Privacy Policy
Last updated: 4 August 2026
1. Who we are
PeopleOnly is a verified social media platform built around the principle that every contributor is a real, verified human being. This policy explains what personal data we collect, how we use it, and what rights you have over it.
Privacy questions and requests can be sent to [email protected].
2. Cookies and tracking
PeopleOnly uses no third-party tracking cookies.
Most websites place tracking scripts from Google, Facebook and advertising networks that follow you across the internet, building a profile of your behaviour on thousands of sites to target you with ads.
PeopleOnly does none of this.
The cookies we set are essential session cookies that keep you logged in, plus small first-party cookies (kept for up to a year, and only set if you choose to share this information) that remember a suburb, city, region, or country you've confirmed you're reading from as a guest, so we can show you more relevant local content. Your IP address is never stored. On your first anonymous visit, we use it for a single, immediate server-side lookup to guess your approximate location, then discard it; nothing is saved to a cookie unless and until you confirm that guess is correct (or set your location manually yourself), at which point it's your confirmed location, never your IP, that gets stored. None of these cookies are used for tracking, are sold, or are shared with any third party.
We never load Google Analytics, Facebook Pixel, or any other external tracking script on any page.
All usage data (which content you read, how long you spend reading, where you are in the world) is collected directly by PeopleOnly's own systems, stored in our own database, and never sold or shared with any third party.
Your reading behaviour on PeopleOnly stays on PeopleOnly.
3. What we store in your browser
Beyond essential session cookies, PeopleOnly stores a small amount of data in your browser to remember your preferences.
Stored only in your browser, never sent anywhere
- Your dismissed banners (so we don't show them again)
- Your last selected feed tab
Also sent to PeopleOnly, because it's needed to show you relevant local content
- Your confirmed location: a suburb, city, region, or country you've told us you're reading from as a guest. Stored in first-party cookies (kept for up to a year) and used to personalise the "Near me" feed and our content-view records, never used for cross-site tracking, never sold, and never shared with any third party.
- On your first anonymous visit, your IP address is used for a single, immediate server-side lookup to guess your approximate area. That guess is never itself stored in a cookie, and your IP address is never stored at all. The guess is shown as a suggestion the first time you see a "Near me" prompt; you can confirm it (which then stores your confirmed location, as above), replace it with a manual search, or ignore it entirely.
You can clear any of this at any time by clearing your browser's local storage, cookies, or site data.
4. No cookie consent banner
You may have noticed PeopleOnly does not show a cookie consent banner. This is intentional.
Cookie consent banners exist because of third-party tracking cookies that require your permission under POPIA and GDPR. Since PeopleOnly uses none of these (only essential session cookies and the optional first-party suburb preference cookie described above), no consent banner is required or appropriate.
We believe cookie banners have become meaningless theatre on most websites: a legal checkbox that users click through without reading, protecting nobody. Our approach is different: we simply don't use the tracking technologies that require consent in the first place.
5. What data we collect
Account and profile data
When you register, we collect your email address, display name, and the profile type you select: Verified Journalist or Verified Citizen. If you complete your profile, you may also provide a biography, avatar image, and type-specific information such as journalistic beat or publication history.
Identity verification data (KYC)
PeopleOnly requires identity verification for users who wish to publish content (posting, commenting, or adding a take). Reading full articles and reacting require only a verified email address, not identity verification. See section 8 for the full disclosure process this verification supports. We never store your identity documents. Identity verification is performed entirely by our third-party provider, Didit. Didit captures and holds your documents and biometric data. PeopleOnly receives only a verified token confirming you are a real person and, where applicable, a small set of confirmed metadata (for example, that you are over 18). Didit's privacy policy governs how Didit handles your data.
Content you publish
Articles, posts, videos, and any other content you create on the platform are stored on our servers and associated with your profile. A short preview of published content is visible to anyone, including unregistered visitors; reading the full text requires a free account with a verified email address.
Activity data
We store records of actions you take on the platform: reactions, comments, follows, subscriptions, bookmarks, and content you have viewed. This data is used to deliver the platform's features (for example, showing your reaction on a post) and to calculate depth scores and reading streaks where applicable.
Encrypted tip messages
If you send a message to a journalist's encrypted source inbox, that message is end-to-end encrypted on your device before it is transmitted. PeopleOnly's servers handle only ciphertext. We never see the plaintext contents of any tip message. We store the ciphertext and the nonce required for decryption by the journalist's private key. No metadata identifying the sender is stored.
Notifications
If you enable push notifications, we store your browser's push subscription endpoint and associated cryptographic keys in order to deliver notifications to your device.
Technical data
Standard server logs may capture your IP address, browser type, and request timestamps. These logs are used for security monitoring and are not linked to your profile for advertising purposes.
6. How we use your data
- To create and manage your account
- To deliver platform features: feeds, reactions, comments, notifications
- To process subscriptions and payments, once a payment provider is connected
- To send you platform notifications and, if you opt in, email updates
- To detect and prevent fraud, abuse, and violations of our terms
- To comply with legal obligations, including valid court orders
- To improve the platform based on aggregate, anonymised usage patterns
We do not sell your personal data to third parties. We do not use your data for behavioural advertising. Any advertising on PeopleOnly is targeted by content topic, never by individual user behaviour or profile. See section 7 for our policy on aggregated and de-identified data.
7. Who we share your data with
Didit (identity verification)
Didit performs KYC on our behalf. Didit holds your identity documents. PeopleOnly does not receive those documents. See Didit's privacy policy for details of their processing.
Payment provider
PeopleOnly does not currently have a live payment provider connected, so no payment data is processed or shared with anyone right now. Once a provider is connected, this section will name it and describe its processing of your payment card data and tax compliance — PeopleOnly will never store card numbers or payment credentials itself. See our Refund Policy for how billing, cancellation, and refunds will work once payments are live.
Cloudflare (CDN and media hosting)
Media files (including video hosted via Cloudflare Stream) are served through Cloudflare's network. Cloudflare may log request metadata (IP address, timestamp) in the course of normal CDN and DDoS protection operations. Cloudflare's privacy policy governs their processing.
Courts and legal authorities
PeopleOnly will disclose user identity information only when served with a valid court order from a court of competent jurisdiction in a recognised democratic country. See section 5 for the full disclosure process.
Aggregated and de-identified data (future use)
PeopleOnly does not currently share, license, or sell any aggregated or de-identified data. We are, however, reserving the right to do so in the future — for example, with research partners, industry organisations, or other third parties. This section describes a permission we may use later, not something happening today.
In this policy, "aggregated" datameans data that has been combined across many users into summary statistics or trends — for example, what share of readers in a region engaged with a topic — never any individual reader's own activity on its own. "De-identified" (or "anonymised") data means data that has had names, account identifiers, and any other identifying detail removed, such that it cannot reasonably be used, on its own or combined with other information, to identify a specific individual.
This is separate from, and does not change, our commitment never to sell your individual personal data — see the section immediately below and section 6 above. That commitment is absolute and covers any data that identifies you or could reasonably be used to identify you, whether directly (your name, email address, or account) or indirectly. Only data that has genuinely been aggregated and/or de-identified — such that it can no longer reasonably be traced back to you — could ever be shared, licensed, or sold under this section, and only if and when we actually begin doing so.
No one else, for your personal data
We do not share your personal data — data that identifies you or could reasonably be used to identify you — with advertisers, data brokers, analytics companies, or any other third parties beyond those listed above. The only exception is the possible future sharing of aggregated and/or de-identified data described immediately above, which by definition is not personal data.
8. Identity disclosure and the public ledger
If a court of competent jurisdiction in a recognised democratic country issues a valid order requiring us to disclose a user's identity, we will:
- Require that the order is cryptographically signed and reviewed by at least two designated keyholders within PeopleOnly before any disclosure proceeds.
- Contact the subject of the order where legally permitted to do so.
- Provide the requesting party with the minimum information required to satisfy the order. In most cases, this means passing the request to Didit, who holds the underlying identity documents.
- Log the disclosure immediately on our public immutable disclosure ledger, recording the date, jurisdiction, and legal order reference number. The identity of the subject is not shown on the public ledger, only that a disclosure occurred.
There is no silent surveillance. Every disclosure is public. PeopleOnly will never disclose identity information voluntarily, for commercial purposes, or without a valid court order.
9. Cookies
PeopleOnly uses a minimal number of cookies, all first-party:
- Session cookie: A secure, HttpOnly cookie that keeps you signed in. It contains a cryptographically signed session token, not your personal data.
- CSRF token: A security cookie that prevents cross-site request forgery attacks.
- Guest location preference (optional):If you're reading as a guest and choose to tell us your suburb or city (see section 2), we set a
guest_suburb/guest_citycookie so the feed can use it. You only get this cookie if you opt in, and it's never used for tracking.
We do not use tracking cookies, third-party advertising cookies, or analytics cookies.
10. Data retention
We retain your account data for as long as your account is active. If you delete your account, we remove your personal information (email address, display name, avatar, bio) within 30 days. Some records are retained for legal reasons:
- Disclosure log entries are immutable and permanent. They record that a disclosure occurred, not who the subject was.
- Transaction records are retained for 7 years for accounting and tax compliance.
- Voluntary retractions you submit are permanently linked to the original content for accountability reasons. If you delete your account, the retraction record is anonymised.
11. Your rights: GDPR and POPIA
You have the following rights over your personal data under the GDPR (if you are in the EU/EEA/UK) and POPIA (if you are in South Africa):
- Access: Request a copy of the data we hold about you.
- Rectification: Ask us to correct inaccurate data. Most profile data can be corrected directly in your account settings.
- Erasure (Right to be Forgotten): Request deletion of your personal data. Delete your account to initiate this process. Some data is retained as described in section 7.
- Portability: Request your data in a structured, machine-readable format (JSON).
- Objection: Object to processing of your data where we rely on legitimate interests as the legal basis.
- Restriction: Ask us to restrict processing while a complaint is being resolved.
- Complaint: If you are in South Africa, you may lodge a complaint with the Information Regulator (inforegulator.org.za). If you are in the EU/EEA/UK, you may lodge a complaint with your local data protection authority.
To exercise any of these rights, email [email protected]. We will respond within 30 days.
12. Security
We take security seriously. Our platform uses TLS encryption for all data in transit. Passwords are hashed using bcrypt and never stored in plaintext. The source protection inbox uses end-to-end encryption, so we cannot read those messages. An independent security audit is planned before public launch.
If you discover a security vulnerability, please report it responsibly to [email protected].
13. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and update the date at the top of this page. Continued use of PeopleOnly after a change constitutes acceptance of the revised policy.
14. Contact
For any privacy-related questions or requests: [email protected]