CC Editor Browse Sign in

Privacy Policy

Last updated: August 2026

1. Who We Are

CC Editor is operated by Stephen Turner, based in the United Kingdom. We are the data controller for personal data collected through this Service. You can contact us at [email protected].

2. Data We Collect

We collect the following personal data when you use the Service:

  • Account data: your email address, and a display name if you choose to set one
  • Authentication data: the six-digit sign-in codes we email you, stored only in hashed form and only until they expire, together with your session record
  • Content data: the convention cards and system notes you create through the Service
  • Feedback data: anything you send us through the feedback form, including the optional contact address, the page you were on, and your browser's user-agent string
  • Technical data: IP address (used for security and rate limiting), browser type

We do not ask for or store a password. Signing in works by emailing you a code, so there is no password to be lost or reused.

3. Your Convention Cards Are Public

This is the most important thing to understand about the Service.

Convention cards created on CC Editor are visible to everyone, including people who are not signed in, and may be viewed and copied by other users. Your display name is shown alongside the cards you create. Your email address is never shown to other users.

Please do not put anything private or sensitive in a convention card or in its system notes.

4. How We Use Your Data

We use your data to:

  • Provide and operate the Service
  • Sign you in and keep your account secure
  • Send you sign-in codes by email
  • Respond to feedback and bug reports you send us
  • Prevent abuse of the Service, such as automated sign-in attempts
  • Comply with legal obligations

We do not sell your personal data to third parties, and we do not use it for advertising.

5. Legal Bases for Processing

Under UK GDPR, we rely on the following legal bases:

  • Performance of a contract — to provide the Service you have signed up for
  • Legitimate interests — to keep the Service secure, prevent abuse, and improve it
  • Legal obligation — where we must retain or disclose data to comply with the law

6. Third-Party Services

We use the following third-party services, which may process your data:

  • Hetzner — server hosting (Germany, EU)
  • Resend — delivery of sign-in code emails
  • Cloudflare — DDoS protection and CDN

We do not use third-party analytics, advertising networks, or social sign-in providers.

7. International Data Transfers

Some of the providers above process data outside the United Kingdom and European Economic Area, in particular the United States (for example Cloudflare and Resend). Where data is transferred outside the UK/EEA, we rely on appropriate safeguards such as UK adequacy regulations, the UK extension to the EU–US Data Privacy Framework, or Standard Contractual Clauses.

8. Data Retention

We retain your personal data for as long as your account is active. Sign-in codes expire within minutes and are deleted. Sessions expire after 30 days.

If you ask us to delete your account, we remove your email address, display name, and your convention cards and notes within 30 days. Note that if another user has already copied one of your cards, their copy is their own content and remains theirs.

9. Your Rights (UK GDPR)

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data ("right to be forgotten")
  • Object to or restrict processing of your data
  • Data portability — you can also export any card as a PDF at any time

To make any of these requests, contact us at [email protected].

10. Complaints

If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk. We would appreciate the chance to address your concerns first, so please do contact us.

11. Children's Privacy

The Service is intended for users aged 13 and over and is not directed at younger children. If you believe a child under 13 has provided us with personal data, please contact us and we will delete it.

12. Cookies

We use one cookie, which keeps you signed in. We do not use advertising or tracking cookies, and we do not use analytics. On this basis no cookie consent banner is required.

13. Security

We take reasonable technical and organisational measures to protect your data, including encrypted connections (HTTPS), sign-in codes stored only as hashes, limits on how often codes can be requested or guessed, and access controls that allow only you to edit your own cards.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by a notice on the Service.

15. Contact

For any privacy-related questions or requests, contact us at [email protected].

© 2026 Bridge Forge

Privacy Terms

v1.5.0

HomeHelpAboutFeedback