Privacy Policy
This is a short, honest description of what Third Platz actually collects today — not a boilerplate list of things a bigger company's stack might collect. If that changes, this page changes with it.
What we collect
Three things, all directly tied to using the service:
- Account email, if you create one. Used only for login and, if you ever request it, account recovery. Your password is stored hashed, never in plain text.
- A legacy stub identity cookie. Earlier versions of the service gave every visitor a random, signed cookie that tied their contributions to a consistent (but not personally identified) handle, like "swift-falcon-07". Contributing now requires an account, so no new stub cookie is ever issued; an existing one is only still read so a visitor who has one keeps seeing their own past contributions as theirs. It contains no personal information by itself.
- Content you contribute. List titles and descriptions, item blurbs, entity details (name/kind/address/url), and votes, all attributed to your account (or, for contributions made before accounts were required, to a legacy stub identity).
- An optional home location, geo-level only (e.g. a city or country, never a precise address or coordinates), if you choose to set one on your own profile. It's never inferred from your IP address or any other signal — only set, changed, or cleared by you, from your own profile page — and it's used to power an optional "Locals" ranking lens on list pages.
What we don't collect
For human visitors, Third Platz runs with no analytics and no third-party trackers of any kind — no ad pixels, no cross-site tracking cookies, no behavioral profiling. We don't collect your IP address for anything beyond the request-rate-limiting already required to keep the service usable (see Security in the project README), and that isn't stored long-term. (See "Automated traffic and search-gap logging" below for the separate, narrower logging that applies only to automated/bot requests, not to people.)
Cookies
Two cookies, both functionally required (not for advertising or tracking): a session cookie if you're logged in, and the legacy stub identity cookie described above if you were given one before accounts were required. Neither is used for cross-site tracking.
How data is stored and shared
All data lives in a single database operated by us. We do not sell or share your data with third parties. Because content you contribute is, by design, publicly visible on the site (that's the product), don't include personal information in a list title, blurb, or entity detail that you wouldn't want public. Every account, and every legacy stub identity, also has a public profile page (/u/{handle}) that aggregates this same already-public contribution history — lists created, items added, posts, comments, with counts — nothing beyond what's already visible elsewhere on the site, and never your email or votes. Karma (shown next to your handle and on your profile) is public too, derived entirely from that same public contribution history — never from your individual vote history, which stays closed, always.
Your choices
Reading needs no account and never will; contributing does, so the only data we hold about you is what you chose to sign up with and what you chose to contribute. Your home location (see above) is entirely opt-in, and you can change or clear it at any time from your own profile page — nothing else on the site requires it. If you have an account and want it removed, or have any other privacy question, contact us — see below.
Automated traffic and search-gap logging
Separately from anything above, we log two narrow things about automated requests — not about people. Neither changes the "no analytics, no trackers, no behavioral profiling" promise above, because neither applies to human visitors or measures individuals.
First: when a request to a machine-readable surface (the markdown twins, robots.txt/llms.txt, and similar endpoints) is classified as automated — a bot, scraper, or agent, not a browser being used by a person — we log the user-agent class, the path requested, a coarse (hour-level) timestamp, and a salted hash of the IP address. This exists to produce weekly aggregate rollups of automated traffic (how much, what kind, to which paths) — not to build a profile of any bot, operator, or the human behind one. The salted hash is used only to de-duplicate repeat requests and support rate-limiting; it is never linked to an account, legacy stub identity, or contribution history, and the salt itself is never published.
Second: when a site search returns zero results, we store the normalized query text (not the raw query as typed, and not tied to who typed it) as a candidate for the "wanted list" — a curated feature for seeing what's being looked for that we don't have yet. These candidates are never shown publicly as raw text; only entries a human has reviewed and approved can ever become a visible list suggestion.
- Raw automated-read log entries (user-agent class, path, timestamp, IP hash) are pruned after 30 days.
- Weekly aggregate rollups computed from that log (counts and trends, no per-request detail) are kept indefinitely — they're statistics, not records of any individual request.
- Search-miss candidates are kept for up to 90 days, then deleted if never approved onto the wanted list.
Changes to this policy
If what we collect changes — for example, if analytics are added later — this page will be updated to reflect it truthfully, not left stale.
Contact
Privacy questions: [email protected].