Identity and access
Email address, password credentials handled by Supabase Auth, confirmation and recovery state, login identities and sessions are used to create and secure an account.
Public privacy facts · version 1.1
This page maps what the current Cindra product handles, what members control and what it deliberately does not measure. The legal notice is now published. This page stays the product map.
Product facts updated 23 August 2026The categories below come from the active product schema and client behaviour. This review did not require reading names, goal text or private messages.
Email address, password credentials handled by Supabase Auth, confirmation and recovery state, login identities and sessions are used to create and secure an account.
Name, role, organisation, website, biography, experience, expertise, country, fields, avatar and chosen ways to help can form a member profile.
Goals, tasks, progress, posts, comments, help relationships, conversations and member-uploaded chat media support the human-help loop.
A new goal is private unless its owner explicitly chooses public. Missing, malformed and older visibility values fail closed as private.
Private messages and goal context are restricted to their participants. A private invitation reveals no goal or task on its public entrance page.
Signed-in discovery uses a restricted professional profile projection. It excludes email address, payment state and private goals, and results are not ranked by attention.
Public goals and contributions are only shown in their intended product surfaces. Private messages, private goals and internal behaviour are not offered to search engines.
The current model contains no advertising product or data-broker flow. The public release contains no Google Analytics, Tag Manager, Meta pixel or third-party font request.
The active feed is chronological. Cindra does not predict which person or contribution will hold attention and does not use authored text for engagement ranking.
Private activation events use fixed event categories, technical identifiers, scope and timestamps. They have no name, email, post, goal or message-content field and are not readable or writable by the browser.
Sparks, help offers and private acknowledgements do not become public totals, leaderboards or a competitive reputation score.
The public site runs through TransIP in the Netherlands. Accounts and application data use Cindra’s Supabase project in the Frankfurt region. Domain email is routed through Google Workspace. Supabase is controlled by a Singapore entity and its hosted Frankfurt region runs on AWS.
The European Commission explains that people must receive clear information about the controller, purposes, data categories, legal basis, retention, recipients, international transfers, rights and complaint route when data is collected.
Profile correction, local export, explicit visibility and account deletion are real product controls. They reduce dependency on a manual request for common actions.
Cindra must still document access, rectification, erasure, restriction, portability, objection, consent withdrawal where relevant, identity checks, response handling and escalation to the correct authority.
These sources describe the transparency and member-rights baseline. Only the GDPR and applicable law create legal rights and obligations; this Cindra page records current product facts.
First public product-level privacy map: data categories, private/public boundaries, member controls, measurement limits, provider dependencies and the exact legal work still open.