Privacy Policy
Version 1.4. Last updated: 7 September 2026.
This policy explains what data vyaz.net (the "Service") collects, why, and what you can do about it.
1. What we collect
- Account data: email address, username, display name, password (stored only as a hash), preferred language, optional avatar and profile text.
- Content you publish: patterns, project progress, posts, comments, reviews, inventory entries and messages.
- Technical data: IP address, browser user agent, timestamps of actions, and session identifiers. These are used to detect and stop abuse, and access to them inside the Service is limited to what a specific investigation requires.
- Payment data: if you purchase virtual currency, payments are processed by a third-party provider. We do not receive or store your card details.
We do not interrogate your device: the Service runs no fingerprinting script and reads no canvas, font list or device identifier. What it does read from the browser is the time zone your system is set to, once, so that your own stitching days are counted where you live; you can set the zone yourself instead, and if you have, the browser is not asked again. What it stores on your device is listed in section 8.
2. Why we collect it
- To operate your account and display your content.
- To keep the Service usable. This purpose is a list rather than a word: preventing automated mass registration, detecting password guessing, stopping spam at the moment of publication, enforcing rate limits, and investigating a specific incident. Without IP addresses and user agents the Service cannot be defended against automated abuse.
- To investigate reports and disputes.
- To translate published content into the languages the Service offers (section 6).
- To decide whether an advertising slot is shown to you (section 8).
- To establish, exercise or defend legal claims — which is why support tickets and rights claims outlive the accounts they concern.
- To comply with legal obligations and to answer lawful requests from authorities (section 10).
3. Legitimate interests, and your right to object
Operating your account rests on our contract with you. Answering a binding order rests on a legal obligation. The rest of the processing above rests on our legitimate interests under Article 6(1)(f) GDPR, and we have written down the assessment behind that rather than asserting it: what each interest is, what it costs you, and why it outweighs that cost.
The interests are three. Defending the Service against abuse — the enumerated list in section 2, not "security" in general — which is what makes an open community possible at all. Funding the Service by advertising, in the limited form section 8 describes. Establishing and defending legal claims, which is why a decision, a ticket and a rights claim are kept after the person concerned has gone.
What limits the cost to you: the data is what the purpose needs and no more; raw addresses are erased on the clocks in section 4 and replaced by a one-way code that cannot be turned back into an address; access to them is limited to staff acting on a specific case; nothing here is used to build a profile of you, to select what you are shown, or to make a decision about you without a person (section 7); and none of it is sold or shared for anybody else's purposes.
Your right to object. You may object at any time to processing based on our legitimate interests, on grounds relating to your particular situation, by writing to [email protected]. We will stop that processing unless we can demonstrate compelling legitimate grounds that override your interests, or unless we need the data to establish or defend a legal claim — and where we do, we will tell you which of the two it is and for what data. This right stands whatever else this policy says.
4. How long we keep it
- Account data: while the account exists.
- IP addresses and user agents: kept in full for a limited period for abuse prevention — ninety days for the addresses an account is seen signing in from, one year for the address an account registered from — and then erased. What we keep after that is not the address but a one-way code calculated from it together with a secret key we hold separately: it lets us tell that two accounts used the same connection, which is how mass registration and ban evasion are recognised, and without that key it cannot be matched back to an address. This is pseudonymised data rather than anonymous data, so it remains covered by this policy and by your rights below. We keep it with no fixed end date, for that one purpose, because the gap between an account being closed for abuse and the same person returning is measured in years; it is erased when the account it belongs to is erased.
- Published content: until you delete it, subject to the notes on deletion below.
- Moderation records and reports: kept as long as needed to enforce decisions consistently and to answer for them, which outlasts the account they concern — a decision has to stay explicable after the person it was about has gone. Where such a record notes the connection behind an action — a staff decision, or a report — it holds a one-way code of the kind described above and a browser description, never an address. So these records are not on the clocks named above and do not need to be: there is no address in them to erase, because none is written into them.
- Support tickets and rights claims: kept beyond the account, because they are the record that an obligation was discharged and the evidence in a claim that may still be brought.
- Records of a reading made in answer to a lawful request (section 10): kept without a fixed end date and never altered, because their whole value is that they show the limits of what was read.
5. Private messages
Private messages are not public, but they are not end-to-end encrypted. Where a complaint, dispute or suspected abuse requires it, authorised staff may read messages relevant to that case. Such access is logged. Section 10 describes the separate case of a lawful request from an authority. Do not send anything through the Service that you would not want a moderator to read.
6. Machine translation
Published content is translated automatically into the other languages the Service offers. To produce a translation, the text is transmitted to a third-party provider of language models, which may be located outside your country; where that is so, the transfer is made under the safeguards required by applicable law.
What is sent is the text and nothing attached to it: the title, summary and description of a chart published in the catalogue, articles and their comments, short posts, and reviews. Your email address, your username, your IP address and your account identifier are not sent. Drafts, private charts, hidden content and private messages are not translated and are not sent anywhere.
Translations and the sentence pairs they are built from are stored on our systems, so that the same sentence does not have to be sent a second time. Do not publish sensitive personal information in content that will be translated.
7. Automated checks and decisions
Nothing you publish is submitted to an artificial-intelligence service to be assessed, scored or classified. The automated processing that does happen is the following, and all of it is mechanical: a list of forbidden words that refuses a submission containing one; rate limits and duplicate checks; the weighing of reports made by other users, which hides a publication once their combined weight passes a threshold; and the comparison of the technical data in section 1 between accounts, which is how one person operating several accounts is recognised. A bot check from Cloudflare runs on the registration and rights-claim forms; it sees the address and browser of the request.
Decisions about you are taken by a person. The single exception is a time-limited pause on publishing applied to a newly registered account reported for spam by several different people; it is never a suspension, it is reviewed by a person, and you may ask for that review by replying to the notice. You have the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you, to express your point of view, and to contest the decision.
8. Advertising and cookies
What the Service stores on your device is three things and no more: the cookie that keeps you signed in and carries the session; a cookie holding the time zone your browser reports, read once as section 1 describes; and, if you arrived through an invitation or a campaign link, a cookie holding that link's code for thirty days, so that the invitation can be credited to whoever sent it. There is no analytics cookie and no advertising cookie.
The Service may display advertising, in the declared places named in the Terms of Use. Whether a slot is shown to you at all is decided on our own servers from two facts about your account — whether it holds a paid subscription, and the standing it has earned in the Service's reputation system — and that decision is made before anything outside the Service is contacted. Advertising here is not selected from your content, your private messages, or a profile built about you, and we do not share your personal data for advertising profiling.
Where we engage an advertising or analytics provider whose code runs in your browser, we will name it here before it does, and where it requires storing or reading anything on your device we will ask for your consent first and let you withdraw it.
9. Who else processes it
We do not sell your personal data and we do not transfer it to third parties in exchange for payment. Data may be processed by service providers acting on our behalf and under contract — hosting, storage, content delivery, network and bot protection, email delivery, payment processing and machine translation. Some of these providers operate outside your country; where that is the case, transfers are made under the safeguards required by applicable law.
10. Requests from public authorities
We disclose data where the law requires it, including in response to a lawful request from a court, law-enforcement or another competent authority; such a request may cover the content of private messages. We answer what the request covers and nothing beyond it. Where we are legally required or permitted to keep such a request confidential, we will not notify you of it. We do not volunteer user data to anyone who has no legal right to it.
The means of reading message content for such a request is not part of the ordinary administration of the Service. It is switched off by default; it is reachable only by the operator's own account, only from a permitted network address, and only after a second authentication factor; and every reading it performs is written to a record that the Service itself cannot alter or delete, naming who read what, about whom, and when. That record exists so that the limits of what was read can be shown afterwards.
11. Your rights
You may request access to your data, correction of inaccurate data, deletion of your account, an export of your content, restriction of processing, and you may object to processing based on our legitimate interests (section 3). Write to [email protected]. We may ask you to confirm that you control the account. If you are in the EU or the UK you may also complain to your national data protection authority.
12. Closing your account
Closing your account hides it immediately and starts a recovery window, stated in the message we send you when you close it. After that window your personal data — email address, display name, avatar, profile texts, and the addresses recorded at registration and last sign-in — is erased. Erasure is confirmed by a person rather than performed by a timer, because it cannot be undone.
What you published stays published, shown as the work of a closed account and linking nowhere; your username is not erased and not released, because releasing it would let somebody else inherit everything filed under it. Content that others rely on — a comment in a discussion thread, a message in somebody else's conversation — stays where it is without your name, so that conversations remain readable. Support tickets and rights claims are kept, as section 4 describes. Backups are rotated and may retain data for a limited period after erasure.
13. Security
Passwords are stored hashed. Traffic is served over HTTPS. No system is perfectly secure; if a breach affects your data we will notify affected users where required by law.
14. Children
The Service is not intended for children under 16. If we learn that an account belongs to a child below that age, we will remove it.
15. Changes
We may update this policy. Each version carries the number and date shown at the top of this page, and material changes will be announced within the Service.
Contact: [email protected] · Terms of Use · Community Rules