PRIVACY://

PRIVACY POLICY

This site is a directory of Fake Rare Pepe artwork. It runs no analytics, no advertising, and no tracking cookies. This page explains the little data that does move, and what rights you have over it under the GDPR.

> last_updated:// [YYYY-MM-DD]
[001]

Who is responsible

The controller for the processing described here is [CONTROLLER_LEGAL_NAME], [ADDRESS], contactable at [PRIVACY_CONTACT_EMAIL].

// The contact details shown elsewhere on this site are a joke and are not a route to the controller.

No Data Protection Officer has been appointed; the site does not carry out large-scale or systematic monitoring that would require one.

[002]

What we collect

Browsing this site does not require an account and does not build a profile of you.

  • Server logs. Our hosting provider records the usual request data — IP address, timestamp, requested URL, user agent — to serve pages and to detect abuse.
  • Theme preference. Choosing light or dark stores the value theme in your browser's local storage. It never leaves your device and is not read by us.
  • Administrator sign-in. If you sign in at /login with an Arweave wallet, we store a signed session cookie named fr_session containing your wallet address and an expiry. This only happens after you deliberately sign a challenge.
  • Contact form. The form on the home page is not connected to any backend. Nothing you type into it is transmitted or stored anywhere.
[003]

Cookies and local storage

We set no advertising, analytics or profiling cookies, so no consent banner is required. Only two items are ever written:

  • fr_session — strictly necessary. HttpOnly, SameSite=Lax, cryptographically signed, expires after 7 days. Set only when an administrator signs in, never for ordinary visitors.
  • theme — a local storage entry holding your light/dark choice. Functional, set only when you use the toggle, and removable by clearing site data.
[004]

Third parties that see your IP address

Some content is loaded directly from other servers. Your browser contacts them itself, which necessarily reveals your IP address, user agent and referring page to them. We do not control what they log.

  • fakeraredirectory.com and arweave.net — card artwork shown in the gallery.
  • trisha.hsd.services — the radio audio stream, contacted only when you start playback.
  • brooklyn.hsd.services — the events timeline data on the history page.
  • arweave.app — the wallet connector, contacted only on the administrator sign-in page.

Links to sites such as xchain.io are ordinary links: nothing is requested from them until you click.

// Fonts are served from this site, not from a font CDN, so no request is made to a third party to render text.

[005]

Why we are allowed to do this

  • Legitimate interests (Art. 6(1)(f)) — serving pages, keeping the site available, and protecting it from abuse. Server logs and the third-party content above rest on this basis.
  • Contract / pre-contract (Art. 6(1)(b)) — maintaining an administrator session for people authorised to edit the directory.
  • Consent (Art. 6(1)(a)) — where you actively choose something, such as starting the radio stream. You can withdraw it by stopping playback.
[006]

How long we keep it

  • Server logs: retained by our host for [RETENTION_PERIOD], then deleted.
  • Administrator sessions: 7 days, or immediately when you sign out or your wallet is removed from the authorised list.
  • Theme preference: until you clear your browser storage.
[007]

Your rights

Where we process your personal data you may request access, rectification, erasure, restriction, portability, and you may object to processing based on legitimate interests. Write to [PRIVACY_CONTACT_EMAIL].

You also have the right to complain to a supervisory authority in the EU or EEA country where you live or work.

// In practice we hold almost nothing that identifies you. If you have not signed in as an administrator, we are unlikely to be able to link any record to you, and we will not collect extra data purely to try.

[008]

Transfers, security and children

Depending on where our host and the services above operate, data may be processed outside the EEA. Where that happens we rely on the safeguards those providers put in place. Hosting is provided by [HOSTING_PROVIDER].

Traffic is served over HTTPS. Administrator access is proven by wallet signature — we never ask for, receive, or store a password, seed phrase or private key. No one operating this site will ever ask you for a seed phrase.

This site is not directed at children under 16.

[009]

Changes

If this policy changes materially we will update the date at the top of this page. Continuing to use the site after a change means the revised policy applies.

> _