Privacy policy
Last updated 31 July 2026
We keep the least we can: a name, an email address, and what you chose to write. No advertising, no profiling, no third-party analytics, no cookie banner — because there is nothing to consent to beyond keeping you signed in.
Who is responsible
PoroTrainer is run by the association behind this site, which is the data controller for everything described here. Write to privacy@porotrainer.gg for anything on this page; we answer within a month, usually the same week.
What we hold, and why
Four things, and nothing else:
What we do not do
We do not profile you, sell or rent anything to anyone, run advertising, or load third-party analytics. Nothing you do here trains an advertising model. Reading, drilling and submitting a question work without an account at all, and we do not try to identify anonymous readers.
Cookies and local storage
One cookie, and only once you sign in: the session cookie that keeps you signed in. Your filter settings and drilling progress sit in your browser’s local storage and never reach us. Since we set no tracking or advertising cookies, there is no consent banner to click.
Who else touches your data
Only processors, bound by contract, and only for what they are there for:
Where your data lives
In the European Union. If that ever has to change, we will use the European Commission’s standard contractual clauses and say so here first.
How long we keep it
Your account, until you delete it — then it and your comments go within 30 days. Security records, 12 months. Email delivery logs, 90 days. Published questions and articles stay online because the community relies on them, but we will detach your name on request and credit them to a removed member.
Your rights
Under the GDPR you may ask for a copy of your data, correct it, have it erased, restrict or object to how we use it, take it elsewhere in a portable form, and withdraw any consent you gave. Most of it is a button on your account page: export, change, delete. Anything else, email privacy@porotrainer.gg. If we get it wrong you can complain to the CNIL (cnil.fr) or to the authority where you live.
Children
You need to be 15 or older to open an account, or to have a parent or guardian agree on your behalf. We do not knowingly keep accounts for younger players; tell us and we will remove one.
How we protect it
Passwords are hashed with argon2id and never stored or emailed in the clear. Everything travels over TLS. Two-factor authentication is available to every account and encouraged for editors and admins. Roles are least-privilege, admin actions are written to an append-only audit log, and the Brevo key is stored server-side and never sent back to a browser. If a breach ever affects you, we notify the CNIL within 72 hours and you directly without undue delay.
Changes
If we change anything that matters, we email everyone with an account before it takes effect, and the date at the top of this page changes.