← Back to the site

Privacy Policy

Last updated: 5 August 2026

This Privacy Policy explains what personal data The Veg Advocacy ("we", "us", "the site") collects when you use thevegadvocacy (the "Service"), why we collect it, who we share it with, and the choices and rights you have. We wrote it to reflect exactly what the site does — no vague boilerplate.

1. Who We Are

The Veg Advocacy is a website providing a free, community-supported guide of questions, answers, and sources for discussing and debating veganism. For the purposes of data protection law, The Veg Advocacy is the data controller responsible for the personal data described in this policy.

Contact details for data protection questions or requests are in Section 16.

2. Information We Collect

2.1 Information you provide directly

WhenWhat we collect
Creating an accountEmail address, and password (if you sign up with email/password) or basic profile info from Google (if you sign in with Google — name, email, profile photo, as permitted by Google's own consent screen).
Editing your profileDisplay name; your language preference; and, if you choose one, a profile picture — this is only a reference to one of a fixed set of predefined images we provide (like choosing an icon from a catalog), never a photo or file you upload (kept in sync across your devices once logged in).
Saving favoritesThe list of questions you mark as favorites (linked to your account once you're logged in).
Suggesting a question or reporting a problemThe question, answer, explanation, and source text you submit, or the bug/content report you write, plus the page URL (for reports) and your display name (see Section 3 — this becomes public).
Suggesting a Bible verseThe book, chapter, verse(s), which side of the argument you think it supports, and any notes you add, plus your display name (see Section 3 — this becomes public, same as question suggestions).
Taking the Vegan Verification questionnaireYour written answers, when you started and submitted, how many times you switched away from the tab, pasted text, or deleted text, how long you were inactive, your typing pace, your IP address and browser/device string, and the result of the captcha check — see Section 4 for full detail. This is not published publicly like Section 3 — only our moderators can see it.
Applying to become a moderatorYour written answers to the application questions, and when you submitted it — see Section 4. Only available once you hold the Vegan badge; simpler than the Vegan Verification questionnaire (no timer, captcha, or anti-cheat signals). Reviewed by admins only, never published publicly.
Buy Me a Coffee donationsWe do not collect or process any payment or donation data ourselves — donations happen entirely on Buy Me a Coffee's own platform, under their own privacy policy and terms.

2.2 Information collected automatically

3. Public Contributions: Please Read

Important: when you suggest a question, suggest a Bible verse, or report a problem, it is published as a public "Issue" on our public GitHub repository — together with your display name (or your email address, if you haven't set a display name). This is publicly visible to anyone, including search engines, indefinitely, and is not automatically removed if you later delete your account (see Section 11).

If a submission is rejected, our reason for rejecting it is also posted publicly as a comment on that same Issue, and the same applies to an estimated implementation date if a suggestion is accepted. We use this public system deliberately, in the interest of transparency about how the site's content is curated — but it does mean you should think of anything you submit through these forms as public, not private, communication.

If you would prefer we not attribute a submission to your name, please contact us (Section 16) before submitting, or afterwards to request that a specific submission be edited or anonymized on GitHub.

4. Vegan Verification & Moderator Application

If you choose to take the optional questionnaire to earn a "Vegan" badge next to your name, we collect more than we do anywhere else on the site, specifically so a human moderator can judge whether the questionnaire was genuinely completed by you. This section explains exactly what that includes and why.

What we collect with your Vegan Verification submission: the text you typed for each answer; the timestamp you started and the timestamp you submitted (so we can see how long you took); how many times you switched away from the browser tab while answering; how many times you pasted text into an answer box; how many times you deleted text you had already typed (this is completely normal and not by itself treated as suspicious); how many seconds you spent inactive — not typing or selecting anything — while the timer was running; the resulting words-per-minute and total word count; your IP address at the moment of submission; your browser's user-agent string; and the outcome of a Cloudflare Turnstile captcha check.

Unlike question suggestions and problem reports (Section 3), this data is never published or made public — it is stored in our private database and is visible only to site moderators reviewing your submission. There is no automated pass/fail: a person reads your answers and the signals above, and decides whether to grant the badge.

If your submission isn't approved, you can submit again after 24 hours. We keep past submissions (approved or not) linked to your account for as long as the account exists, so moderators have context if you try again; they are permanently deleted if you delete your account (Section 11).

Once you hold the Vegan badge, you can similarly apply to become a moderator from your account menu. This works the same way, but we collect less: only your written answers to the application questions and when you submitted them — no timer, captcha, or anti-cheat signals. Applications are reviewed by admins only (a smaller group than the moderators who review Vegan Verification), and accepting one grants the Mod role immediately. As with Vegan Verification, this data is never published publicly, and past applications are deleted if you delete your account.

5. How We Use Your Information

We do not sell your personal data, and we do not use it for advertising or profiling.

7. How We Share Your Information

We do not sell your personal data. We use a small number of third-party service providers ("processors") to run the site, each of whom only receives the data described below and is bound by its own privacy terms:

ServiceWhat it's used forWhat it receives
Google Firebase (Authentication & Firestore database)Account sign-in, and storing your profile, favorites, contribution history, Vegan Verification submissions, and Moderator ApplicationsEmail, display name, password hash or Google OAuth identity, favorites, contributions history, and — only if you take the questionnaire or apply to moderate — the data described in Section 4
GitHubPublicly hosts our question/answer content and your submissions as IssuesThe content of your suggestion/report, your display name or email, submission date (see Section 3 — this data is public)
CloudflareHosting, content delivery, and short-lived rate-limit storageStandard web request data, and a temporary IP-based counter (see Section 2.2)
Cloudflare TurnstileCaptcha check when submitting the Vegan Verification questionnaire, to help confirm a real person is submittingStandard captcha-verification data (your IP address and browser data), under Cloudflare's own privacy policy
ResendSends an email notification to our moderators when a new suggestion/report arrivesThe submission content, your display name, and a link to the GitHub Issue — sent to our moderator inbox only, not to any third party
Buy Me a CoffeeOptional, visitor-initiated donations widgetNothing from us — if you choose to use it, you interact directly with buymeacoffee.com under their own privacy policy
Google FontsLoads the "Sora" typeface used across the siteYour IP address and browser data, directly from your browser to Google's font servers, under Google's own privacy policy

We may also disclose information if required to do so by law, or to protect the rights, property, or safety of the site, our users, or the public.

8. Cookies & Local Storage

We do not set tracking cookies. The site uses your browser's local storage (not cookies) to remember, on your device only: your theme preference (light/dark) and your language choice, both of which work whether or not you're signed in; a local copy of your favorited questions, kept in sync with your account — note that you must be signed in to mark a question as a favorite in the first place, so this is only ever a local mirror of account data, never a way to use the feature anonymously; and, if you are a signed-in moderator or admin, a temporary admin session token. None of this is used to track you across other websites.

9. Data Retention

10. Your Rights

Depending on where you live, you may have the right to:

To exercise any of these rights, contact us using the details in Section 16. We will respond within the timeframe required by applicable law.

11. Deleting Your Account

You can permanently delete your account at any time from Edit Profile → Delete Account. This immediately and permanently removes your account profile, favorites, and contribution history from our database, and cannot be undone.

Deleting your account does not remove any question suggestions, problem reports, or comments you previously submitted that were published as public GitHub Issues — those remain part of the public project history, as explained in Section 3. If you'd like a specific past submission removed or anonymized, contact us directly.

12. International Data Transfers

Our service providers (Google/Firebase, GitHub, Cloudflare, Resend) are based in, or operate infrastructure in, the United States and other countries outside the EEA/UK. Where required, these transfers are protected by appropriate safeguards such as Standard Contractual Clauses, as offered by each respective provider.

13. Security

We use industry-standard measures to protect your data, including encrypted connections (HTTPS) throughout the site, password hashing handled by Firebase Authentication, and signed, short-lived session tokens for administrative access. No method of transmission or storage is 100% secure, but we work to protect your information using commercially reasonable safeguards.

14. Children's Privacy

The Service is not directed at children, and we do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us so we can delete it.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will update the "Last updated" date at the top of this page when we do. Significant changes will be highlighted on the site.

16. Contact Us

If you have questions about this Privacy Policy, or want to exercise any of your rights, contact us at: info@thevegadvocacy.com

Governing jurisdiction for this policy: Portugal