Privacy Policy

sharkey.inari-lost-shrine.net (hereinafter "this Instance") — Last updated: August 9, 2026

This Privacy Policy explains how personal data is processed when you use the microblogging service sharkey.inari-lost-shrine.net (hereinafter “this Instance”). This Instance is a non-commercial, single-user instance operated privately by an individual. It is based on the open-source software Sharkey (a fork of Misskey).

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, this policy describes your rights under the General Data Protection Regulation (GDPR). We process personal data only to the minimum extent necessary to operate a federated social network.

1. Controller (Responsible Party)

Operator: YomiPlush
Service: sharkey.inari-lost-shrine.net
Contact: [email protected]
Federated account: @[email protected]

For all questions relating to data protection, or to exercise your rights, please contact the address above. We aim to respond within 30 days.

2. Categories of Personal Data Processed

Registration on this Instance is currently disabled; accounts are created only by the administrator. Even so, the following data may be processed:

CategoryDescription
Account dataUsername, display name, password (stored only as an unreadable hash), email address (if provided), biography, avatar and banner images.
Content dataPosts (“notes”), reactions, replies, mentions, polls, and any files you upload (images, videos, audio).
Interaction dataFollows, blocks, mutes, lists, and other social graph data needed for the service to function.
Technical dataAccess tokens (stored only on your device), web-session identifiers, and the information technically required to deliver the service.
IP addressesNot stored by this Instance. IP-logging is disabled on the server. IP addresses may nevertheless pass through network infrastructure (see section 6) and may appear in transient network logs.

3. Purposes and Legal Bases of Processing

We process personal data only for the purposes described below. Under the GDPR, each purpose relies on one or more legal bases:

PurposeLegal basis (Art. 6 GDPR)
Providing the service: storing and displaying posts, files, profiles, and enabling the social graph.Performance of a contract (Art. 6(1)(b)) and, where no contract exists, legitimate interest in operating the service (Art. 6(1)(f)).
Federating content with other servers via the ActivityPub protocol.Legitimate interest (Art. 6(1)(f)); federation is the core functionality of the service. Where you explicitly enable federation features, consent (Art. 6(1)(a)) may also apply.
Security, abuse prevention, and responding to data-subject requests.Legitimate interest (Art. 6(1)(f)) in protecting the service and its users.
Backups to prevent data loss.Legitimate interest (Art. 6(1)(f)).

4. Recipients and Processors

Your data is shared only as necessary for the operation of the service:

We do not sell personal data, and we do not share data with advertisers or data brokers.

5. International Data Transfers

Federation and Cloudflare’s global network may involve transferring data to countries outside the EEA (including the United States and Japan). Cloudflare relies on adequacy decisions and/or the European Commission’s Standard Contractual Clauses for such transfers. Data sent to federated instances may be stored in countries whose data-protection laws differ from those in your country; by using a federated service you acknowledge this inherent property of the ActivityPub protocol.

6. Cookies, Local Storage, and Tracking

This Instance itself sets no tracking cookies and uses no advertising, analytics, or tracking pixels. Session state is kept in your browser’s local storage. Because the site is served through Cloudflare, Cloudflare may set its own cookies (such as __cf_bm or cf_clearance) for security and bot-mitigation purposes. See Cloudflare’s Privacy Policy for details.

7. Data Retention

DataRetention period
Account and profile dataUntil the account is deleted or this Instance is shut down.
Posts and uploaded filesUntil deleted by you, by the administrator, or until this Instance is shut down.
BackupsBackups are kept for a rolling period of approximately 7 days, after which older copies are deleted automatically.
Network/CDN logsPer the retention policies of the respective processors (e.g., Cloudflare).

Deletion from backups may take place no later than when those backups expire.

8. Your Rights under the GDPR

If you are located in the EEA, the UK, or Switzerland, you have the following rights, which you may exercise by contacting us (section 1):

There is no automated decision-making, including profiling, on this Instance.

9. Children

This Instance is not directed at children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, please contact us so that we can delete it.

10. Security

We apply reasonable technical and organisational measures appropriate to a personal, single-user instance, including encrypted (HTTPS) transport, hashed passwords, access controls, and automatic encrypted backups of the database and files.

11. Changes to This Policy

We may update this Privacy Policy from time to time. The current version is always available at this URL, and the “Last updated” date at the top will be revised accordingly. Material changes will be announced on the instance.

Controller contact for data-protection requests: [email protected]. Please allow up to 30 days for a response.

Effective: August 9, 2026