Legal / Privacy Policy
Privacy Policy
Last updated 2026-07-14
In plain words: we collect the minimum needed to run the service, your email, a hashed password, and the content you choose to add. There are no third-party trackers, no advertising, no analytics scripts, and we never sell data. Region-specific rights are set out in the notices for the EU & EEA, the UK, the US and Korea.
Who is responsible
The operator of 1BURO (contact: hello@1buro.app) is the data controller for the personal data described here, with one exception: where an artist runs a newsletter or stores their own contacts through 1BURO, the artist is the controller of that data and 1BURO processes it on their behalf.
What we collect
- Account data, your email address (your login), your display name, and your password, which is stored only as a salted hash, we cannot read it. If you enable two-factor authentication, the secret needed to verify your codes.
- Your content, the artworks, images, texts, records and notes you add. Some of it may be personal data (a CV is); it is processed only to provide the service, under your visibility settings.
- Technical data, standard server logs (IP address, time, requested page) and error logs, kept for security and debugging and routinely rotated.
- Newsletter subscribers, if an artist enables a newsletter, the addresses that subscribe to it. That list belongs to the artist; we store and process it for them.
What we deliberately don't do
No third-party analytics, no advertising or tracking pixels, no fingerprinting, no social-media embeds that phone home. Public pages load only from us. We do not sell personal data, we do not share it for advertising, and your content is never used to train AI models.
Cookies
First-party cookies only: a session cookie that keeps you logged in (essential), and a signed identity-hint cookie used solely so the optional "Let's be friends" button can work across 1BURO sites. No consent banner is needed because there is nothing to consent to, no tracking cookies exist.
Service providers
We use a small number of processors, each only for what the service needs:
- Render (cloud hosting, US), runs the servers and stores the data.
- Anthropic (AI, US), receives the text you submit only when you invoke an AI feature; API data is not used to train their models.
- Cloudflare (US), TLS certificates for custom domains, if you connect one.
- Backup storage you configure (e.g. Dropbox or a WebDAV server), only if the account owner sets up off-site backup, to the destination they choose.
- Mailing providers (e.g. Resend or Mailchimp), only if an artist connects one for their newsletter, to send that newsletter.
Some providers are outside your country; the regional notices describe the safeguards that apply to those transfers.
Retention and deletion
Your data is kept for as long as your account exists. You can export your complete account as a portable archive at any time. When you delete your account, your records, images and sessions are removed from the service; copies in routine backups age out on the backup cycle. Legal retention duties (e.g. accounting records for paid services), if any apply, are honoured and then the data is deleted.
Security
Traffic is encrypted in transit (TLS). Passwords are stored only as salted hashes. Sessions use httpOnly cookies. Newsletter provider keys are stored encrypted. Access to production systems is restricted to the operator.
Your rights
Wherever you are, you can ask us for access to your data, correction, deletion, or a portable copy, most of which you can do yourself in the app (export, edit, delete account). Write to hello@1buro.app and we will respond within a month. Your region may give you specific additional rights: see the EU & EEA, UK, US and Korea notices.
Children
The service is not directed at children and requires users to be at least 16.
Changes
If this policy changes materially, we will say so on this page (the date above always reflects the current version) and, for significant changes, notify you in the app or by email.