How we collect, use, and protect your data.
Last updated: 28 August 2026
TrueColours is operated by By Ylfa, Azuriet 33, 3831 VV Leusden, Netherlands. For privacy questions, contact us at help@truecolours.app.
When you create an account, we collect your email address, display name, and profile photo. You can sign in with an email link, Google, or Facebook.
Content you create in TrueColours: uploaded images, pen matches, page photos, your books, pen sets, and custom titles.
After you press Add Page photo or Replace photo, TrueColours sends the confirmed crop and saves your Page photo. We do not send the original, uncropped file. The temporary upload is private. Only our upload service and authorised operators can access it. Show this in the Gallery starts on for a new photo. Turn it off before saving to keep the photo private. A replacement keeps the existing sharing choice unless you change it. Answers entered while the photo saves stay in that window until the save is confirmed. Closing the browser does not keep those answers or guarantee that an unfinished upload will continue.
A signed-in User can post an Idea, support an Idea, and add one public reason. Signed-in Users can see the Idea, its author name, its public reasons, its status, and its support count. We store each vote against the User's account to prevent duplicate votes. A report is private. It stores the selected reason, a copy of the reported text at that time, and a personal hide for the reporter.
When you block someone, we store that User's identifier and the date you blocked them. We use this record to stop either signed-in User from seeing or interacting with the other while signed in, and to remove their direct social connections. Public content can still be viewed while signed out. The record is deleted when either User is permanently deleted.
A signed-in User can privately report a public Page photo. We store the selected category, optional details, reporter account, Page photo, time, case, and human decision. The protected Admin queue shows reporter identity only on the case page. The affected User never receives reporter identity or report details. An operator alert contains only the case reference, coarse category, and secure Admin link.
Standard server logs collected by our hosting provider (Vercel): IP address, browser type, and device information.
Your browser stores display preferences and recovery copies of your edits. Section 8 explains what these copies contain, when they are removed, and the limits of offline access.
We use a privacy-first product-analytics tool (PostHog, EU) to understand which features people use, so we can improve the service. It records a small set of product events (such as page views and key actions like starting a trial or completing a purchase). Analytics state stays in memory for the current page session; PostHog creates no cookie, local-storage entry, or session-storage entry. We do not use automatic click tracking, session recording, or analytics for advertising. If you are signed in, the only personal identifier we attach is your account ID — never your email or other personal details. Where your browser still sends a Do Not Track signal, PostHog treats you as opted out.
When you join the beta waitlist, we store your email address, where you opened the form, the contact promise you accepted, and the submission date. We may email you a beta invitation. If you do not join, we may email once more at public launch. We send no promotions, newsletters, or other marketing follow-up. If you unsubscribe, we cancel pending waitlist emails. We delete identifying waitlist data no later than 30 days after the launch email or 12 months after unsubscribe, whichever comes first. If your email already belongs to a TrueColours account, we store nothing and send no waitlist email.
If a TrueColours Admin sends you a direct Beta invite link, the Admin stores a short label to tell that link apart from other invitations. The label is for Admin use only. It does not verify your identity. When you use the link, we store the email address that you choose and send a confirmation email before account setup.
When you use the Help & feedback form, we collect the email address you provide for a reply, the topic you choose, and the pen set, book, or message details you enter. We give the submission a reference and send you a copy. We use the full message to answer you and maintain a reasonable Support record. For a problem report, you can choose to add the page path without anything after ? or #, app release, browser and device description, window size, and UTC time. You can inspect these details before you send them. You can also attach one private screenshot. We verify, resize, and remove embedded metadata from the image before we send it only to the Support inbox. We do not save the image in app storage or attach it to your email copy. Pen-set and book requests may also create a separate product Signal containing the submitted product detail and reference, but not your name, email address, account, or IP address.
If you report allegedly illegal public content, we collect the exact content URL, your explanation, and your good-faith confirmation. We also collect your name and email address unless the notice concerns suspected child sexual abuse or exploitation. We use these details to review the notice, send a receipt where contact information is provided, explain our decision, and handle an appeal.
| Purpose | Legal basis |
|---|---|
| Account management and sign-in | Contract performance (GDPR Art. 6(1)(b)) |
| Displaying your content in the community | Contract performance |
| Operating Community Ideas, votes, public reasons, personal hides, and content review | Contract performance and legitimate interest in improving and protecting the service |
| UI preferences (sidebar, sort order) | Legitimate interest (Art. 6(1)(f)), strictly necessary for the service |
| Processing payments | Contract performance (via Paddle) |
| Platform security and abuse prevention | Legitimate interest |
| Understanding feature usage to improve the service (privacy-first product analytics) | Legitimate interest (Art. 6(1)(f)) |
| Sending people on the Beta waitlist a possible personal invitation or one public-launch email, with no promotions or newsletters | Consent (Art. 6(1)(a)) — withdraw via the unsubscribe link in any email |
| Answering Support messages and prioritising pen set and book requests | Legitimate interest (Art. 6(1)(f)) and steps taken at your request |
| Reviewing illegal-content notices and communicating the decision | Legal obligation (Art. 6(1)(c)) and legitimate interest in keeping the service lawful |
| Reviewing Page photo reports, protecting Users, and communicating a human moderation decision | Legitimate interest in operating a safe community (Art. 6(1)(f)) and legal obligation when a notice concerns illegal content |
We prepare translations of public biographies, Page-photo descriptions, Community Ideas and public reasons when they are published or edited. Language detection runs on our server. Public text goes to the European Commission’s eTranslation service for translations into English, Dutch and French. The service processes the text in the EU and does not use it to train models. It may retain operational metadata. Ideas can appear translated automatically. Other text starts in its original language. We retain the original and reuse saved translations for up to 180 days. An edit or loss of public visibility removes outdated translations.
eTranslation produces automatic translations without human review. They help you understand another language, but their wording and meaning can contain errors. Check the original when a detail matters. The European Commission gives no accuracy guarantee and does not accept liability for translation errors.
The European Commission’s eTranslation service translates public text within the EU. It does not use submitted text to train its models. Operational metadata may be retained. eTranslation
Supabase Inc. (United States): database hosting, authentication, and file storage. Your data is stored in the eu-north-1 (Stockholm) region. Supabase's Data Processing Agreement and Standard Contractual Clauses apply.
Vercel Inc. (United States): application hosting, edge network, and server logs. Vercel's Data Processing Agreement applies.
Paddle.com Market Ltd (United Kingdom): payment processing as Merchant of Record. Paddle processes payment data directly; TrueColours does not store your payment card details. See Paddle's Privacy Policy at https://www.paddle.com/legal/privacy.
Google LLC (United States): OAuth authentication provider, only if you choose to sign in with Google. See Google's Privacy Policy at https://policies.google.com/privacy.
Meta Platforms Ireland Limited (Facebook) Ireland. Provides sign-in when you choose Facebook. Facebook privacy policy.
Functional Software, Inc. (Sentry) (Germany, EU data residency): error monitoring and session replay. Captures error stack traces, the URL where the error occurred, browser type, and a redacted recording of the page state at the moment of the error. Personal identifiers (IP addresses, cookies, request bodies) are not sent. See Sentry's Privacy Policy at https://sentry.io/privacy/.
PostHog, Inc. (United States company; EU data residency): privacy-first product analytics. Processes a small set of product events during the current page session to help us understand feature usage. Data is stored in the European Union. We disable persistent browser storage, automatic click tracking, and session recording. If you are signed in, the only identifier attached is your account ID — no email, IP-based profiling, or advertising use. See PostHog's Privacy Policy at https://posthog.com/privacy.
Resend, Inc. (United States): transactional email delivery (sign-in links, account verification, trial check-ins) and beta waitlist emails (confirmation when you join, a possible personal invitation, or one public-launch email), delivery of Support-form messages to our Support inbox, and receipts or decisions for illegal-content notices. Resend processes the reply email address, message contents, and any private screenshot that you choose to attach. See Resend's Privacy Policy at https://resend.com/legal/privacy-policy.
Cirrux (European Union): hosts our shared Support mailbox. Cirrux stores the email address, message contents, and any private screenshot that you choose to attach. Freek and Ylfa use this information to answer your message. See Cirrux's Privacy Policy at https://cirrux.co/privacy.
Cloudflare, Inc. (United States): bot-protection challenges on sign-up, sign-in, and the Help & feedback form (Cloudflare Turnstile). Turnstile processes your IP address and browser fingerprint to distinguish humans from automated traffic, without third-party tracking cookies. See Cloudflare's Privacy Policy at https://www.cloudflare.com/privacypolicy/.
Your data may be transferred to the United States (Supabase, Vercel, Google, Resend, Cloudflare) and the United Kingdom (Paddle). Sentry processes error data in Germany (EU) and PostHog processes product-analytics data within the European Union. These transfers are protected by the EU-US Data Privacy Framework, Standard Contractual Clauses, and adequacy decisions where applicable.
We keep your data while your account is active. Deleting your account clears your public Profile details immediately. You have 30 days to restore the account. At the end of that period, we delete your account, uploaded photos, and private data, including drafts, Collection, and preferences. Published pen matches may remain without your name. We may retain anonymised aggregate statistics, such as the total number of saved pen matches, but no data that could identify you. Server logs follow Vercel’s standard retention policy.
Beta waitlist: use the unsubscribe link in any waitlist email to stop these messages. We cancel pending emails and delete your identifying waitlist data no later than 30 days after the launch email or 12 months after unsubscribe, whichever comes first. You do not need to make a separate deletion request.
Direct Beta invitations: we delete the Admin label and reserved email no later than 12 months after the invitation is joined, expires, or is revoked. We delete them earlier if the related account is permanently deleted.
Temporary Page photo uploads: an unused upload expires after one hour. Our daily cleanup normally removes its files within 26 hours after cancellation or expiry. Failed cleanup is retried and monitored. We keep a small upload record for 30 days to make retries and cleanup safe. It records the account, Page, file checks, times, and whether the photo was saved or canceled, but not the answer text. If cleanup fails, we keep the record until the files are removed. After that record is removed, we keep only its random upload identifier to prevent an old request from saving the photo again. This entry contains no account, Page, photo, or answer details.
Support messages: we keep your message and reply address only as long as needed to answer you and maintain a reasonable Support record, unless a longer legal or transactional obligation applies. A screenshot that you choose to attach becomes part of that private email record and follows the same period. It does not enter app storage. A separate Signal may remain as product evidence without your identity, linked only by the Support reference so we can locate it if needed.
Illegal-content notices: we keep the notice, review notes, decision, and correspondence only as long as needed to handle the notice, an appeal, and any related legal record.
Community Idea reports: after a review case closes, we keep its report text, report-time copy, decision reason, and legal-hold reasons for 90 days. This is our operating policy, not a period set by law. It gives time to correct a decision or handle an appeal. A documented legal hold can pause deletion. The daily retention task removes this text after the period ends. It keeps only the text-free case facts needed to show that a review occurred.
Page photo reports: we keep open cases, active restrictions, appeals, and legal holds. At 180 days after a final resolution, when no restriction, appeal, or legal hold remains, an exact Admin action removes report details, reporter identity, internal notes, and inactive public-reason text. We keep the text-free Page photo reference, category, decision, Admin actor, and timestamps needed for a minimal audit. This is our operating policy, not a period set by law.
If you permanently delete your account, your votes, reasons, personal hides, and unengaged Ideas are deleted. An Idea that another User supported, or that has combine history, can remain without your identity so the shared community record stays coherent.
Under GDPR (Articles 15-22), you have the right to:
To exercise any of these rights, email help@truecolours.app or delete your account from your account settings.
You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at https://autoriteitpersoonsgegevens.nl.
TrueColours uses functional local storage for UI state (sidebar position and sort preference), pen-match recovery data, an on-device browser database for copies saved by earlier versions, and an essential authentication cookie issued by Supabase to keep you signed in. Saved copies can contain pens, Page or sampling images, and pending edits. Offline access is not currently supported. Device data can be removed when you remove a copy, sign out, switch accounts, or clear the browser's data; the browser may also remove it if storage space is low. Signing out or signing in to a different account removes saved copies and unsynced edits before the next account's private pages appear; those unsynced edits cannot be recovered after the account change. Pending edits are sent to TrueColours when the app attempts to save them with a connection. Our privacy-first product analytics (PostHog, EU) uses memory only for the current page session: it creates no cookie, local-storage entry, or session-storage entry and performs no cross-site or advertising tracking. Vercel Speed Insights collects anonymised performance metrics (Core Web Vitals) so we can keep the site fast, without storing an identifier against your visit. Because analytics creates no browser storage and the remaining storage is functional or essential, you will not see a cookie-consent banner.
TrueColours is not intended for children under 16, which is the age of digital consent in the Netherlands. We do not knowingly collect data from children under 16. If we discover that we have, the data will be deleted promptly.
If we make changes to this policy, we will notify you by email or through an in-app notice at least 30 days before the changes take effect. The "Last updated" date at the top of this page will be revised. If you disagree with the changes, you can close your account and export your data during that notice period.
Want to manage your data or ask a privacy question?