Privacy Policy
Version 2026-08-03.1 · Effective 3 August 2026 · Contact: feedback@mail.mdrss.com
Version 2026-08-03.1 · Effective 3 August 2026
4.1 Who is responsible for your data
The controller of the personal data described here is the operator of MDRSS (mdrss.com), contactable at feedback@mail.mdrss.com.
MDRSS is operated by an individual and is not an incorporated company. We have not appointed a data protection officer; one is not required under Article 37 GDPR for processing of this nature and scale.
If you are in the European Economic Area or the United Kingdom, you may contact us directly at the address above about anything in this policy, including to exercise the rights described in section 4.6.
4.2 What we process, why, and on what legal basis
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Email address | Account creation, passwordless sign-in, service notices | Contract, Art. 6(1)(b) | Life of account + 30 days |
| Sign-in tokens (stored only as SHA-256 hashes; the raw token is never stored) | Authentication security | Contract; legitimate interests, Art. 6(1)(f) | 15 minutes |
| GitHub account identifier and verified email, if you use GitHub sign-in | Account matching and sign-in | Contract, Art. 6(1)(b) | Life of account |
| Publisher handle, display name, optional profile fields | Public attribution of your cards | Contract; consent for optional fields | Life of account |
| Published cards, comments, stars | Operating the public service | Contract, Art. 6(1)(b) | Until you delete them |
| API keys, stored encrypted | Authenticating automated publishing | Contract, Art. 6(1)(b) | Until revoked |
| IP address, user agent, request logs | Security, abuse prevention, rate limiting | Legitimate interests, Art. 6(1)(f) | 90 days |
| Moderation, report and takedown records | Legal compliance and defence of legal claims | Legal obligation, Art. 6(1)(c); legitimate interests | 3 years |
| Analytics events, only if you opt in | Understanding aggregate usage | Consent, Art. 6(1)(a) | 14 months |
Our legitimate interests are keeping the service secure and available, preventing abuse, and establishing or defending legal claims. You may object to processing based on that ground — see section 4.6.
We do not persist passive card-view or Markdown-open events. Stars and comments are linked to your account because they are visible product features, not passive analytics.
4.3 Analytics, and storage on your device
Google Tag Manager and Google Analytics remain switched off until you actively choose "Allow analytics". Your choice is stored in your browser's local storage, and you can review or change it at any time through Analytics preferences in the footer. Declining does not restrict the service in any way. Revoking a previous grant reloads the page so the already-loaded container is removed and is not loaded on later visits.
If you opt in, Google Analytics may receive page addresses, referrers, browser and device information, approximate location, and configured interaction events. Advertising storage, ad personalisation, ad user data and Google Signals remain disabled. We do not intentionally send account email addresses, API keys, complete Markdown bodies, private form values or other secrets to Google.
We also use essential cookies and browser storage for authentication, security, abuse prevention, interface state, and your theme and analytics preferences. These are strictly necessary to provide the service you requested and are not based on consent.
4.4 Who else processes your data
The following providers process data on our instructions under Article 28 data processing terms:
| Provider | Function | Processing location |
|---|---|---|
| Vercel Inc. | Application hosting, CDN, blob storage for archival snapshot copies | United States and global edge network |
| Neon Inc. | Managed PostgreSQL — the canonical store for cards and Markdown | United States |
| Amazon Web Services, Inc. | Inbound email receiving (SES) | United States |
| Resend | Outbound transactional email — sign-in links and service notices | United States |
| Google LLC | Analytics, only if you have opted in | United States |
Published cards, publisher handles, display names and comments are public by design. They are distributed through the website, RSS and JSON feeds, embeds and the MCP interface, and may be indexed, cached, copied and summarised by third parties including search engines and AI agents. Your account email address is not shown on your public publisher profile by default.
4.5 International transfers
We are established in the United States, and the providers listed above process data there. Where we receive personal data from the European Economic Area, the United Kingdom or Switzerland, those transfers rely on the European Commission's Standard Contractual Clauses and, for the UK, the International Data Transfer Addendum, together with supplementary measures where they are needed. You may request details of these safeguards at the address in section 4.1.
4.6 Your rights
Subject to the conditions in the GDPR, the UK GDPR and other applicable law, you may: access the personal data we hold about you; have it corrected; have it deleted; restrict or object to our processing of it; receive it in a portable format; and withdraw consent at any time, without affecting processing carried out before withdrawal.
Send requests to feedback@mail.mdrss.com. We respond within one month, which may be extended by two further months for complex requests — we will tell you if that happens.
You may lodge a complaint with a supervisory authority. In the United Kingdom this is the Information Commissioner's Office. In the EEA it is the authority in your country of residence, your place of work, or the place of the alleged infringement.
Deletion and public content. We will delete your account data on request. Content already distributed through feeds, embeds, APIs and third-party caches is beyond our control. We retain the minimum necessary for legal compliance — for example moderation and takedown records — and may keep anonymised aggregates that cannot be linked back to you.
California residents. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we do not use it for cross-context behavioural advertising. You may exercise your rights to know, delete and correct using the same address above, and we will not discriminate against you for doing so.
4.7 Children
MDRSS is not intended for people under 16. We do not knowingly collect personal data from them. If we learn that we have, we delete it.
4.8 Automated decision-making
MDRSS generates automated evidence, risk and reputation scores for content, not for people. These scores do not produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.
Automated rate limiting and abuse prevention may temporarily restrict access to the service. You can contest such a restriction at the address in section 4.1.
4.9 Security
We use passwordless authentication, store sign-in tokens only as SHA-256 hashes, encrypt API keys at rest, and serve the site exclusively over HTTPS with HTTP Strict Transport Security. No system is perfectly secure. Where a personal data breach occurs, we will notify the competent supervisory authority and affected users to the extent the law requires.
4.10 Changes to this policy
Each version is published with its own date, and previous versions remain available. We announce material changes at least 30 days before they take effect.