SiteOfSites
  • Explore
  • How it works
  • Legal
    • Privacy Policy
    • Terms of Service
    • Community Rules
    • External Links Disclaimer
  • Log in
  • Register

Privacy Policy

Document version: 1.3

Effective date: 2026-05-19

If a translated version differs from the English version, the English version prevails.

This notice describes how the service works and how personal data is processed. For privacy requests, use the privacy contact listed below.

Data Controller

Controller: Francesco Perra

Privacy contact: postmaster@siteofsites.org

Contact details: postmaster@siteofsites.org

Data We Process

  • Account data: username, email, encrypted or hashed authentication credentials, role, account status, registration date, technical account security data needed for login, session management and account protection, accepted legal document versions and legal acceptance timestamp, which also records the age declaration.
  • User content: URLs, descriptions, categories, tags, groups, group relationships, group roles, public or private visibility and related metadata.
  • Votes and reactions: like, dislike, reject vote, vote date and association with the user and target content.
  • Reports: target, reason code, description, date, status, priority, content snapshot, anonymous reporter email when provided, reporter account when authenticated, and related source-report or notification context when a report is submitted from a moderation notification.
  • Report anti-abuse data: pseudonymized technical identifiers such as IP-related hashes, user-agent hashes, email hashes and reporter identity hashes.
  • Security and rate-limit events: IP address when needed, email, username, userId when available, request count, time window and technical details.
  • Internal notifications and moderation/audit actions.
  • Transactional email data for registration, password recovery, bug reports and service communications.
  • Bug report attachments when users choose to send them.
  • URL safety cache and safety-provider data: normalized URL, domain, provider, result, threat categories and cache expiry.
  • User report and account moderation data: reported account identifier, username, account status, role, suspension status, suspension reason, suspension duration, related report ID, admin moderation notes and moderation timestamps.
  • User suspension anti-abuse data: pseudonymized technical identifiers such as IP-related hashes, email hashes, user-agent hashes, source of the restriction, expiry date and hit count, used to prevent suspended users from immediately abusing registration or anonymous reporting flows.

Google Sign-In

If you choose to sign in with Google, we receive and process the Google account identifier required to authenticate you, your email address and whether Google reports that the email address is verified. We use this information only to create or access your SiteOfSites account. We do not store Google access tokens or refresh tokens.

Purposes and Legal Bases

PurposeLegal basis
Account creation and managementPerformance of the requested service/contract
Authentication and account securityService performance and legitimate interest in security
Publishing URLs, descriptions, tags and groupsPerformance of the requested service
Votes, reject votes, ranking and search qualityService performance and legitimate interest in quality and anti-abuse
Reports and moderationLegitimate interest and legal obligations where applicable
URL safety checks and Web RiskLegitimate interest in service and user safety
Rate limits and suspicious IP eventsLegitimate interest in security and abuse prevention
Transactional emailsPerformance of the requested service
Privacy requestsLegal obligation
Technical/session/auth/antiforgery cookiesTechnical necessity for the requested service
User reports, account moderation and account suspensionLegitimate interest in community safety, abuse prevention and enforcement of the Terms, and legal obligations where applicable

Reports and Sharing With Content Owners

Reporter identity is not shown publicly. Qualitative reports that may be forwarded to content owners are available only to authenticated users. For these reports, the report description may be forwarded to the owner of the reported content only when the reporter explicitly chooses to share that description. The reporter identity, email, username and technical anti-abuse data are not shared with the owner through this flow.

For legal, safety or abuse cases, SiteOfSites may keep logs and may avoid sharing details when disclosure would create legal, security or anti-abuse risks.

Reports against users are handled as account safety and moderation reports. The reported user may receive a general notice if an account restriction or suspension is applied, but reporter identity and technical anti-abuse data are not shared. Detailed report information may be withheld when disclosure would create privacy, safety, legal or anti-abuse risks.

Moderation, Trust and Automated Decisions

SiteOfSites may use internal anti-abuse and trust signals to help prevent false reports, spam, manipulation and other abusive behavior. These signals are not public and are used only for service safety, moderation, rate limiting and abuse prevention.

Some actions may be automatic or semi-automatic, such as temporary hiding after a confirmed Web Risk result, after multiple independent reports, or after community reject-vote thresholds are reached. These actions may limit public visibility but do not represent a legal judgment or certification about the external site.

User reports may lead to manual account moderation actions, including temporary or permanent account suspension, restoration after review, login invalidation and anti-abuse restrictions connected to suspended-account activity.

Google Web Risk and Safety Providers

For security reports, SiteOfSites may send the reported URL to external reputation or safety providers such as Google Web Risk. Reporter identity, email, username, IP hash and report description are not sent to the provider. Results may be cached to reduce calls and abuse.

Recipients and Providers

Data may be processed by hosting providers, SMTP/email providers, URL safety providers, technical logging services and competent authorities when required by law.

Retention

  • Account data: kept while the account is active.
  • Deleted accounts: disabled and anonymized according to the account deletion procedure.
  • Votes: kept while the account/content exists, unless deletion or anonymization applies.
  • Reports and moderation technical data: retained for 365 days by default, for security, disputes and moderation audit.
  • Reporter trust events: retained for 730 days by default for anti-abuse and moderation integrity.
  • Suspicious IP/security logs: direct technical data is minimized after 90 days by default.
  • Web Risk cache: expired safety checks are cleaned after 7 days by default; clean results are cached for 7 days by default, risk results for 24 hours by default, and error results for 1 hour by default.
  • Transactional email records: retained only as needed to provide the service, troubleshoot delivery, manage security and comply with applicable obligations.
  • User suspension anti-abuse restrictions: retained until the suspension or restriction expires. For permanent suspensions or serious abuse cases, related pseudonymized restriction records may be retained longer where needed for abuse prevention, disputes, legal obligations or service integrity.

Technical cleanup is handled by configurable cleanup procedures. Retention values must be set in production configuration and reviewed periodically.

User Rights

Where applicable, users may request access, rectification, deletion, restriction, objection, portability and withdrawal of consent where consent is used. Users may also lodge a complaint with a competent data protection supervisory authority. Use postmaster@siteofsites.org for privacy requests.

Account Deletion

Accounts may be disabled and anonymized. When available, users may choose whether to remove content they created or keep it in anonymized form. Some data may remain in anonymized or pseudonymized form, or in security/moderation logs, when needed for abuse prevention, legal obligations or service protection.

Cookies

SiteOfSites uses technical cookies needed for session, authentication, remember-me login and antiforgery protection. It also uses the sos_culture functionality cookie to remember the selected language for one year. These cookies are required to provide the service, preserve language preferences and protect requests. If analytics, advertising or non-technical tracking are introduced in the future, this policy will be updated and consent will be requested where required.

Minors

The service is not intended for minors under 18.

Policy Updates

This policy may change over time. Relevant changes may require users to accept the updated legal documents again.