Federated infrastructure for direct P2P cooperation, trade and communications

Your data & the right to be forgotten

A plain-language summary of what we process, why we are allowed to, how long we keep it, and how you erase yourself — including the honest answer to what happens to your signatures and vouches when you leave.

This page is a summary. For the formal instrument, read the full Privacy Policy.

What data we process

We keep the data below only for as long as a purpose and a legal basis apply to it.

  • Identity & account — Your login handle (stored as a hashed network address), your username, and a one-way hash of your password. We never store the password itself.
  • Profile — Display name, optional bio, avatar, and the territory you associate with. Pseudonymous profiles carry no legal-name requirement.
  • PGP public key — Your public key is published to a transparency keyring so anyone can verify your signatures. Your private key is generated on your device and never reaches our servers.
  • Content you create — Listings, posts, comments, photos and other content you choose to publish.
  • Web of Trust — Who has verified you, and whom you have verified — the edges of the trust graph.
  • Signed agreements — Contracts and debt records you enter into, together with their PGP signatures and timestamps.
  • Technical logs — Server access logs (including IP address) kept briefly for security and abuse prevention, plus a session cookie so you stay signed in.
  • Chat identifier — If you use chat, a Matrix account identifier tied to your username.

What we deliberately do not collect

  • Special-category data (health, beliefs, biometrics) is not collected by default; where a feature needs it — such as a civic ballot — it is opt-in, on explicit consent, and pseudonymous by construction.
  • No background location tracking — your map position lives in your browser, not our database.
  • No private cryptographic keys, ever.
  • We never sell your data.

On what legal basis

Under the GDPR we process personal data only where one of these applies:

  • Consent — Art. 6(1)(a) — For anything optional: chat, civic ballots, communications you opt into. Withdrawable at any time.
  • Contract — Art. 6(1)(b) — To run the account and the features you asked for — signing contracts, keeping your listings live.
  • Legitimate interest — Art. 6(1)(f) — Security, abuse prevention, and keeping the trust graph honest against Sybil attacks.
  • Legal obligation — Art. 6(1)(c) — Where Portuguese or EU law requires us to retain or disclose specific records.

How long we keep it

Nothing is kept longer than its purpose needs.

  • Account, profile & content — Kept until you delete them or close your account. There is no silent expiry.
  • Technical logs — Access logs that carry your IP address are rotated within about 14 days.
  • Signed contracts & debts — These outlive your account. When you leave, your identity is detached from them, but the record itself stays with the other party — because it is their evidence of a deal you actually made (see below).
  • Cryptographic audit anchors — The transparency keyring and the Bitcoin-anchored proof hashes are append-only by design and cannot be rewritten. After you leave they remain — but as pseudonymous fingerprints and hashes, no longer linked to your identity.

How to delete your account

Erasure (GDPR Art. 17) is self-service — you do not have to ask us:

  1. 1Open Profile → Data & Privacy.
  2. 2Recommended first: Export your data — one archive with your contracts, signatures, proofs and PGP key (GDPR Art. 20).
  3. 3Under Danger Zone, choose Delete account and type DELETE to confirm.

No access to your account? Email info@parahub.io and we will action your request.

The right to be forgotten, meet the web of trust

A network built on signed records and mutual vouching raises an honest question: if trust and signatures are the whole point, what happens to them when someone exercises the right to be forgotten? Here is exactly how we resolve the tension — and where we draw the line.

What is truly erased

You. Your identity, your content, your contactability, and every live trust edge you hold. Afterwards, no one can look you up on Parahub.

The vouches you gave to others

A verification is a present-tense statement — “I, now, vouch for this person.” It is not a possession that outlives you. When you leave, the verifications you granted go with you. Someone you had vouched for may fall below the verification threshold and need a fresh vouch from an active member. Trust is not inherited from people who are no longer here — which is exactly what keeps the Sybil defence meaningful.

The agreements you signed

This is the boundary. A contract or debt you signed is not only your data — it is also the counterparty's evidence of a deal you genuinely made, and one party cannot rewrite the other's records. So when you leave, your name is detached from the agreement (it shows as a removed party), while the signed record itself stays with the counterparty, along with your signature and its timestamp. The GDPR anticipates this: the right to erasure yields to the establishment or defence of legal claims (Art. 17(3)(e)).

The cryptographic trail

Signatures are checked against a public transparency keyring, and proof hashes are anchored to the Bitcoin timeline — both append-only by nature. A hash committed to a public chain cannot be un-committed. On deletion your public key is marked revoked rather than physically scrubbed, precisely so every counterparty can still verify contracts they legitimately hold. What remains is pseudonymous: a fingerprint and a set of hashes, no longer tied to a living identity in our systems.

The principle

Erasure removes you from the living network — completely. It does not, and cannot, rewrite what other people truthfully recorded about agreements you chose to make. Your right to disappear stops exactly where it would overwrite someone else's memory of a promise you made to them.