Privacy notice
Last updated: 3 August 2026
1. Who processes data
Data is processed by the administration of Tibicen (tibicen.cc) — an independent, non-commercial project with no separate legal entity. Privacy and rights requests go via the Contacts page.
2. Data and legal bases
- Username, email, password hash, avatar, account status, comments, reactions, likes, favourites, author subscriptions, notifications, and the author application (name, bio, musical interests): account performance, Article 6(1)(b) GDPR.
- IP, request/security logs, device/browser and error data: security and defence of claims, Article 6(1)(f).
- Legally required data: Article 6(1)(c).
- View counting stores only an anonymised daily hash (SHA-256 of a salt, the date, and technical request attributes); the raw IP is not stored in the counter: legitimate interest, Article 6(1)(f).
- Page paths without query parameters, referrals, the fact and length of on-site searches (the query text itself is not sent), interaction events, click maps and link tracking (Yandex Metrica), approximate location, and Google Analytics 4/Yandex Metrica identifiers: consent, Article 6(1)(a). Refusal does not affect core functions.
3. Recipients and transfers
Recipients are the site administration and the technical providers the Service depends on: site and database hosting, the SMTP email provider (verification and password-reset emails), GlitchTip/Sentry-compatible error monitoring, and—only after consent—Google Analytics 4 and Yandex Metrica. Reports about comments, error reports, and guest “become an author” requests are forwarded to the administration via Telegram: the messenger provider receives the message content and, for the guest form, the submitted name and email; guest requests are not stored in the Service database. Transfers outside the EEA use adequacy decisions or safeguards such as EU Standard Contractual Clauses and supplementary measures where needed.
4. Retention
Account and activity data remain while the account is active and are erased from the live database after deletion. Password-reset links live until used, at most 60 minutes; registration codes — 15 minutes; security and error logs — up to 90 days; isolated backups — until scheduled overwriting, at most 30 days; analytics — per provider settings, at most 14 months. Longer retention applies only where legally required or needed for claims.
5. Cookies
Essential HttpOnly cookie wmg_jwt maintains login for up to 30 days; wmg_analytics_consent remembers the analytics choice. Analytics do not load before consent. The persistent Cookie settings control can be used at any time to withdraw consent and remove analytics cookies accessible to the site.
6. Rights and security
Subject to GDPR conditions, users may request access, correction, erasure, restriction, portability, object to legitimate-interest processing, withdraw consent, and complain to a competent supervisory authority. Requests go via the Contacts page; the normal response period is one month. Controls include password hashing, HTTPS, HttpOnly/SameSite cookies, access controls, and rate limiting.
7. Children, automation, changes
The Service is not directed to children under 16. No solely automated decisions have legal or similarly significant effects. Updates appear here with a new date and additional notice where required.