1. Who operates FixingBook
FixingBook is operated as an independent nonprofit community project. In this policy, “FixingBook,” “we,” and “us” refer to the maintainers who operate fixingbook.com and moderate its registry.
Privacy questions and requests can be sent to team@fixingbook.com. We may ask you to verify account ownership before acting on a request.
2. Information we process
| Category | Examples | Why we use it |
|---|---|---|
| Account data | Email address, display name, profile image, account ID, authentication provider | Sign-in, account recovery, attribution, and account security |
| Community activity | Guides, edits, comments, votes, verifications, moderation records, and reputation events | Operate the public registry and preserve its audit history |
| Technical and security data | IP-derived abuse signals, request metadata, user agent, timestamps, rate-limit records, and request IDs | Prevent fraud, spam, duplicate actions, and attacks; diagnose reliability problems |
| Uploads | Images you attach, validated file properties, dimensions, and storage keys | Show evidence or instructions in community content |
| Email delivery data | Email address, delivery status, and short-lived authentication or recovery links | Send messages that you request, such as magic links and password recovery |
| Analytics data | Page path, referrer, browser and device information, coarse region, and interaction events | Understand how the public registry is used and improve useful guides |
Do not include passwords, recovery keys, private tokens, personal addresses, or other sensitive information in guides, comments, screenshots, or uploads. Content submitted to public areas may be visible to anyone.
3. How we use information
- Provide authentication, account settings, contribution tools, and community features.
- Attribute public work and calculate server-side reputation and verification state.
- Protect accounts and infrastructure through rate limits, risk checks, Turnstile, and moderation.
- Deliver requested transactional email and respond to support, safety, or privacy requests.
- Maintain, debug, and improve the reliability and usefulness of the registry.
- Comply with valid legal obligations and protect users, the public, and the service.
Where privacy law requires a legal basis, we rely on the performance of the service you request, our legitimate interests in operating a safe nonprofit registry, compliance with law, and consent where consent is specifically requested.
4. Service providers
We share only the information needed for these providers to perform their role:
- Cloudflare hosts the application, database, session storage, and security controls. Turnstile processes browser and network signals to distinguish legitimate users from automated abuse. See Cloudflare’s Turnstile Privacy Addendum.
- Resend processes recipient addresses and message content for authentication and recovery email requested by users. See Resend’s Privacy Policy.
- Google provides optional OAuth sign-in. When you choose it, Google shares the profile fields shown on its consent screen, typically name, email, and profile image. You can manage that connection through your Google Account.
- Google Analytics processes usage measurements for the public website. FixingBook does not use analytics for advertising. See Google's Privacy Policy.
- Backblaze B2 stores validated image uploads used by the registry. See the Backblaze Privacy Notice.
These providers may process information in countries other than yours. Their own terms, safeguards, and privacy notices govern their processing.
5. Cookies and local storage
FixingBook uses essential cookies and browser storage for sign-in sessions, security challenges, interface preferences, and abuse prevention. Google Analytics may also use analytics identifiers to measure website usage. We do not use advertising cookies. Blocking storage may limit analytics and may prevent authentication or protected actions from working.
6. Retention and deletion
We retain account information while an account remains active and for a reasonable period afterward where needed for security, dispute resolution, or legal obligations. Authentication tokens expire. Security and abuse records are kept only as long as reasonably needed to protect the service.
Public contributions may remain in the registry after account deletion to preserve the integrity of technical discussions and revision history. Where appropriate, we will remove or detach personal profile information while retaining the contribution itself. Backups and provider caches may take additional time to expire.
7. Your choices and rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, or a portable copy of your personal information. You may also have the right to complain to your local data-protection authority. The European Commission provides a plain-language overview of data-protection rights in the EU.
Send requests to team@fixingbook.com. We will respond within the period required by applicable law and explain if an exception applies.
8. Security and children
We use access controls, encrypted transport, server-side authorization, upload validation, rate limiting, and audit records to reduce risk. No internet service can guarantee absolute security. Report suspected account or data exposure to team@fixingbook.com.
FixingBook is not directed to children under 13, and protected contribution features are not intended for anyone who cannot lawfully consent to data processing in their location. Contact us if you believe a child provided personal information without appropriate permission.
9. Changes to this policy
We may update this policy when the service, providers, or applicable requirements change. Material changes will be identified by a new effective date and, when appropriate, an in-product notice.
