Privacy Policy
What we collect, why we collect it, and what control you have over it.
Last updated
1. Who we are
TedIS (“we”, “us”) is operated by Vedansh, based in Himachal Pradesh, India. For data-protection purposes we are the data controller for the information described here.
Postal address: NIT Hamirpur, Hamirpur, Himachal Pradesh, India. Privacy enquiries: [email protected].
2. What we collect
We collect only what the service needs to function. Specifically:
| Category | Examples | Why |
|---|---|---|
| Account | Email address, username, display name, password (hashed) | To create and secure your account |
| Profile | Headline, bio, location, website, pronouns, avatar and banner images | Shown on your public profile — you choose what to add |
| Content | Posts, comments, projects, reactions, bookmarks, interests you follow | The core of the service; most of this is public |
| Messages | Direct message contents and attachments | To deliver your conversations |
| Technical | IP address, browser user-agent, device fingerprint, approximate location (country/city) | Security: detecting suspicious logins and abuse |
| Usage | Login events, session activity timestamps | To let you review and revoke active sessions |
3. What is public
TedIS is a platform for building in the open, so a lot of what you create is public by design. Your username, display name, profile details, posts, comments, and projects are visible to anyone — including people who are not signed in, and search engines.
Direct messages are not public. They are visible to the participants in the conversation and, where necessary, to our staff investigating a report or abuse (see §6).
4. Why we are allowed to use it
Where the UK/EU GDPR applies, our lawful bases are:
- Contract — to provide the account and features you signed up for.
- Legitimate interests — to keep the platform secure, prevent abuse, and fix errors.
- Legal obligation — where we must retain or disclose data by law.
We do not sell your personal data, and we do not use it for behavioural advertising or profiling.
5. Who else processes your data
We use a small number of infrastructure providers (“sub-processors”). They act on our instructions and are not permitted to use your data for their own purposes.
| Provider | Purpose | Data involved |
|---|---|---|
| Railway | Application hosting | All request data in transit |
| Neon | Managed PostgreSQL database | Account, profile, posts, messages |
| Upstash | Redis — sessions, rate limits, realtime | Session identifiers, presence |
| Cloudflare | DNS, CDN, R2 object storage | Uploaded images and video, request metadata |
| Resend | Transactional email (password reset) | Email address |
| Sentry | Error monitoring | Error traces, which may include IP address |
Some of these providers operate outside your country. Where data leaves the UK/EEA, we rely on the providers’ standard contractual clauses or equivalent safeguards.
6. How long we keep it, and what deletion actually does
You can delete your account at any time from Settings → Danger zone. We think it is important to be precise about what that does, because “delete” means different things on different platforms.
Deleting your account immediately:
- revokes every active session and signs you out everywhere;
- permanently deletes your stored password;
- erases your bio, headline, location, website, avatar and banner;
- replaces your email address, username and display name with anonymised values.
What is retained: posts, comments and messages you have already sent remain, but are attributed to “Deleted account” and are no longer linked to your identity. We keep them because removing them would break conversations other people took part in. Security logs (login events, audit records) are also retained for a limited period for fraud and abuse prevention.
If you need your remaining content removed as well, email [email protected] and we will handle it manually.
7. Your rights
Depending on where you live, you may have the right to:
- access a copy of the personal data we hold about you;
- correct inaccurate data (most of this you can edit yourself in Settings);
- delete your account and associated personal data;
- object to or restrict certain processing;
- request your data in a portable format;
- complain to your local data protection authority.
8. Security
Passwords are hashed with Argon2id and never stored in plain text. Session tokens are stored hashed, expire automatically, and can be revoked by you at any time. All traffic is encrypted in transit over HTTPS.
No service can promise perfect security. If we become aware of a breach affecting your personal data, we will notify you and the relevant authority where the law requires it.
9. Children
TedIS is not intended for anyone under 13. We do not knowingly collect data from children under that age. If you believe a child has created an account, contact [email protected] and we will remove it.
10. Cookies
We use a small number of strictly necessary cookies. See the Cookie Policy for the full list.
11. Changes to this policy
We may update this policy as the service changes. The “last updated” date at the top always reflects the current version, and we will tell you in-app about material changes.
12. Contact
Questions about this policy or your data: [email protected]. General enquiries: [email protected].
