FEED

Privacy Policy

Last updated: July 23, 2026

This Privacy Policy explains what personal data HowTo collects, why, and who it's shared with. Like our Terms of Service, this is an early draft matching how the product works today, not yet reviewed by a lawyer — the Operator's legal details are still placeholders pending finalization.

1. Who processes your data

HowTo is operated by [RAGIONE SOCIALE DA DEFINIRE] ("the Operator", "we"), which acts as data controller for the personal data described below. Contact details for data protection requests: [EMAIL DA DEFINIRE].

2. What we collect

Depending on how far you go through account verification, we collect:

  • Email address — required to create an account (base level).
  • Phone number — required to reach Creator level and publish content, verified via SMS one-time code.
  • Identity/credential documents — only if you apply for Certified Professional verification, handled by a third-party identity-verification provider (see section 4) rather than stored by us directly.
  • Profile information you choose to add — display name, handle, bio.
  • Content you upload — videos, thumbnails, comments, votes, follows, and reports you file.
  • Basic technical data — IP address and similar request metadata, collected by our hosting and security providers as part of operating the Service (see section 4).

3. Why we process it and our legal basis

Under the EU General Data Protection Regulation (GDPR), we rely on the following legal bases:

  • Performance of a contract — creating your account, letting you publish and interact with content, sending you the emails or SMS codes needed to sign in or verify your account.
  • Legitimate interest — securing the Service against bots and abuse (captcha checks), moderating reported content, and improving reliability.
  • Consent — where required, e.g. if we ever add optional marketing communications (none exist today).
  • Legal obligation — where retention or disclosure is required by applicable law.

4. Who we share it with

We don't sell your data. We share the minimum necessary data with the following processors, each acting under their own data processing terms, to operate the Service:

  • Supabase — database, authentication, and file storage for the Service (posts, votes, comments, uploaded video/thumbnail files, account records).
  • Vercel — application hosting and content delivery.
  • Twilio — sends the SMS one-time codes used for Creator-level phone verification; receives your phone number for this purpose.
  • Resend — sends transactional emails (sign-in links); receives your email address for this purpose.
  • Cloudflare — domain/DNS management and bot-detection (Turnstile) shown on the sign-in page; may process your IP address and browser signals to distinguish human visitors from automated traffic.
  • A future identity-verification provider (e.g. Stripe Identity, Onfido, or Persona — not yet selected) — would process identity documents only for users applying for Certified Professional status, once that flow is built.

5. International data transfers

Some of the providers listed above may process data outside the European Economic Area. Where that happens, we rely on the safeguards those providers make available (such as Standard Contractual Clauses) to ensure your data remains protected to a standard equivalent to the GDPR.

6. Data retention

We keep your account data for as long as your account is active. If you delete your account, we delete or anonymize your personal data within a reasonable period, except where we're required to retain specific records (e.g. for legal or moderation-dispute purposes) for longer.

7. Your rights

If you're in the EU/EEA (or another jurisdiction with similar protections), you have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. To exercise any of these, contact us at [EMAIL DA DEFINIRE]. You also have the right to lodge a complaint with your local data protection authority (in Italy, the Garante per la protezione dei dati personali).

8. Cookies and similar technologies

We use the minimum cookies/local storage needed to keep you signed in (authentication session) and to run the Cloudflare Turnstile bot-detection challenge on the sign-in page. We don't currently use advertising or cross-site tracking cookies.

9. Children's privacy

The Service is not directed at, and accounts may not be created by, anyone under 16 years old. If we learn an account belongs to someone under this age, we'll take steps to delete it.

10. Security

We rely on our infrastructure providers' security measures (encryption in transit, access controls, row-level database permissions restricting who can read what data) and apply our own access restrictions on top. No system is perfectly secure, and we can't guarantee absolute security of information transmitted to the Service.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected in the "Last updated" date above and, where appropriate, communicated to registered users.