Public privacy facts · version 1.1

Private by default. Open about the gaps.

This page maps what the current Cindra product handles, what members control and what it deliberately does not measure. The legal notice is now published. This page stays the product map.

Product facts updated 23 August 2026

What this page is

This is a factual product map. The legal privacy notice is at privacy.html. Processor contracts, a full retention table and transfer safeguards are still unfinished and are named as such in that notice.

What Cindra currently handles

The categories below come from the active product schema and client behaviour. This review did not require reading names, goal text or private messages.

Account

Identity and access

Email address, password credentials handled by Supabase Auth, confirmation and recovery state, login identities and sessions are used to create and secure an account.

Professional context

Profile and real work

Name, role, organisation, website, biography, experience, expertise, country, fields, avatar and chosen ways to help can form a member profile.

Collaboration

Goals, contributions and messages

Goals, tasks, progress, posts, comments, help relationships, conversations and member-uploaded chat media support the human-help loop.

Private and public boundaries

Goals start private

A new goal is private unless its owner explicitly chooses public. Missing, malformed and older visibility values fail closed as private.

Private collaboration stays relational

Private messages and goal context are restricted to their participants. A private invitation reveals no goal or task on its public entrance page.

Professional discovery is bounded

Signed-in discovery uses a restricted professional profile projection. It excludes email address, payment state and private goals, and results are not ranked by attention.

Public content requires a deliberate act

Public goals and contributions are only shown in their intended product surfaces. Private messages, private goals and internal behaviour are not offered to search engines.

Controls members have today

Correction
Members can edit their profile, professional context, goals and execution details from inside Cindra.
Visibility
Goal visibility is an explicit member choice. Cindra does not infer a publication decision from authored text or behaviour.
Export
A signed-in member can build and download a readable JSON export in the browser. It is not uploaded to a separate export service.
Deletion
Self-service account deletion removes the account, profile, owned content, goals, execution data, help relationships, identities, sessions and owned media. Words authored by other conversation participants may remain because those people control their own words.
Device cleanup
A successful sign-out clears account-bound Cindra data from local and session storage on that browser. Language and theme remain as device preferences; complete account deletion clears those too.
Human help
welcome@cindra.eu is available for a human account or privacy question. A dedicated privacy contact and formal identity-verification workflow are still to be published.

What Cindra does not turn into an attention product

No advertising or data sale

The current model contains no advertising product or data-broker flow. The public release contains no Google Analytics, Tag Manager, Meta pixel or third-party font request.

No AI-ranked feed

The active feed is chronological. Cindra does not predict which person or contribution will hold attention and does not use authored text for engagement ranking.

Bounded product measurement

Private activation events use fixed event categories, technical identifiers, scope and timestamps. They have no name, email, post, goal or message-content field and are not readable or writable by the browser.

No public human score

Sparks, help offers and private acknowledgements do not become public totals, leaderboards or a competitive reputation score.

Where the data path depends on others

The public site runs through TransIP in the Netherlands. Accounts and application data use Cindra’s Supabase project in the Frankfurt region. Domain email is routed through Google Workspace. Supabase is controlled by a Singapore entity and its hosted Frankfurt region runs on AWS.

European location is not presented as European ownership or proof of complete GDPR compliance. Provider contracts, subprocessors, support access, logs, backups and international-transfer safeguards still require a formal processor review. See the public infrastructure map for the current evidence and limits.

Rights need more than two buttons

The European Commission explains that people must receive clear information about the controller, purposes, data categories, legal basis, retention, recipients, international transfers, rights and complaint route when data is collected.

Useful controls already exist

Profile correction, local export, explicit visibility and account deletion are real product controls. They reduce dependency on a manual request for common actions.

The formal workflow is unfinished

Cindra must still document access, rectification, erasure, restriction, portability, objection, consent withdrawal where relevant, identity checks, response handling and escalation to the correct authority.

Work that remains after the notice

Controller
Published as Cindra.eu, eenmanszaak, KvK 77856295, VAT NL003251089B31. No street address on the site.
Notice
English and Dutch privacy notices and membership terms are live. Payment checkout is not.
Retention
Decide and implement periods for backups, security records and deleted-account remnants.
Processors
Verify DPAs, roles, subprocessors and transfer safeguards for Supabase, TransIP and Google Workspace.
Legal review
Have a lawyer check the live notice against the real product. This page is not that review.

Primary EU references

These sources describe the transparency and member-rights baseline. Only the GDPR and applicable law create legal rights and obligations; this Cindra page records current product facts.

Change history

First public product-level privacy map: data categories, private/public boundaries, member controls, measurement limits, provider dependencies and the exact legal work still open.