Crowdwide / Privacy policy · Last updated September 2026

Your data deserves context.

This policy explains what Crowdwide collects, why it is needed, which outside services touch your data, and the choices available to you. Crowdwide is built to work across your devices, which means some information has to be stored so the service can function.

01

What we collect

Account details you provide (name, email, password hash, bio, links), content you create (posts, comments, communities, hashtags), media you upload (images, video, audio, avatars, banners), your social graph (who you follow, block, and which communities/groups you join), messages you send in direct messages and group chats, and limited technical information such as IP address, device/browser identifiers, and session activity used to keep accounts secure.

02

How we use it

We use this information to authenticate accounts, deliver verification and security emails, operate core features like feeds, search, notifications, and messaging, rank and personalize your "For you" feed, prevent abuse and spam, enforce our Terms and Community Guidelines, and improve the product over time. We do not sell your data, and we do not use it to serve third-party ads.

03

Where it is stored

Account data, posts, comments, communities, and messages are stored in MongoDB. Media (images, video, audio, avatars, and community banners) is stored in MongoDB GridFS - optionally distributed across multiple MongoDB clusters for extra capacity - or, on deployments configured to use it, in a Google Cloud Storage bucket served through a CDN URL. Your session is tracked server-side via connect-mongo so signing out or expiring a session invalidates it immediately.

04

Third-party services we use

Crowdwide relies on a small number of outside services to operate, and only sends them what each feature needs: Google (Gmail API or SMTP, via Nodemailer) to deliver verification, password-reset, login-alert, and security emails to your inbox; Google Cloud Storage, on deployments that enable it, to host uploaded media; GIPHY to power GIF search in chats and comments, when a deployment enables it - your search text is sent to GIPHY the way it would be on giphy.com; a self-hosted ClamAV virus scanner, on deployments that enable it, to scan uploaded files for malware before they are stored, entirely on infrastructure we control; and web push (VAPID) to deliver browser push notifications to devices where you have explicitly turned them on in Settings. We do not use third-party analytics or advertising trackers.

05

Link previews

When you post a link, Crowdwide's server fetches a small amount of publicly available metadata (title, description, preview image) from that page to build a preview card. This is a short, size-limited request made from our server, guarded against reaching private/internal addresses, and does not send it any of your account information.

06

Cookies and sessions

Crowdwide uses a single session cookie to keep you signed in, plus a CSRF token used to protect forms from cross-site attacks. Both are required for the app to function and are not used for cross-site advertising tracking. We do not use third-party tracking or marketing cookies.

07

Security measures

Passwords are hashed with bcrypt and never stored in plain text. Optional two-factor authentication (TOTP, with one-time recovery codes) adds a second layer to sign-in. Traffic is protected with security headers (Helmet), CSRF protection on forms, and rate limiting on sign-in, messaging, and API endpoints to slow down automated abuse. Critical server errors can trigger an internal alert email so problems are caught quickly - this alert never includes your password or message content.

08

Data sharing

We do not sell or rent your personal information. We only share it: with the service providers listed above, strictly to operate the features they support; with other members, to the extent your privacy settings and normal use of the product make it visible (e.g. a public profile, a post in a community you joined); or where we are legally required to disclose it, such as in response to a valid legal request.

09

Data retention

We keep your account data for as long as your account is active. Deleted posts, comments, and messages are removed from normal views immediately and are not recoverable through the product. When you delete your account (see "Your choices" below), your profile, content, and media are removed; some minimal records (such as security or moderation logs) may be retained briefly where needed to prevent abuse or meet legal obligations.

010

Your choices

You can edit or remove your profile details, links, and media at any time from Settings. You can download a copy of your data - profile, posts, and comments - from Settings → Account, and you can permanently delete your account and its content from the same page. You can revoke browser push notifications at any time from your browser or from Settings. For anything else, contact us at developerpuneet2010@gmail.com.

011

Children

Crowdwide is not directed at children under 13, and we do not knowingly collect information from children under 13. If we learn that we have collected information from a child under 13, we will delete it.

012

Changes to this policy

If this policy changes in a material way, we will update the date above and make a reasonable effort to let members know, such as through a notice in the product.