Your Privacy

Privacy Policy

We collect only what's necessary. We share nothing with advertisers. We respect your data and your rights.

1. What We Collect & Why

When you register an account: We collect your email address and chosen username. Your password is encrypted. We need this so you can log in and contribute to the platform.

When you submit comments or reports: We store the content you provide, along with your username and timestamp. This is essential for the platform to function as a community-driven spam database.

Automatically collected: Your IP address and browser timestamps are logged temporarily for security, rate limiting, and abuse prevention. These logs are automatically deleted after 90 days.

What we DO NOT collect: Real names, home addresses, phone numbers (unless voluntarily submitted as part of a spam report), payment information, browsing history, or any personal data beyond what you explicitly provide.

2. Content Moderation & Automated Filtering

All user-submitted content is automatically scanned for violations of our Terms of Service, including but not limited to:

  • Profanity, vulgar language, or obscene expressions
  • Harassment, threats, or personal attacks
  • Hate speech or discriminatory content
  • Personal Identifiable Information (PII)
  • Spam, duplicates, or automated submissions

Content that violates our standards may be automatically rejected, hidden, or deleted. You will be notified if your content is removed and may appeal the decision (see Section 6).

Legal basis: Legitimate interests (GDPR Article 6(1)(f)) - maintaining platform safety, preventing abuse, and enforcing our rules.

3. Data Retention & Deletion

Your account: You may request account deletion at any time by emailing support@whocalled.xyz. Upon deletion, your username and email are removed. Your past comments may remain anonymized to preserve community context.

Your comments/reports: These remain visible as part of the public spam database unless you request removal or they violate our policies.

Moderation records: Content removed for policy violations is kept for 30 days to process appeals, then permanently deleted.

IP logs: Automatically deleted after 90 days.

4. Data Sharing & Third Parties

We do NOT sell, rent, or trade your personal data to anyone. Not to advertisers. Not to marketers. Not to data brokers. Period.

Data is only shared when:

  • Required by Greek law or a valid court order
  • Necessary to investigate fraud, security threats, or platform abuse
  • You provide explicit consent

Operating from Greece. Our infrastructure is located entirely within Greece. All data processing complies with Greek law and EU GDPR regulations.

5. Your Rights (GDPR)

Because we operate from Greece, you have these rights under EU law:

  • Access: Ask what data we hold about you
  • Rectification: Correct inaccurate data
  • Erasure: Request deletion of your data
  • Restrict processing: Limit how we use your data
  • Data portability: Receive your data in a usable format
  • Object: Object to processing based on legitimate interests (including content moderation)
  • Lodge a complaint: File a complaint with the Hellenic Data Protection Authority

To exercise any of these rights, email support@whocalled.xyz. We respond within 30 days.

📢 Content Removed? You Can Appeal

If our automated moderation removed your comment or report and you believe this was a mistake, you have the right to a human review. Email support@whocalled.xyz with your username, the date of submission, and what was removed. We'll review and respond within 5 business days.

6. Cookies & Tracking

We use only essential session cookies to keep you logged in and protect against CSRF attacks. We do not use tracking cookies, analytics cookies, advertising cookies, or any cross-site tracking. Session cookies disappear when you close your browser.

7. Children Under 16

Our platform is not for children under 16. We do not knowingly collect data from anyone under 16. If we discover such data, we delete it immediately. Parents can report concerns to support@whocalled.xyz.

8. Security Measures

We protect your data with industry-standard security: encrypted database connections, password hashing (bcrypt), SQL injection prevention, XSS filtering, and regular security audits. While no system is 100% secure, we take reasonable measures to protect your information.

9. Policy Changes

If we make material changes to this Privacy Policy, we will notify you via platform announcement. Continued use after changes constitutes acceptance. This policy was last updated in January 2025.

GDPR Compliant - Updated May 2026