Privacy Policy

Last updated Markdown version

On this page
  1. Who is responsible for your data
  2. 1Public by design
  3. 2What we collect, why, and our legal basis
  4. 3Who receives your data
  5. 4Our role, and yours
  6. 5Where your data is
  7. 6How long we keep your data
  8. 7Your rights
  9. 8The honest limits of deletion
  10. 9Security
  11. 10Children
  12. 11Data breaches
  13. 12Changes to this policy

This policy explains what personal data pyroclastic.cloud handles, why, and what rights you have. We’ve written it in plain language. Where the law forces a technical term on us, we explain what it means in practice.

Who is responsible for your data

Nick Gerakines, operating pyroclastic.cloud, based in Ohio, USA, is the “controller” of the personal data described here, meaning the one who decides how and why it’s used.

Contact: hello@pyroclastic.cloud

1. Public by design

Before the details, here is the most important thing to understand about an Atmosphere account: most of it is public, on purpose.

Public, and sent out to the network as you create it:

  • everything in your repository, including posts, replies, reposts, likes, follows, blocks, lists, and your profile, and the images and other files attached to them;
  • your handle, your DID (your account’s permanent identifier), and the public keys and server address in your DID document; and
  • whether your account is active, deactivated, suspended, or deleted.

Anyone can read this data, and many services copy and keep it. That openness is what lets you move between apps and providers without losing anything.

Private, kept by us and not published:

  • your email address and password;
  • the settings your apps save for you;
  • your sign-ins and the list of apps you’ve authorized;
  • the contents of private spaces;
  • who has shared access to your account; and
  • our server logs.

Direct messages on Bluesky are stored by Bluesky’s own chat service, not by us. When your app sends a message, it passes through our server on its way there, but we don’t store or log its contents.

We don’t look at your private data except when you ask us to, when we need to investigate a specific report of abuse or a security problem, or when the law requires it.

2. What we collect, why, and our legal basis

Under the GDPR we have to tell you our “legal basis” for each use of your data. Here it is, in a table you can actually read.

What we hold Why Legal basis (GDPR)
Your email address, which is required to create an account To send sign-in codes, confirm sensitive changes like moving or deleting your account, help you recover access, and tell you about anything that affects your account Performance of our contract with you, Article 6(1)(b)
Your password and app passwords, stored only as salted, one-way hashes To sign you in Contract, Article 6(1)(b)
Your handle, DID, DID document, and the signing and recovery keys we hold for your identity To host your identity, sign updates to your repository, and make the identity changes you ask for Contract, Article 6(1)(b)
Your repository and files To store your content and publish it to the network Contract, Article 6(1)(b)
Settings your apps save, such as saved feeds, muted words, content preferences, and any personal details an app chooses to store, like a birth date So your apps work the same way wherever you sign in Contract, Article 6(1)(b)
Private space contents and memberships To store your spaces and check who may read them Contract, Article 6(1)(b). For other people’s data you put in a space, see section 4
Sign-in sessions and app authorizations, meaning which apps you’ve connected, with what permissions, and when To keep you signed in and let you review and revoke access Contract, Article 6(1)(b)
Shared-access records, meaning who can act for your account and which identity took each action So shared accounts work and you can see who did what Contract, Article 6(1)(b), and our legitimate interests, Article 6(1)(f)
Invite records, meaning which invite code created which account To trace spam and abuse networks back to their source Our legitimate interests, Article 6(1)(f)
Server logs: IP address, DID, time, requested address, app or browser name, and response status Security, abuse prevention, rate limiting, and fixing problems Our legitimate interests, Article 6(1)(f). Keeping security logs is a recognized legitimate interest (GDPR Recital 49)
Messages you send us, reports, and records of moderation decisions To answer you, handle reports, and keep a record of decisions affecting accounts Our legitimate interests, Article 6(1)(f), and legal obligation, Article 6(1)(c), where the law requires a record

We don’t use analytics, advertising trackers, or fingerprinting on any pyroclastic.cloud website or server. The Cookie Policy covers the few cookies we do use.

3. Who receives your data

The network. Your public data (see section 1) is sent to anyone who subscribes to our server’s stream of updates, including relays, apps like Bluesky, search services, and archives. This is how the Atmosphere works.

The PLC directory. Most Atmosphere identities are recorded in a public directory called the PLC directory. When your identity changes, for example when you pick a new handle, change keys, or move to another provider, that change is published there and kept permanently, in a history anyone can read. That history includes your past handles.

Apps you authorize. Apps you connect to your account receive what you allow them to. Their own privacy policies apply to what they do with it.

Services your apps reach through us. When your app asks for your timeline, your messages, or a custom feed, the request often passes through our server on its way to the service that answers it, such as Bluesky’s servers, a feed service, or a moderation service. We pass your request along with a short-lived token that tells that service your DID. We don’t keep the contents of these requests.

Our service providers. These companies process data only on our instructions, under data processing agreements:

  • Railway runs our servers and stores account data; and
  • Mailgun sends and receives our email, so it handles your email address and the messages we send you.

Off-site backups stay with us. No third-party backup service holds a copy of your data. The operator, Nick Gerakines, periodically downloads our encrypted backups and keeps them offline, in a safe. These off-site copies contain only encrypted identity, key, and repository data. They never include server logs or records of account activity.

Highport. Highport is run by the same person but is a separate service with its own privacy policy. Having an account here doesn’t share anything with Highport beyond what any service can read publicly. If you publish a site with Highport, it reads your records under its own policies.

Legal requests. We disclose private data only when the law requires it. We review every request, push back on ones that are overbroad, and tell you before we disclose anything unless the law forbids it or someone’s safety is at immediate risk.

Never. We don’t sell, rent, or trade your data. We don’t share it for advertising. We don’t use your private data or your content to train AI models.

4. Our role, and yours

For the data in section 2, pyroclastic.cloud is the controller and is responsible for it.

If you put other people’s personal data into a private space you run, or run a shared account, you decide what goes in and who sees it, and you are responsible for that use, including, where data protection law applies to you, telling those people and having a lawful basis for it. If you’re an organization and need a data processing agreement covering this, contact us.

5. Where your data is

You sign in and manage your account through our entryway, Mayon, which holds your sign-in details and app authorizations and directs each request to the account server that holds your repository.

Server Where it runs
Mayon (mayon.pyroclastic.cloud), the entryway Railway, US East (Virginia)
Vesuvius (vesuvius.pyroclastic.cloud), an account server Railway, US East (Virginia)

Off-site backups are encrypted copies of identity, key, and repository data that the operator downloads periodically and keeps offline, in a safe. Email is handled by Mailgun in the United States. When we add servers, we will list them here before they accept accounts.

Our servers and our email provider are all in the United States, and pyroclastic.cloud is run from Ohio, USA. When we access the servers to operate and maintain the service, we do it over encrypted connections, as GDPR Article 32 requires. Where personal data moves from the EU or UK to a country without an adequacy decision, our agreements with our service providers include the safeguards the law requires, such as the European Commission’s Standard Contractual Clauses.

Your public data is copied by services all over the world. That is part of how the network works, and it’s outside our control.

6. How long we keep your data

  • Your account data, repository, files, app settings, and spaces: for as long as your account exists.
  • After you delete your account: we remove it from our servers right away. Copies in encrypted backups expire within 30 days.
  • After you move to another provider: we keep a deactivated copy for 30 days in case something goes wrong with the move, then delete it.
  • Server logs, including IP addresses: up to 30 days, then automatically deleted. If an outage delays the automatic deletion, we delete them as soon as service is restored.
  • Invite records: for as long as either account involved exists.
  • Messages you send us, reports, and moderation records: up to 3 years after the matter is closed, or longer where the law requires it.
  • Backups: each daily backup expires after 30 days.
  • Off-site backups kept in the safe: up to 30 days. They hold only encrypted identity, key, and repository data, never server logs or activity records.

7. Your rights

These rights apply to everyone with an account here, wherever you live. You can ask us to:

  • access the data we hold about you;
  • correct it if it’s wrong;
  • delete it (the “right to erasure”; see section 8 for an important limit);
  • restrict how we use it;
  • port it to another service; and
  • object to any use we base on legitimate interests.

You can do several of these yourself at any time: download your repository with your app’s data export option, change your email address from your account portal, review and revoke apps you’ve connected, move your account to another provider, or delete it. For anything else, email hello@pyroclastic.cloud.

You also have the right to complain to your local data protection authority, if there is one where you live. We’d rather you came to us first so we can fix it, but you don’t have to.

If you live in a US state with a consumer privacy law: we don’t sell your personal data or share it for targeted advertising, so there’s nothing to opt out of.

8. The honest limits of deletion

When you delete your account, we delete our copies and announce the deletion to the network. Well-behaved services remove their copies when they see that announcement, but we can’t make them, and copies others have made, including archives and screenshots, are outside our control.

The history of your identity in the PLC directory, including your past handles, is permanent and public. We can’t erase it, and neither can anyone else.

9. Security

We protect your data with encryption in transit, hashed passwords, limited and protected administrative access, and encrypted backups. The Security Policy explains how in more detail, how to report a vulnerability, and what you can do to protect your own account.

10. Children

pyroclastic.cloud is for adults only. We do not knowingly collect data from anyone under 18. If you believe a child has an account here, contact hello@pyroclastic.cloud and we will close it and delete their data.

11. Data breaches

If a data breach is likely to create a risk to you, we will notify the relevant authority within 72 hours of becoming aware of it, and we will tell you directly when the risk to you is high. We apply the 72-hour standard to every breach, for every account holder, wherever you live.

12. Changes to this policy

We may update this policy. When we make a significant change, we will email you at least 30 days before it takes effect, unless the law or an urgent safety or security problem requires a faster change, and we will update the “Last updated” date.