Privacy Policy
Last updated: 5 August 2026
This Privacy Policy explains what personal data The Veg Advocacy ("we", "us", "the site") collects when you use thevegadvocacy (the "Service"), why we collect it, who we share it with, and the choices and rights you have. We wrote it to reflect exactly what the site does — no vague boilerplate.
1. Who We Are
The Veg Advocacy is a website providing a free, community-supported guide of questions, answers, and sources for discussing and debating veganism. For the purposes of data protection law, The Veg Advocacy is the data controller responsible for the personal data described in this policy.
Contact details for data protection questions or requests are in Section 16.
2. Information We Collect
2.1 Information you provide directly
| When | What we collect |
|---|---|
| Creating an account | Email address, and password (if you sign up with email/password) or basic profile info from Google (if you sign in with Google — name, email, profile photo, as permitted by Google's own consent screen). |
| Editing your profile | Display name; your language preference; and, if you choose one, a profile picture — this is only a reference to one of a fixed set of predefined images we provide (like choosing an icon from a catalog), never a photo or file you upload (kept in sync across your devices once logged in). |
| Saving favorites | The list of questions you mark as favorites (linked to your account once you're logged in). |
| Suggesting a question or reporting a problem | The question, answer, explanation, and source text you submit, or the bug/content report you write, plus the page URL (for reports) and your display name (see Section 3 — this becomes public). |
| Suggesting a Bible verse | The book, chapter, verse(s), which side of the argument you think it supports, and any notes you add, plus your display name (see Section 3 — this becomes public, same as question suggestions). |
| Taking the Vegan Verification questionnaire | Your written answers, when you started and submitted, how many times you switched away from the tab, pasted text, or deleted text, how long you were inactive, your typing pace, your IP address and browser/device string, and the result of the captcha check — see Section 4 for full detail. This is not published publicly like Section 3 — only our moderators can see it. |
| Applying to become a moderator | Your written answers to the application questions, and when you submitted it — see Section 4. Only available once you hold the Vegan badge; simpler than the Vegan Verification questionnaire (no timer, captcha, or anti-cheat signals). Reviewed by admins only, never published publicly. |
| Buy Me a Coffee donations | We do not collect or process any payment or donation data ourselves — donations happen entirely on Buy Me a Coffee's own platform, under their own privacy policy and terms. |
2.2 Information collected automatically
- IP address, briefly, for spam prevention only: when you submit a suggestion, a problem report, or an admin login attempt, our server briefly records your IP address to enforce a rate limit (e.g. no more than 5 submissions per hour). Each record automatically expires after 15–60 minutes and is never linked to your account or used for any other purpose. We do not keep IP logs or history. (This is separate from the IP address recorded with a Vegan Verification submission, described in Section 4, which is kept for longer.)
- Aggregate page-view counts, not tied to you: when a small set of main pages (home, the debate guide, the school, flashcards, the vegan questionnaire, the moderator application, the staff contact form, articles) finishes loading, we increment a per-day, per-page counter — e.g. "the debate guide loaded 40 times today." This never records who loaded it, your IP address, or any per-visit/session detail, and is never linked to your account. Used only so we know which parts of the site are actually used.
- We do not use Google Analytics, advertising pixels, or any third-party tracking/analytics service. No behavioral tracking, no ad networks, no cross-site tracking, no cookies for this purpose.
3. Public Contributions: Please Read
If a submission is rejected, our reason for rejecting it is also posted publicly as a comment on that same Issue, and the same applies to an estimated implementation date if a suggestion is accepted. We use this public system deliberately, in the interest of transparency about how the site's content is curated — but it does mean you should think of anything you submit through these forms as public, not private, communication.
If you would prefer we not attribute a submission to your name, please contact us (Section 16) before submitting, or afterwards to request that a specific submission be edited or anonymized on GitHub.
4. Vegan Verification & Moderator Application
If you choose to take the optional questionnaire to earn a "Vegan" badge next to your name, we collect more than we do anywhere else on the site, specifically so a human moderator can judge whether the questionnaire was genuinely completed by you. This section explains exactly what that includes and why.
Unlike question suggestions and problem reports (Section 3), this data is never published or made public — it is stored in our private database and is visible only to site moderators reviewing your submission. There is no automated pass/fail: a person reads your answers and the signals above, and decides whether to grant the badge.
If your submission isn't approved, you can submit again after 24 hours. We keep past submissions (approved or not) linked to your account for as long as the account exists, so moderators have context if you try again; they are permanently deleted if you delete your account (Section 11).
Once you hold the Vegan badge, you can similarly apply to become a moderator from your account menu. This works the same way, but we collect less: only your written answers to the application questions and when you submitted them — no timer, captcha, or anti-cheat signals. Applications are reviewed by admins only (a smaller group than the moderators who review Vegan Verification), and accepting one grants the Mod role immediately. As with Vegan Verification, this data is never published publicly, and past applications are deleted if you delete your account.
5. How We Use Your Information
- To create and maintain your account, and let you sign in on any device.
- To save and sync your favorites and language preference across devices.
- To publish the questions, reports, and suggestions you choose to submit, and to notify site moderators by email that a new submission needs review.
- To keep you informed, inside your account, of the status of your own submissions (pending, accepted, rejected, implemented).
- To let a moderator review your Vegan Verification questionnaire, or an admin review your Moderator Application, and decide whether to grant the badge or role (Section 4).
- To prevent spam and abuse of our public submission forms.
- To operate, secure, and improve the Service generally.
We do not sell your personal data, and we do not use it for advertising or profiling.
6. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with similar requirements, we rely on the following legal bases:
- Contract: processing your account data (email, password/OAuth identity, profile, favorites) is necessary to provide the account features you request.
- Consent: submitting a question suggestion or problem report is entirely voluntary, and by submitting you consent to it being published publicly as described in Section 3. Taking the Vegan Verification questionnaire, and the fuller data collection that comes with it (Section 4), is likewise entirely optional and only happens if you choose to start it.
- Legitimate interest: briefly recording an IP address to rate-limit abusive/spam submissions, and sending moderators an email notification when new content needs review.
7. How We Share Your Information
We do not sell your personal data. We use a small number of third-party service providers ("processors") to run the site, each of whom only receives the data described below and is bound by its own privacy terms:
| Service | What it's used for | What it receives |
|---|---|---|
| Google Firebase (Authentication & Firestore database) | Account sign-in, and storing your profile, favorites, contribution history, Vegan Verification submissions, and Moderator Applications | Email, display name, password hash or Google OAuth identity, favorites, contributions history, and — only if you take the questionnaire or apply to moderate — the data described in Section 4 |
| GitHub | Publicly hosts our question/answer content and your submissions as Issues | The content of your suggestion/report, your display name or email, submission date (see Section 3 — this data is public) |
| Cloudflare | Hosting, content delivery, and short-lived rate-limit storage | Standard web request data, and a temporary IP-based counter (see Section 2.2) |
| Cloudflare Turnstile | Captcha check when submitting the Vegan Verification questionnaire, to help confirm a real person is submitting | Standard captcha-verification data (your IP address and browser data), under Cloudflare's own privacy policy |
| Resend | Sends an email notification to our moderators when a new suggestion/report arrives | The submission content, your display name, and a link to the GitHub Issue — sent to our moderator inbox only, not to any third party |
| Buy Me a Coffee | Optional, visitor-initiated donations widget | Nothing from us — if you choose to use it, you interact directly with buymeacoffee.com under their own privacy policy |
| Google Fonts | Loads the "Sora" typeface used across the site | Your IP address and browser data, directly from your browser to Google's font servers, under Google's own privacy policy |
We may also disclose information if required to do so by law, or to protect the rights, property, or safety of the site, our users, or the public.
8. Cookies & Local Storage
We do not set tracking cookies. The site uses your browser's local storage (not cookies) to remember, on your device only: your theme preference (light/dark) and your language choice, both of which work whether or not you're signed in; a local copy of your favorited questions, kept in sync with your account — note that you must be signed in to mark a question as a favorite in the first place, so this is only ever a local mirror of account data, never a way to use the feature anonymously; and, if you are a signed-in moderator or admin, a temporary admin session token. None of this is used to track you across other websites.
9. Data Retention
- Account data (profile, favorites, contribution history) is kept for as long as your account exists, and deleted when you delete your account (see Section 11).
- Vegan Verification and Moderator Application submissions are kept linked to your account for as long as it exists (see Section 4), and deleted when you delete your account.
- Rate-limit records (IP-based) automatically expire after 15–60 minutes.
- Public GitHub Issues created from your submissions are retained indefinitely as part of the project's public history, independent of your account (see Section 3).
10. Your Rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you;
- Correct inaccurate data (you can edit your display name and language yourself, at any time, from your profile);
- Delete your account and associated profile data (see Section 11);
- Export a copy of your data in a portable format;
- Object to or restrict certain processing;
- Withdraw consent at any time, where processing is based on consent;
- Lodge a complaint with your local data protection supervisory authority.
To exercise any of these rights, contact us using the details in Section 16. We will respond within the timeframe required by applicable law.
11. Deleting Your Account
You can permanently delete your account at any time from Edit Profile → Delete Account. This immediately and permanently removes your account profile, favorites, and contribution history from our database, and cannot be undone.
12. International Data Transfers
Our service providers (Google/Firebase, GitHub, Cloudflare, Resend) are based in, or operate infrastructure in, the United States and other countries outside the EEA/UK. Where required, these transfers are protected by appropriate safeguards such as Standard Contractual Clauses, as offered by each respective provider.
13. Security
We use industry-standard measures to protect your data, including encrypted connections (HTTPS) throughout the site, password hashing handled by Firebase Authentication, and signed, short-lived session tokens for administrative access. No method of transmission or storage is 100% secure, but we work to protect your information using commercially reasonable safeguards.
14. Children's Privacy
The Service is not directed at children, and we do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us so we can delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date at the top of this page when we do. Significant changes will be highlighted on the site.
16. Contact Us
If you have questions about this Privacy Policy, or want to exercise any of your rights, contact us at: info@thevegadvocacy.com
Governing jurisdiction for this policy: Portugal