# Privacy note _Last updated 2026-09-10_ EthnoGrid is a small, invitation-only product. This note describes exactly what account and usage data it stores about you, why, and how you can get it back or have it removed. It is a factual description of what the running system does, not boilerplate. ## What is stored - **Account fields** — your email address, the display name you chose, which sign-in methods are set on your account (Google, an emailed sign-in link, a password), and when the account was created. - **Project content and version history** — every Project you own or are given access to: its pattern data, and every version saved to it, by you or a collaborator. Saved versions are never overwritten or deleted. - **Sign-in records** — each time you sign in, EthnoGrid records when, which method you used (Google, emailed link, or password), and your browser's user agent string (which browser and operating system you were using). **No IP address or location data is recorded — for sign-ins, or for anything else in the product.** - **Invitations** — if you invite someone to a Project, EthnoGrid stores the email address you invited, your account as the inviter, and the invitation's status until it is accepted, declined or revoked. - **Feedback reports** — if you send a bug report or review, EthnoGrid stores what you wrote, your account, and — unless you choose not to include one — a screenshot of the editor and a snapshot of the app's state (app version, browser, current theme, and details of the Project you were working on) as attachments on the report. ## What is not stored No IP address, device location, or advertising identifier is ever recorded, about anyone. Nothing about you is stored before your first sign-in. ## How long it is kept Account and Project data is kept for as long as your account exists. Sign-in records are kept for as long as the account they belong to exists in the database — deleting your account (below) does not remove them, so they remain on file but stop identifying you once your account has been anonymised. ## Exporting your data Account settings → Export downloads a JSON file containing every Project you own with its full version history, your Assets, and your account fields (display name, email address, creation date). Projects you only collaborate on, and anything belonging to other people, are never included. ## Deleting your account Account settings → Delete account replaces your display name with "Deleted user", clears your email address, password and Google sign-in link from the account, signs you out everywhere, and moves every Project you own to Trash. It also removes your access to other people's Projects and revokes any invitation still waiting on you. **This anonymises your account; it does not erase it.** Versions you authored in other people's projects remain in their history, attributed to your now-anonymised account — the database will not let a saved version be rewritten or removed, because doing so would destroy that other person's project history too. Once deleted, your account's email address is freed and can be invited again later, as a genuinely new account. ## Requesting removal Account settings → Export and Delete account, above, are self-service for the data they cover. For anything they do not reach — a sign-in record, an invitation you sent, or a feedback report — contact the person who operates this EthnoGrid instance directly. There is currently no separate self-service request form for those records.