Skip to content

Privacy Policy

Last updated: 10 September 2026

Common Strangers is a community platform for publishing and sharing creative work. This page explains what personal data we collect, why, and what you can do about it. We have tried to write it in plain language rather than legal boilerplate.

Who is responsible

The controller of your personal data is [CONTROLLER — legal name and address], Greece.

For anything on this page — questions, requests, complaints — write to [CONTACT EMAIL].

What we collect

When you create an account

  • Username — required. It is public: it appears on everything you publish and on your profile.
  • Email address — optional. If you give one, it is used only to send you account emails, such as a password reset link. It is never shown publicly.
  • Password — stored only as a cryptographic hash. Nobody, including us, can read it.

If you register without an email address, we have no way to reach you and no way to reset your password if you lose it.

When you use the site

  • What you publish — text, images, audio, video links, and the theme and title you file them under.
  • Your profile — photo, biography, links and favourites, if you choose to fill them in. All of it is public.
  • Comments — the text, and the IP address and browser identifier recorded with them. This is standard for the software the site runs on and is used to deal with abuse.
  • Server logs — our hosting provider records IP addresses and requests for security and troubleshooting.

What we do not do

There is no analytics, no advertising, no tracking pixels, no profiling and no automated decision-making. We do not sell or rent personal data to anyone, and we never will.

Why we are allowed to hold it

  • To provide your account and publish your work — this is our contract with you (GDPR Article 6(1)(b)).
  • To moderate content, prevent abuse and keep the site secure — our legitimate interest in running a usable community (Article 6(1)(f)).
  • To meet legal obligations where one applies (Article 6(1)(c)).

Cookies and local storage

This site sets only what it needs to work. There are no advertising or analytics cookies.

  • Session cookies — set when you sign in, so the site remembers you between pages. They are removed when you log out.
  • Consent notice — a single value stored in your browser so the cookie notice does not reappear on every page.
  • Open windows — on the desktop version, which windows you have open and where you dragged them is kept in your browser for the length of the visit, so the page survives a reload. It never leaves your device.

Because these are strictly necessary for the site to function, they do not require your consent — the notice you saw is there to inform you, not to ask permission.

Embedded video

Some publications embed video from YouTube or Vimeo. When you open a page containing one, your browser contacts those services directly, and they receive your IP address and may set their own cookies. We use YouTube’s no-cookie player, which reduces but does not eliminate this. Their handling of your data is governed by their own privacy policies, not this one.

Who else sees your data

We do not share personal data except with the providers we need to run the site, who process it on our instructions:

  • Hosting — Hostinger International Ltd (Lithuania, EU).
  • Email delivery — a transactional email provider, used only to send account emails.

We may also disclose data if a court or competent authority requires it by law.

How long we keep it

  • Account data — until you ask us to delete it.
  • Published work and comments — for as long as they are on the site. Deleting your account does not automatically delete work already published; tell us if you want it removed too, and we will.
  • Server logs — a short period set by our hosting provider, typically a few weeks.

Your rights

Under the GDPR you can ask us to:

  • give you a copy of the data we hold about you;
  • correct anything inaccurate;
  • delete your data;
  • restrict or object to how we use it;
  • hand it over in a portable format.

Write to [CONTACT EMAIL] and we will answer within one month. You will not be charged, and asking costs you nothing.

If you think we have handled your data badly, you can complain to the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα) at www.dpa.gr.

Children

This site is not intended for children under 15. If you believe a child under 15 has created an account, tell us and we will remove it.

Security

The site is served over HTTPS, passwords are hashed, and submissions are reviewed before they appear. No system is perfectly secure, but if a breach ever affects your rights we will tell you and the authority, as the law requires.

Changes

If we change this policy we will update the date at the top. Significant changes will be announced on the site.