Privacy
Last updated 2026-09-30.
This is what the service stores about you, why, and how you get it removed. The text describes the system as it is built.
Who is responsible
Aksel Edvardsen, private individual, aksel@anedvardsen.no. Write there for access, correction or deletion.
If you have a page
We store the email address you log in with, and what the login service needs to recognise you (Supabase Auth). Passwords are stored only as a hash. If you log in with Google or another provider, we get your email address and an id from them, not your password.
We store your profile document: all the text you write on the page, the theme, and which sections are shown. Every save sets the previous version aside, so you can undo once.
Images and video you upload are stored in a file store (Supabase Storage). The files get their own addresses that are not listed anywhere, but that work for anyone who has them, also while the page is a draft. To get an image gone for good, remove it from the page and delete the account with “delete everything”, or ask us to delete the file.
Large images are shrunk in your browser before they are sent. That also strips the hidden data in the file, such as where the picture was taken and with which camera. We never see it.
Drafts you write in the editor, the workshop and the forms are stored in your own browser, not with us.
If you write a few words about someone
We store what you write: the quote, your name, how you know each other, and an optional title and link. Alongside that we store the time, which page the words are for, and the language you chose. If you are logged in when you send, the words are linked to your account, so you can see them again under “Your words”. If you send without an account, no such link exists.
The owner of the page chooses whether the words are shown, but cannot change them. The only thing the owner can rewrite is the description of how you know each other, and then it says the owner wrote it.
You can withdraw the words at any time with the link you got when you sent them. They are then removed from the page and cannot be put back up. The row itself stays, marked as withdrawn, until the owner deletes it or their account.
To prevent mass submissions we store a hash of your network address (IP address) together with the current date for up to one day. The address itself is not stored, and the hash cannot be reversed.
If you give advice about a page
At the bottom of some pages there is a form for advice about the page. We store your name, the email address or link you gave, the advice, and the language the form was in. It goes only to the owner of the page, is never shown publicly, and is deleted when the owner deletes it or their account. Against mass submissions we use the same hash of the network address as for quotes, for up to one day.
Cookies and browser storage
Login uses cookies from Supabase that keep your session. Your language choice for the tools is kept in a cookie (btcv_ui) for one year. On logout a short-lived cookie is set that clears local drafts. Visitor analytics does not use cookies.
Drafts, writing fields and form text are stored in the browser's own storage (localStorage and sessionStorage). They are not sent to us, and are removed when you log out.
Visitor analytics and display variations
We use Vercel Web Analytics on the landing page and published profiles. It provides statistics on visitors, page views, referrers, countries and device types. The editor, login, submission forms, printouts and unpublished profiles are not counted. We do not send form contents, email addresses or account IDs to analytics. Query parameters and fragments are removed from page URLs before sending.
Visits are not counted when the browser sends Do Not Track or Global Privacy Control, or when you add ?analytics=off to the URL. Profiles with display variations draw a new appearance on each page load. This does not use a cookie or visitor ID. We do not currently measure contact clicks or results by variation.
Where it is stored, and who processes it
The database and files are hosted by Supabase in Ireland (AWS eu-west-1). The pages run on Vercel, which keeps ordinary server logs for a short period. The source code lives in a private repository at GitHub. Backups of the database and files are taken every night, encrypted before they leave the job, stored in a private repository at GitHub and deleted after 60 days.
How long, and how you delete
Everything is kept until you delete it. On the account page you can delete the account in two ways. “Delete the account, leave the content” removes the account and sets the page to draft; nobody can edit it any more. “Delete everything” also removes the page, the files and every word others have sent you.
Deletion starts immediately: the pages are hidden and locked. If an upload link is still valid, the deletion completes once it has expired, within a day of the deadline when the automatic job is set up, otherwise when you come back and press again. The account is removed from the login service as the last step.
Words you have written about other people stay on their pages, with your name as you wrote it. If you want them gone, withdraw them before deleting the account.
Backups are deleted on their own schedule, see above.
Your rights
You can ask to see what we hold about you, have it corrected, or have it deleted. Most of it you can do yourself on the account page. The rest you arrange by writing to the address at the top. If you believe we handle data wrongly, you can complain to the Norwegian Data Protection Authority (Datatilsynet).