Privacy Policy

Information pursuant to Art. 13/14 GDPR (Regulation (EU) 2016/679) on the processing of personal data by the memstead.io package registry.

The registry is operated from Germany. This page describes what personal data memstead.io processes, why, on what legal basis, and for how long. The controller's identity and contact are in the imprint.

Controller

Björn Bösenberg, Finowstraße 17, 10247 Berlin, Germany — email hello@memstead.com (see the imprint). No separate data protection officer is appointed; none is required for processing at this scale (Art. 37 GDPR). Data-protection enquiries go to the email above.

What we process, why, and on what legal basis

| Data | When / why | Legal basis (Art. 6(1) GDPR) | Retention | |---|---|---|---| | GitHub login and numeric user ID | Resolved via the GitHub API when you authenticate to publish or moderate. The numeric ID is stored as the uploader of each mem you publish and as the actor on any moderation action. | (b) performance of the publishing service you request; (f) legitimate interest in attributing uploads and moderation. | Uploader ID: for the lifetime of the published mem (removed when you unpublish). Audit-log actor: see audit log below. Auth cache: transient (~60 s). | | IP address | Processed transiently to rate-limit requests (abuse prevention) and may appear in short-lived server logs. | (f) legitimate interest in service security, integrity, and abuse prevention. | Rate-limit state is in-memory and per short window; server logs are rotated and not retained long-term. IP addresses are not written to the registry database. | | Publisher-terms acceptance | Recorded once per publishing identity and versioned, as evidence that the current terms were accepted before a publish. | (b)/(c) record of the agreement required to use the publishing service. | Kept as the record of acceptance while the identity uses the registry. | | Audit log | Moderation and takedown actions (actor, action, affected scope/name, reason, timestamp) are written to an append-only log. | (f) legitimate interest in an accountable moderation record; (c) where retention supports legal compliance (e.g. DSA/TMG notice handling). | Retained as the moderation record; periodically reviewed and pruned when no longer necessary. |

We do not use tracking cookies, advertising, or third-party analytics on the registry.

Recipients and third parties

Your use of a GitHub token is governed by GitHub's own privacy policy; we receive only your login and numeric ID.

infrastructure (region europe-west4) that acts as a processor on our behalf under Art. 28 GDPR. Requests reaching the service traverse the hosting provider's edge.

Published mem archives and their metadata (including the uploader's GitHub login/ID) are public by the nature of a package registry — that is the purpose of publishing.

International transfers

The registry and its database are hosted in the EU. Authentication calls to the GitHub API may involve transfer to GitHub, Inc. (United States); such transfers rely on the recipient's applicable safeguards. No other transfer to a third country takes place.

Your rights

Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and to object to processing based on legitimate interest (Art. 21). To exercise any of these, contact hello@memstead.com. You also have the right to lodge a complaint with a supervisory authority — for Berlin, the Berliner Beauftragte für Datenschutz und Informationsfreiheit.

Note that erasing the uploader identity on a published mem is achieved by unpublishing it; moderation audit entries may be retained where a legitimate or legal interest requires it, balanced against your objection.


Publisher terms: see terms. Report illegal content: see the abuse / notice page. Provider details: see the imprint.