Privacy Policy
Policy version:
InkSpire is a community learning platform. The organization operating this installation is responsible for its personal-data handling. This policy explains the current application; your community operator must also explain any additional local practices and applicable privacy requirements.
1. Why information is processed
Information is used to create and manage accounts, authenticate members, protect against misuse, provide posts, replies and appreciation reactions, moderate the community, and handle support or privacy requests. InkSpire has no payment, delivery, or marketing mailing service. The operator must identify the applicable legal basis for these activities and provide notice, or obtain separate consent where required, before using information for a new purpose.
2. Information handled
- Account details: required email address, display name and password. Passwords are stored as salted scrypt hashes, not plain text.
- Registration checks: a privately shared signup code and an arithmetic answer are submitted to control registration. The application keeps only the configured SHA-256 signup-code hash, not the submitted code. A temporary arithmetic challenge and its answer are stored in the database, linked to your anonymous session.
- Security details: encrypted authenticator setup secrets, two-factor enrollment status, hashes of unused recovery codes, verification failure counts, temporary lockout times and the last accepted authenticator time step.
- Community activity: post titles, text and topics; replies; appreciation reactions; authorship and creation times.
- Administration and sessions: account role, disabled status, content moderation status, account creation time, and session identifiers, sign-in phase, expiry times and form-security tokens.
- Technical and support information: IP addresses are used for short-lived, in-memory request rate limiting. Your operator's web server may log IP addresses, request paths, times and browser details. Information you provide to community support is handled under the operator's support procedures.
3. How information is collected
You provide details when registering, signing in, setting up two-factor authentication and participating in the community. Session and security records are created while you use the service. The application does not currently import information from partner organizations or collect offline event records.
Community administrators must determine age eligibility and arrange any required parent or legal-guardian authorization before onboarding children, including children under 14 where applicable. InkSpire does not collect birth dates, verify age or provide a guardian-consent workflow. If you are unsure whether you may join, ask your community operator before registering.
4. Visibility and sharing
This installation has one community, not separate private course groups. Other signed-in, two-factor-enrolled members can see your display name, visible posts and replies, and reaction totals. These discussions are not public web pages. Community administrators can see account emails and review hidden content; authorized server operators can access stored data for operation and support.
Do not post sensitive personal details or another person's private information. InkSpire does not include a feature to sell personal data or send it to advertising services. Your operator must disclose any hosting providers, other processors, legal disclosures or international transfers that apply to its deployment. Adding integrations requires a review of this notice and any required authorization.
5. Retention
Account and community records are retained until an authorized operator removes them under the operator's retention procedures. Disabling an account or hiding a post or reply is not deletion. There is no automated account or content retention schedule.
Signed-in sessions expire after 12 hours, anonymous sessions after one hour, and enrollment or sign-in challenges after 10 minutes. Expired database sessions are cleaned up every 15 minutes while the server runs. Used recovery codes are removed; signing out removes the current session, and password changes revoke other sessions.
Arithmetic registration challenges expire after five minutes. Registration submissions that pass form-security and origin checks and the request limit consume the session's challenge when checked, even if registration fails; requests rejected by those safeguards do not consume it. Refresh replaces the challenge. Storage is bounded to one challenge per session. Expiry stops use but does not immediately erase an unused challenge: it remains until replaced, consumed, or its session is deleted. Session deletion also deletes the challenge, including through the existing periodic expired-session cleanup while the server runs; otherwise an authorized operator must arrange cleanup.
The operator must establish and communicate retention periods for learning records, support requests, server logs and backups, including any legal or safeguarding holds. This application does not enforce the commercial transaction retention periods in policies for shopping services.
6. Deletion and disposal
Request deletion through the privacy contact below. There is no self-service account deletion in this version. Authorized operators must review the request, remove or anonymize data when appropriate, and explain any records that must be retained by law or organizational obligations. InkSpire does not automatically delete data within five days.
The operator is responsible for secure disposal of database records, exported files, backups and any paper records. Backup expiry and any retained copies must be addressed in its retention procedures; hiding content alone does not dispose of it.
7. Your rights and requests
Contact your community operator to request access to your information, correction, deletion, or restriction of processing, and to discuss withdrawal of consent where consent is the legal basis. Rights and any exceptions depend on applicable law. Guardians or authorized representatives may make requests where permitted, subject to appropriate identity and authority checks.
These requests are handled by authorized staff, not automatically by this application. Avoid sending passwords, signup codes, authenticator secrets or recovery codes with a request. Respect the privacy and rights of other community members.
8. Cookies and your choices
InkSpire uses one essential first-party session cookie: __Host-inkspire in production, or inkspire in development. It supports sign-in, two-factor verification and protection against forged form submissions. It is also created when visiting sign-in or registration pages before logging in. The Privacy Policy page itself does not create a session cookie.
The cookie lasts for the session durations described above. It is HTTP-only and SameSite=Lax; production deployments use Secure cookies over HTTPS. You may block or delete it in your browser's privacy or site-data settings, but account and community features will not work without it. InkSpire has no optional analytics or advertising cookies, so it does not offer a marketing-cookie consent banner.
9. Safeguards
The application uses password hashing, encrypted authenticator secrets, hashed recovery codes, mandatory two-factor authentication for community access, role-based administration, request limits, form-security checks and security headers. These measures reduce risk but do not guarantee absolute security.
The operator must configure HTTPS, restrict database and server access, protect encryption keys and backups, keep software updated, and establish staff training, incident response and physical access controls. Those operational safeguards are not automatically provided by the application.
10. Privacy contact and access requests
For privacy questions, complaints, access requests or other rights requests, contact: dr.jansen@chalkpost.com.
The community operator is responsible for verifying requests, responding under applicable deadlines and explaining its local retention and data-handling practices.
11. Complaints and policy changes
If a concern is not resolved by your operator, you may contact the privacy regulator or other responsible authority for your jurisdiction. Your operator can provide the relevant contact details and available complaint procedures.
Material changes to data use must be communicated by the operator before they take effect, with additional consent where required. The policy version above identifies this application notice. This page supports transparency; it is not a certification of legal compliance.