Skip to content
PapaCoder Labs

Privacy Policy

Last updated: 2026-07-31

Who we are

PapaCoder Labs (“we”, “us”) operates this developer media site. We are based in New Zealand and design our practices around the Privacy Act 2020 (NZ). Where visitors in the EU/EEA or UK use the site, we also aim to meet the spirit of GDPR/UK GDPR for the limited data we process.

Privacy contact: support@papacoder.dev. See also Contact.

What we collect

  • Account / sign-in — If you sign in with GitHub (comments) or as an admin: name, email, avatar URL, and provider account IDs stored in our database.
  • Sessions — Session tokens needed to keep you signed in. Where our auth stack records them, we may also store IP address and browser user agent with the session.
  • Comments — The Markdown you post, tied to your user account. Hiding a comment (soft-delete) is not the same as erasing your account.
  • First-party reading metrics — Aggregate view counts and event metadata such as user agent, coarse device/country, and referrer. We do not store raw IP addresses on view events; IP may be hashed briefly only for rate limiting.
  • Optional Google Analytics — Only if we have enabled it and you accept analytics cookies. Google may process device/usage data under its own terms. See Cookies.
  • Newsletter email — Only if you subscribe when that feature is available (not required to read the site today).

Why we use it

  • Run and secure the site (hosting, auth, abuse prevention).
  • Show and moderate comments you choose to post.
  • Understand which posts are read (first-party views) so we can improve discovery.
  • Optional product analytics (Google Analytics) — only with your consent.
  • Respond to privacy or support requests you send us.

We do not sell personal information. We do not use your comment content to train third-party foundation models.

Legal bases (plain language)

  • Necessary to provide the service — account, session, and comment data when you sign in or participate.
  • Legitimate interests — first-party view metrics, security logging, and keeping the site reliable, balanced against your privacy.
  • Consent — optional Google Analytics cookies, which you can accept or reject.

Cookies

Essential cookies keep signed-in sessions working. Non-essential analytics cookies load only after you opt in. Details and controls: Cookies.

Who we share with

We use processors that help us run the product. They only get what they need to do that job:

  • Hosting and edge delivery (Vercel).
  • Managed PostgreSQL (Neon).
  • Object storage for images/OG assets (Cloudflare R2), when used.
  • GitHub, when you choose OAuth sign-in.
  • Google Analytics, only if enabled and you have accepted analytics cookies.

Some providers may process data outside New Zealand. We choose mainstream vendors with published security and privacy commitments for this stack.

How long we keep it

  • Sessions — until the session expires or you sign out.
  • Accounts — while your account is active; removed or anonymised after a verified deletion request (typically within 30 days of verification).
  • Comments — while the account exists; removed or anonymised with the account on a verified deletion request.
  • Analytics events — up to 24 months in identifiable/event form, then deleted or kept only as aggregates that cannot identify you.
  • Server / access logs — typically up to 90 days, unless needed longer for security investigation.

Your choices and deletion

You can request access to or deletion of personal data we hold about you by emailing support@papacoder.dev (subject: “Data deletion request”) or via Contact. We will verify the request (for example by confirming control of the email or GitHub account used) and complete verified requests. There is no self-serve account-delete button yet; email is the supported path.

Soft-deleted comments may remain hidden in our systems until a full deletion request is processed — ask explicitly if you want account-level erasure.

Children

The site is aimed at professional developers. We do not knowingly collect personal information from children under 16. If you believe we have, contact us and we will delete it.

Changes

We may update this policy as the product changes. The “Last updated” date at the top will change when we do. Continued use of the site after an update means you have had a chance to read the revised policy.