice describes the current development site. It must be expanded before analytics, reports, production moderation verification, public submission publishing, or public collection publishing launch.
Current site
Public browsing does not require an account. Saving assets into collections requires Discord sign-in. pfseeker stores private collection names, ordered saved asset IDs, and collection timestamps in D1 for signed-in users.
The previous anonymous localStorage collection behavior has been removed from production behavior, and no anonymous collection import path is retained.
If you sign in with Discord, pfseeker stores your Discord user ID, username, global display name when available, avatar hash when available, account timestamps, and a hashed local session record. The raw session token is kept only in an HTTP-only cookie. pfseeker does not store Discord email, guild membership, roles, access tokens, refresh tokens, passwords, or bot-derived data in this phase.
Signed-in users may submit images into a private pending state. For pending submissions, pfseeker stores the uploaded Cloudinary public ID, verified file metadata, selected asset type, optional category, optional tags, optional description, optional creator or credit name, optional source URL, optional suggested tags, timestamps, ownership, and duplicate-check metadata. Pending media is stored through Cloudinary and is not linked from public pages.
Cancelling a pending submission deletes the pending Cloudinary file and D1 submission record. On the Phase 13 feature branch, moderation can retain reviewed submission records, public rejection reasons, internal rejection notes, cleanup status, and append-only moderation events.
Future functionality
Public collection publishing, reports, production analytics, advertising, and public media publication will require a fuller privacy policy before they are enabled.