PoroTrainer

Privacy policy

Last updated 31 July 2026

We keep the least we can: a name, an email address, and what you chose to write. No advertising, no profiling, no third-party analytics, no cookie banner — because there is nothing to consent to beyond keeping you signed in.

Who is responsible

PoroTrainer is run by the association behind this site, which is the data controller for everything described here. Write to privacy@porotrainer.gg for anything on this page; we answer within a month, usually the same week.

What we hold, and why

Four things, and nothing else:

Your account — display name, email address, and either a password hash or the identifier your Google or Discord account gives us. We need it to sign you in and to attribute what you write. Legal basis: performance of our agreement with you.
Security records — IP address, browser, and timestamps of sign-ins, failed attempts and password resets. Legal basis: our legitimate interest in keeping accounts from being taken over. Kept 12 months, then deleted.
What you post — questions, articles, comments and reports, with the name you chose. Published on the site by design.
Email preferences — which notifications you asked for. Legal basis: your consent, withdrawable at any time from your account page.

What we do not do

We do not profile you, sell or rent anything to anyone, run advertising, or load third-party analytics. Nothing you do here trains an advertising model. Reading, drilling and submitting a question work without an account at all, and we do not try to identify anonymous readers.

Cookies and local storage

One cookie, and only once you sign in: the session cookie that keeps you signed in. Your filter settings and drilling progress sit in your browser’s local storage and never reach us. Since we set no tracking or advertising cookies, there is no consent banner to click.

Who else touches your data

Only processors, bound by contract, and only for what they are there for:

Brevo (Sendinblue SAS, France) — sends verification, password-reset, invitation and notification emails. It receives your email address and the message. Data stays in the EU.
Our hosting provider (EU region) — stores the database and files.
The card-data service — receives card names only. No personal data ever goes to it.

Where your data lives

In the European Union. If that ever has to change, we will use the European Commission’s standard contractual clauses and say so here first.

How long we keep it

Your account, until you delete it — then it and your comments go within 30 days. Security records, 12 months. Email delivery logs, 90 days. Published questions and articles stay online because the community relies on them, but we will detach your name on request and credit them to a removed member.

Your rights

Under the GDPR you may ask for a copy of your data, correct it, have it erased, restrict or object to how we use it, take it elsewhere in a portable form, and withdraw any consent you gave. Most of it is a button on your account page: export, change, delete. Anything else, email privacy@porotrainer.gg. If we get it wrong you can complain to the CNIL (cnil.fr) or to the authority where you live.

Children

You need to be 15 or older to open an account, or to have a parent or guardian agree on your behalf. We do not knowingly keep accounts for younger players; tell us and we will remove one.

How we protect it

Passwords are hashed with argon2id and never stored or emailed in the clear. Everything travels over TLS. Two-factor authentication is available to every account and encouraged for editors and admins. Roles are least-privilege, admin actions are written to an append-only audit log, and the Brevo key is stored server-side and never sent back to a browser. If a breach ever affects you, we notify the CNIL within 72 hours and you directly without undue delay.

Changes

If we change anything that matters, we email everyone with an account before it takes effect, and the date at the top of this page changes.