§Legal
Privacy.
What Agora keeps about you, where it lives, and how to get it removed.
The short version
Looking needs no account and leaves almost nothing behind. Posting needs an account, and what you post is public by design. There are no advertising trackers, no analytics scripts and no third-party fonts on this site.
When you only look
- A cookie called
agora_sidholds a random id. It lets the site count a view or a brand click once per visitor instead of once per page load, and count how many people are here right now. It says nothing about who you are. It lasts a year and is deleted from our side after 90 days without a visit. - Your address (IP) is never stored. A hash of it, salted with a value that changes every day, is kept for a short while to stop scripts from inflating views and to limit abuse. The hash cannot be turned back into the address, and yesterday’s hash cannot be matched with today’s.
- The name your browser sends (the user agent) is stored with the session, to tell people from crawlers.
- Page loads are counted as a number. Nothing about which pages, by whom.
When you make an account
- Your email address and your password. Sign-in is handled by Supabase Auth; the password is stored only as a hash and this site never sees it in the clear. If you sign in with GitHub or Google, we receive the email address and public name those services share, and nothing else.
- Your username, and whatever you choose to put on your profile: a short bio, a location, links, an avatar.
- What you post: projects, their images, comments, reactions. All of it is public and shown with your username.
Brands
A brand asking for a slot gives a brand name, a line, a link, a logo and a contact email. The name, line, link and logo are shown on the board; the email is used for the invoice and the go-live note and for nothing else.
Where it lives
- The database, accounts and images: Supabase, in Frankfurt, Germany.
- The site itself: Vercel, with its server code running in Frankfurt and its static files served from Vercel’s network worldwide.
- Emails about your account (confirmation, password reset) are sent by Supabase Auth.
How long
- Sessions: 90 days after the last visit. Abuse counters: two days. Brand requests that were never followed up: 90 days.
- Content you remove is marked removed and hidden at once. It stays in the database so a moderator can restore it if it was removed by mistake, and is deleted with the account.
- An account and everything attached to it is deleted on request.
Your rights
You can ask what we hold about you, have it corrected, or have it deleted. Write to iason.parthenidis@gmail.com. Under the GDPR you may also complain to a data protection authority; in Germany that is the authority of the state you live in.
Who is responsible
The person named in the imprint.