Privacy
Privacy statement
Version 0.1 (draft, 20 September 2026). Controller: the publisher of HangLobby (company details and contact address follow before the public launch).
What we process and why
- Account: e-mail address (signing in with a code), creation date, sessions. Basis: contract.
- Rooms: screen name per room, memberships, rooms you follow, settings. Basis: contract.
- Messages and topics: what you write, with time and room. Chat disappears after the room's retention period (30 days by default); topics stay as long as they are published. Basis: contract.
- Moderation: automatic pre-checking of text, reports, decisions with a reason, appeals and an audit log. Basis: legitimate interest (safety) and legal obligations.
- Audio table: who is at the table and in which role; short fragments from speakers can be checked automatically as text. Fragments are deleted immediately; only when there is a signal does a short text stay for 30 days for the room's moderation. No conversations are recorded. Basis: legitimate interest; you see this before you turn on your microphone.
- Paying: subscription, status and invoice details at our payment provider; we do not keep card or account numbers. Basis: contract and legal retention obligation (7 years for invoice data).
- Partner sites: if you sign in via a partner site, we only receive an anonymous link from that site — no e-mail address, no roles. The link applies to one room.
- Technical: IP address and browser in security logs (briefly), usage meters without content.
- Measuring whether it works: a small number of events without content (room opened, joined in, first message, reply received, came back, embed loaded) with a code per account that cannot be traced back instead of your data, kept for 90 days and only looked at as totals. No message text, no e-mail address, no tracking across websites. Basis: legitimate interest (improving the product).
What we do not do
- No advertising network, no tracking across sites, no selling of data.
- Private content never goes to advertising and not to routine external AI.
- No newsletter without separate consent.
Processors
- Hosting in Amsterdam (UpCloud); security and cache via Cloudflare.
- Live chat transport (Centrifugo) on our own servers.
- Audio/video: LiveKit Cloud (project data in Frankfurt).
- Automatic text checking and AI drafts for session reports: OpenAI moderation and, where needed, Anthropic — only the text, without names; a draft only from public rooms and only when the host asks for one. Never private content as a routine.
- Speech-to-text for the sample: Deepgram — only audio bytes, no identity.
- Paying: Stripe. E-mail: Amazon SES.
Retention periods
- Chat messages: the room's retention period (30 days by default). Topics: as long as they are published.
- Reports and audio signals: 30 days; moderation decisions and the audit log: up to 1 year.
- Account: until you delete it. Deleting erases your messages, frees your screen name and is applied again after a backup restore.
Your rights
Access and export: My rooms → Your data. Deleting: on the same page. Appeal against a moderation decision: via the decision itself. For other requests or complaints, mail the contact address above; you can also go to the Dutch data protection authority.