Privacy.

Three different things live under this word here: what somebody else is told because you signed in, what we hold about you, and what the chain holds because you published it. They could not be more different, so this page keeps them apart. The first one goes first because it is the one nobody expects.

What Google is told

There are two ways to publish a page here. One is a Hive wallet, and it involves nobody but you. The other is signing in with Google, and that one tells Google something about you every single time: that you have an account at opntr.ee, on the day you make it and on every day you sign in. Google sees when, and the network and the device you did it from, the same as for every other site anybody uses a Google account at, and it lands in your own Google account activity where you can read it back for yourself. We cannot switch that off and we are not told what is done with it.

Two bounds on that, stated exactly, because overstating either would be worse than saying nothing at all. Google is not told which Hive account is yours, what is on your page, or that you published anything, because the only thing that crosses is a sign-in to a domain. And a court order served on Google reaches the fact that somebody used opntr.ee and stops there, where the same order served on us reaches the name.

Google is not a processor of ours and this page will not call it one. For the sign-in itself Google decides what it records, under its own policy, and not on our instructions, which makes it an independent controller in its own right and makes us the party that sent you to it. One thing more, if the Google account is a work or school one: whoever runs that account can reset its password and sign in as you, here and everywhere else, and can switch this way in off for everybody at that organisation at once. That is Google’s model rather than ours, and nothing we do here alters it.

What we hold about you

If you have only read pages here, nothing. There are no visitor accounts, no tracking, no advertising pixels and no analytics of any kind, and nothing about your visit is recorded here unless you sign in.

Signing in changes that, and what follows is the whole of what it changes, said in the affirmative. A list of things we do not do makes a linkage invisible by naming only what is absent.

We hold the link between your Google account and your Hive account. That link is what makes signing in work at all, and it is the thing anybody wanting to know who publishes a page would ask us for. It carries the email address Google gives us, which is where a notice about your keys is sent.

Four private keys to the Hive account we made for you. They are encrypted, in a store this website cannot open by itself, and there is exactly one route out of them, which never ends in a refusal: a fresh sign-in at Google made on the spot, a second thing that proves it is you, a wait of between an hour and thirty days set by how old that second thing is, a notice to every address and every device we have for you, and a cancel that works on any day of the wait.

A fifth key is ours rather than yours, and it sits inside your account’s own posting permissions. It is what signs your page and puts your pictures up under your name. One operation from any Hive wallet takes it and our other permission away together, and anybody can read on Hive that they are gone rather than take our word for it.

We are your account’s recovery partner on Hive, which is how a stolen owner key can be fought. For thirty days after you change that key we still are, whether or not you still want us to be, because that is how long Hive counts an old owner authority as recent.

Nothing in that list signs anybody in. There is no password of yours here, no code and no token: a full copy of our database would tell somebody who signed up and which Hive account is whose, which is serious, and it would not let them become any of them. The rest is sessions, the abuse controls, and the record of what we signed for you. An IP address is never kept whole, only the network it arrived from: a /24 of an IPv4 address, and a /64 of an IPv6 one. Card details are Stripe’s if and when payments arrive.

What the chain holds because you published it

A page you publish through this site is a signed operation on the Hive blockchain: public, worldwide and permanent. The chain is not ours to run, and nothing on it is ours to rewrite. We can decline to show something in our own reader, and doing that leaves the chain exactly as it was, because other readers will still show it. Publish what you are content to have stand.

If your account is one we made, there is a second half to that and it is the weaker half. Two things on the chain were signed by us rather than by you: the operation that created the account, which bound a permanent public Hive name at a moment we chose, and every publish of your page, signed with a key of ours that your account granted. Nobody can undo either, we least of all, so asking us to erase them is asking for something that does not exist. What you can do is end the arrangement going forward, from any Hive wallet, and take your keys.

Pictures sit just outside all of that, and it is worth knowing which way. Your page carries the address of a picture rather than the picture itself, and a picture uploaded here goes to Hive’s own public image service rather than into a block. It is public from the moment it is uploaded, that service has no delete, and changing the address on your page stops this reader showing it while the file stays where it was put. On the wallet path your own key signs the upload. On the path where we made your account, the key of ours inside your account signs it, so the file goes up under your name with us as the party that signed for you. The location and camera data come out of the file first, either way.

Who sees your requests

Reading a page asks Hive’s public nodes, sometimes directly from your browser. The operators of those nodes see the requests, the way any site’s host sees its traffic. We send them nothing about you beyond the request itself. Signing in is the exception to that sentence and it is the section at the top of this page.

Cookies

There were none. There are three now, all of them ours, and none of them for advertising or measurement. Two are session cookies, one saying you are signed in and one the pair to it, and no site can sign anybody in without them, which is why they ask no consent.

The third gets its own paragraph because it is set before you have proved anything to us at all. It is called __Host-opntree_flow, it holds up to three random values and nothing else, and it lasts ten minutes. Its whole job is to match a sign-in coming back from Google to the browser that started it, which is what stops a link pasted into a chat window from signing somebody into your account. Strictly necessary is a claim rather than a category, and that is the claim.

Your rights

Under the GDPR you may ask what we hold about you, have it corrected, or have it deleted. Here those are routes rather than promises.

Access and portability. An export gives you your account name, the four public keys, every identity linked to you and the rows themselves, the same day rather than within the month the law allows.

Erasure. A deletion removes what we hold: the link between your Google account and your Hive account, and your sessions here. It reaches nothing on Hive, and it reaches nothing in Google’s own record of having signed you in. Take your keys before you ask for it, because afterwards there is nothing left here that proves you are you.

Rectification splits, and saying so is better than offering a form that cannot work. Your address is held inside your Google account, so it is corrected there and reaches us the next time you sign in. Everything else is the editor.

The keys are their own route, and it is the strongest right on this page. The wait and the fresh sign-in standing in front of them are identity checks under Article 12(6) and security measures under Article 32. The wait is thirty days at its very longest, and there is no case in which it ends in a refusal. One exception, stated rather than buried: somebody who cannot sign in at Google at all cannot reach the route, and what we can do for them is a judgment a person here makes rather than a right we are able to promise.

When somebody with a court order asks

We hold the link between a Google account and a Hive name, which makes us worth asking, and saying nothing here would amount to saying we hand it over. So: we require valid legal process from a competent Dutch or EU authority, or a request through the mutual legal assistance route. We refuse informal requests. We tell you unless we are forbidden to, and when a prohibition lapses we tell you then. We publish a count once a year.

Two things follow that are worth knowing rather than working out. There is a second place to serve an order now and it holds less: Google can be asked whether somebody signed in to opntr.ee and can answer that, and cannot be asked which Hive account is theirs, because Google was never told. And an order over the vault is a different instrument from an order over the link, because it can move an account and it can never unpublish anything. The same requirements apply to it, and the yearly count includes every route that reaches the vault from outside the ordinary flow.

Age

You need to be sixteen for us to make you a Hive account. It is public and permanent, and nobody can undo it later, which is not a thing to sign somebody up to quietly.

Asking us

Questions, and any of the rights above, reach us through OpenAttribute.

Connecting