Privacy Policy

How we collect, process, and protect personal data: legal bases, retention, data subject rights, and cookie controls.

Last reviewed:

This Policy explains how we collect, use, and protect personal data in line with the EU General Data Protection Regulation (GDPR), ePrivacy requirements, and applicable Ukrainian personal data laws.

Related legal documents: Cookie Settings and Terms of Use.

1. Data controller and contacts

The data controller is the editorial team of Laravel. Legal details, postal address, and operational contacts are available on the contact page.

  • Email for privacy requests: [email protected]
  • Legal request channel: feedback form
  • DPO / responsible officer: published on the contact page when applicable.

2. Categories of personal data we process

2.1. Technical and log data

  • IP address, user agent, device type, operating system.
  • Visited URLs, timestamps, referrer, and technical security logs.

2.2. Account data

  • Name/nickname, email, password hash, profile preferences.
  • Reading preferences, language, and interface settings.

2.3. Service interaction data

  • Reading history, bookmarks, comments, reactions.
  • Cookie consent history for authenticated users.

3. Legal bases for processing (GDPR Art. 6)

  • Consent (Art. 6(1)(a)) — analytics/functional/marketing cookie categories, and where relevant push or newsletter subscriptions.
  • Contract performance (Art. 6(1)(b)) — account operations and profile-related functionality.
  • Legal obligation (Art. 6(1)(c)) — audit logs and subject-right request handling.
  • Legitimate interests (Art. 6(1)(f)) — abuse prevention, platform security, and aggregated analytics.

4. Purposes of processing

  • Provide core website functionality and account services.
  • Personalize content and reader settings.
  • Measure product performance and improve UX (where consent applies).
  • Moderate user content and prevent fraud/security incidents.
  • Comply with legal duties and process DSAR requests.

5. Retention periods

  • Reading history: 90 days, then automatically cleaned.
  • Consent logs: up to 2 years.
  • Data export files: 7 days.
  • Technical logs: retained per operational necessity and security policy.

After an account deletion request, a 30-day grace period applies. After that, data is deleted or anonymized according to system configuration.

6. Cookies and localStorage

We use four categories: necessary, analytics, functional, and marketing. Necessary storage is always enabled; all other categories require consent.

6.1. Necessary (always on)

  • laravel_session, XSRF-TOKEN, cookie_consent_v1, locale.

6.2. Analytics (consent-based)

  • Analytics collection and events run only after explicit consent.

6.3. Functional (consent-based)

  • Theme, reading mode, and other UX preferences in cookies/localStorage.

6.4. Marketing (consent-based)

Disabled by default. If new marketing integrations are introduced, this Policy is updated before activation.

You can revise your choice at any time via /cookie-settings.

7. Third parties and international transfers

  • Google LLC (Analytics / Tag Manager): web analytics subject to consent.
  • Mail delivery infrastructure (SMTP / SES / Postmark / Resend / Mailgun): transactional service emails.
  • Hosting and infrastructure providers: data hosting, backups, and infrastructure support.
  • Browser-vendor infrastructure for Web Push: push delivery only after explicit subscription.

Where cross-border transfers apply, we rely on GDPR transfer mechanisms (including SCCs or adequacy decisions) as appropriate.

8. Data subject rights (DSAR)

  • Right of access and export: /gdpr/export.
  • Right to rectification: via user profile settings.
  • Right to erasure/anonymization: through the request form in your profile (with grace period).
  • Right to restriction or objection: via the dedicated privacy contact channel.
  • Right to withdraw consent: at any time through cookie settings.

The standard response time for DSAR requests is up to 30 calendar days.

9. Minors

The service is not intended for users under 16. If you believe a minor has submitted personal data, please contact us and we will review and remove it where required.

10. Security measures

  • HTTPS/TLS for data in transit.
  • Modern password hashing.
  • Role-based access control and admin action audit logs.
  • Queue isolation, backups, and incident monitoring processes.

11. Policy updates

We review this Policy periodically. The latest review date is shown on the page. Material changes may trigger additional notices and renewed consent collection where required.

12. Related legal pages