Privacy Policy – Lights & Colors
Ostatnia aktualizacja: 2025-08-18
Ostatnia aktualizacja: 2025-08-18
Last updated: 2025-08-18
Domain: lightsandcolors.art
• Contact: kunsttherapieblog@gmail.com
The data controller is the owner of the service Lights & Colors, available at
https://www.lightsandcolors.art
(hereinafter: “Service”).
For data protection matters, you can contact us at:
kunsttherapieblog@gmail.com.
This policy describes data processing related to the use of the Service (web application/blog) and user accounts.
Argon2
(we do not store plain-text passwords)Scope of permissions: email
and profile
(name and avatar).
For security and maintenance purposes, we may process: IP address (from X-Forwarded-*
headers), timestamps, request identifiers, basic error logs.
Any content added to the Service (e.g. posts, images, comments) is processed in order to provide the publishing and account management service.
email
and profile
We do not conduct behavioral marketing or profiling.
To prevent abuse (e.g. spam, hateful content, incitement to violence) and to maintain service quality, we use OpenAI API as a data processor.
We only transfer the minimum necessary data, mainly user-submitted content for moderation and technical metadata required for classification.
Details on OpenAI’s side: openai.com/policies
eu-north-1
(Stockholm, EEA)We do not sell data.
Data is stored in the EEA (Supabase eu-north-1
).
If exceptionally transferred outside the EEA, appropriate safeguards are applied (e.g. Standard Contractual Clauses).
helmet
): CSP, HSTS, X-Frame-Options, nosniffValidationPipe
)Authorization
header, no cookies)email
, profile
)X-Forwarded-*
)You have the right to: access, rectification, erasure (“right to be forgotten”), restriction, data portability, and objection.
We may refuse full erasure in case of abuse (Art. 17(3) GDPR) – in such cases we retain a minimal dataset (email, IP, logs).
Requests: kunsttherapieblog@gmail.com.
We use JWT tokens in the Authorization header (not in cookies).
The Service may only use necessary cookies (e.g. UI preferences).
No marketing cookies.
In case of suspected criminal activity (e.g. threats, hate speech, child exploitation, fraud), we may provide competent authorities with all available data, including IP addresses and logs – to the extent required by law.
You can revoke our app’s access at any time in your Google account settings (“Security” → “Third-party access”).
Revoking access will prevent Google login until you grant consent again.
This policy may be updated. The current version is always available at this address.
© Lights & Colors — Privacy Policy