Docht is operated by an individual based in Norway, who is the data controller for the personal data described here. Norwegian and EEA data-protection rules apply. Questions or requests about your data go to admin@docht.app.
1. What we collect
When you create an account we store your email, handle, password (hashed, never in plain text), and anything you choose to add to your profile — bio, avatar, banner. When you use Docht we store the posts, comments, reactions, saved Notebook entries, and messages you create, along with basic usage data (timestamps, view counts) needed to make the product work.
2. How we use it
Your data is used to operate Docht: showing your posts to people who follow you, powering search, computing your contribution score, sending you notifications, and letting you message other traders. We do not sell your personal data to third parties.
The legal bases for this are: performing our agreement with you (running your account and the features you use), our legitimate interest in keeping the product working and free of abuse (error monitoring, spam and fraud prevention), a legal obligation for records we are required to keep (payment and transaction records, once paid subscriptions exist), and your consent where you give it.
3. Who can see what
Posts, profiles, and comments you make public are visible to anyone. Direct messages are only visible to the people in that conversation. You can block or report another user at any time from their profile or a post.
4. Payment data
Docht is in Open Beta and takes no payments — paid creator subscriptions and payouts are not available yet, so no card or bank details are collected today.
When paid subscriptions open: if you subscribe to a creator or set up creator payouts, your payment details (card number, bank account) are collected and processed directly by Stripe, our payment provider — Docht never sees or stores your full card number. We store the record that a payment happened: amount, date, platform fee, and which creator/subscriber it belongs to, so subscriptions and creator payouts work and can be audited. See Terms for how subscriptions, Docht's fee, and Stripe fit together.
5. Error monitoring & session replay
Docht uses Sentry to catch and diagnose crashes/errors. When an error happens, Sentry receives technical data about that session — the error itself, browser/device info, and the sequence of pages/actions leading up to it. For a small sample of sessions (5%) and for every session where an error actually occurs, Sentry also records a lightweight visual replay of what happened on screen, to make bugs easier to diagnose than a stack trace alone. By default this replay masks all text content and blocks all media (images/video) before anything leaves your browser — we haven't changed that default. This processing is for keeping the product working (legitimate interest), not analytics or advertising.
6. Data storage, security & retention
Data is stored with Supabase (Postgres + object storage), protected by row-level security policies so you can only read or write data you're authorized to. Passwords are hashed by Supabase Auth; we never see or store them in plain text.
Your profile, posts, comments, Notebook entries, and messages are kept while your account is active and removed when you delete your account. Payment and transaction records (amount, date, platform fee, and which subscription they belong to — never a card number) are kept for as long as we are required to retain them for accounting and dispute-handling purposes, even after an account is deleted; once an account is gone, its link to those records is removed so they no longer identify a named person.
7. Your rights
You can edit or delete any post, comment, or Notebook entry you've created at any time, and you can permanently delete your account and associated data from Settings — this is irreversible.
You also have the right to ask for a copy of the personal data we hold about you, to have inaccurate data corrected, to receive your data in a portable form, and to object to or ask us to restrict certain processing. Where processing is based on your consent, you can withdraw it. To use any of these, email admin@docht.app. If you think we have handled your data wrongly, you can complain to the Norwegian Data Protection Authority (Datatilsynet), or to the supervisory authority in your own EU/EEA country.
8. Where your data is processed
Docht's database and file storage are provided by Supabase. Payments are processed by Stripe, and crash/error reports are processed by Sentry (whose intake for this project is in Germany). Using these providers can mean your data is processed on servers outside Norway, including within and outside the EU/EEA, under the safeguards those providers offer for such transfers.
9. Contact
Questions about this policy or your data — reach out at admin@docht.app.