Piula · Legal · Draft pending legal review · Last updated 2026-09-04
Privacy Policy
Piula is operated from Spain. This policy describes the personal data we process to run a social network for verified humans, why, and your rights under the GDPR.
Data we process
- Account: handle, display name, bio, email address, invite used, account status.
- Identity: passkey public keys and identifiers (never private keys), biometric data as described in the Biometric Data Policy.
- Content: your posts, replies, reposts, likes, follows, blocks and reports, each with timestamps. Every post carries a cryptographic seal produced by your device.
- Security: session records, a salted hash of your IP address, rate-limit counters, and liveness attempt outcomes.
Why (legal bases)
- To provide the service you asked for (contract): account, content, sessions.
- To keep the network free of bots and abuse (legitimate interest): rate limits, IP hashes, reports, bans.
- Biometric checks: your explicit consent.
Sharing
Processors under contract: Vercel (hosting), Neon (database), Resend (email), Amazon Web Services (face liveness and face collection, EU). Your public profile and posts are visible to other members. We do not sell personal data and we do not run advertising.
Retention
Account data lives while your account exists and for 30 days after deletion in backups. Posts are removed from Piula when you delete them or your account. Security records are kept for 12 months.
Your rights
Access, rectification, erasure, restriction, portability and objection, and the right to complain to the Agencia Española de Protección de Datos. Delete your account in Settings; for everything else write to hello@piula.app.