Privacy Policy
Updated:
The Pidhorodne community portal respects your privacy and collects only the minimum data needed to run your account. This page explains what we collect, why, and what rights you have.
What we collect
Email — for sign-in, account confirmation, and notifications you subscribe to.
Display name — your real name or a pseudonym; your choice.
Password — stored ONLY as a cryptographic hash (scrypt), never in plain text; we cannot see your password.
We deliberately do NOT store your IP address or browser fingerprint with sessions — data-minimization by design.
Why we use it
Authentication — to sign you in and keep your session (secure httpOnly cookies, not readable by scripts).
Notifications and subscriptions — only those you turn on yourself.
Attribution — if you submit news or a post, your display name accompanies it.
Social sign-in
If you sign in via Google or Facebook, that provider sees the fact of your login. We receive only an identifier and email to link accounts.
The veterans’ cabinet does NOT support social sign-in for safety — email, password, and an optional verification code only.
Who we share with
We do NOT sell your data or share it for advertising.
Data leaves the portal only to the email delivery provider (to send confirmation and password-reset messages) and to your chosen OAuth provider when you use social sign-in.
Your rights
You can view and correct your account data.
You can request account deletion — we anonymize data associated with you.
Pseudonyms are allowed: you are not required to provide a real name.
Retention and changes
Account data is kept while the account is active; after deletion it is anonymized.
We may update this policy; material changes are marked by the update date at the top.