Privacy

Last updated: September 2026

The short version

This service runs on the AT Protocol, an open network. Some of what you do here becomes a public record in your own repository, which anyone on the network can read and copy. Everything else stays on our server and is never published. This page lists which is which.

Your identity

Signing up with an email address creates an AT Protocol identity for you on our own data server (pds.unconference.events): a permanent identifier (a DID) and a generated handle such as calmotter417.unconference.events. The handle is never derived from your email. Your DID and handle are public by design; that is how the network works.

We hold the password for that identity on your behalf, encrypted, so you never have to manage one. You can take full ownership at any time from Settings: we rotate the password, show it to you once, and stop holding it. You can export your whole repository whenever you like.

If you sign in with an existing AT Protocol account (for example Bluesky), the public records you create here are written into that account's repository and are permanently associated with it. We ask you to confirm this before your first public action.

Your email address is never published and is used only to sign you in and send the notifications you choose.

What becomes public (records on the network)

  • Session proposals you make, in your own repository: title, description, format, duration, topics and skills, and an optional public area you choose. Never an exact address.
  • Your confirmation when you accept an invitation to co-host a session, in your own repository.
  • Public endorsements, if you choose to make one. An endorsement is not a vote.
  • An RSVP, only if you choose to share it publicly for a session.
  • Your availability for a proposal, only if you choose to publish it.
  • A public listing of your role at a gathering (for example host), only if the gathering allows it and you opt in.
  • What gatherings publish in their own repository: the gathering itself, its policy, rooms, tracks, the published schedule, and vote tallies that show counts only, never who voted.

Public records are copied by relays and other services across the network. You can delete a record you wrote, and we remove it from our index, but copies made by others before deletion may persist.

What stays private (never published)

  • Votes. While a round is open, your allocation is visible only to you; nobody sees live counts, including organizers. When the round closes, your votes are separated from your identity and the key that could link them is destroyed. Only the anonymous totals remain, and totals below a gathering's minimum voter count are not shown at all.
  • Session feedback, which is anonymous and shown only as a summary once enough people have responded.
  • Membership and the roster, visible only to fellow members of the same gathering. You can hide yourself from the directory.
  • Tickets, payments and check-ins. Card payments are handled by Stripe; we never see card numbers.
  • Exact locations for self-hosted sessions, meeting links and chat groups, shown only to confirmed attendees, hosts and organizers.
  • Your profile details beyond your handle, display name and picture (bio, affiliation, interests), shown to members of gatherings you share. Telegram is shown only to fellow members. An ENS name is shown only if you verified it and chose to show it.
  • Notifications and your notification preferences.

Where data is stored and for how long

Private data is stored in a database on a server in Helsinki, Finland, operated for this instance. Public records live in repositories on our data server and on whatever servers the network copies them to. Transactional email is delivered through Resend.

  • Vote allocations are deleted when a round closes; only anonymous entries remain.
  • Notifications are deleted after 90 days.
  • Who invited whom is forgotten 30 days after an invitation is used.
  • Check-in times for past gatherings are reduced to counts after 90 days.
  • Sign-in links expire after 15 minutes; sessions expire after 30 days.

Cookies and tracking

We set one essential cookie that keeps you signed in. There are no analytics, advertising or tracking cookies, and no third-party trackers.

Your choices

You can edit your profile, change notification preferences, hide yourself from directories, delete records you published, and take ownership of your identity from Settings. To delete your account and the private data we hold about you, contact hello@unconference.events. Deleting your account does not remove copies of public records held elsewhere on the network.

Changes

If this policy changes materially, we will update this page and its date.