Skip to content
WALKERJACOB · privacy
privacy

Privacy Policy

Effective August 14, 2026. Contact: Jacob Walker (jacobwalker@walkerjacob.com). Covers walkerjacob.com, Hub (hub.walkerjacob.com), and related services that power them.

This policy explains what personal information is collected here, why it’s used, and your choices. This is a personal site with a members Hub (join by invite or approved request) — not a commercial product. There is no advertising, no sale of personal data, and no marketing mailing list.

1. Information we collect

Accounts (invite or approved request)

  • Username, email address, optional phone number, and password hash. Each phone number may be associated with only one account (normalized for uniqueness).
  • Optional profile data: display name, bio, links, avatar image, profile banner, profile background color
  • Preferences (theme, visibility defaults, notification toggles, DM opt-in)
  • Browser / device push subscriptions for Hub alerts (on by default; you can Disable per device in Account) — endpoint URL and encryption keys needed to deliver alerts; tied to your account and this device
  • Uploaded files (“drops”), media compositions, comments on media, quiet quality votes on those items, optional Standing (activity) preferences, direct messages, optional credits/collaborator relationships on content (who is credited, invite/accept state), and Hub edit jobs (titles, briefs, status, milestone timeline, correction notes with optional timecode, and which Hub members are on the crew)
  • Member reports (reason and optional details) and helper soft-moderation records (who hid or restricted what, and when) when you use or are subject to Hub moderation tools
  • Account review signals for abuse prevention (for example possible shared-IP / alt signup flags and unusual deletion patterns), reviewed by owners and helpers with moderation access — signup is still allowed when a signal is raised
  • A sign-in cookie so you stay logged in on Hub
  • Hashed IP address when using an invite link or submitting an access request
  • Soft email/phone verification status (confirm links or SMS codes when mail/SMS is configured). Unverified contacts do not block Hub use; email and phone stay private unless you opt in and verify them before they appear on your profile

Access requests

  • Name, email, optional preferred username and message
  • Hashed IP address and Cloudflare Turnstile verification result

Public comments (no account required)

  • Display name and comment body (required)
  • Optional email and website
  • Hashed IP address and user-agent for spam/abuse moderation

Optional comment email is used for moderation and spam control. It is not shown publicly and is not used for marketing.

2. How we use information

  • Operate accounts, authentication, and invite/approval flows
  • Host and share files and media you choose to upload or make available
  • Send transactional email (access decisions, signup invites, email verification, optional product notifications you enable, including credit/collaborator notices when you opt in)
  • Deliver in-app, browser, and device push notifications for Hub Alerts and messages (browser/device alerts are on by default; you can Disable per device in Account)
  • Send SMS verification codes when Twilio is configured and you add a phone number (without SMS config, phones may be saved but stay unverified)
  • Moderate abuse, spam, and security threats (including soft-hiding content, timed posting restricts for Hub members, and staff account disable when needed)
  • Triage member reports submitted from Hub
  • Maintain and improve the site

3. Cookies and similar technology

  • cerb_session — sign-in cookie on Hub (and the staff site, if you use it). Keeps you logged in; not set on this public site. Legacy name cerb_admin_session may still be accepted briefly.
  • Cloudflare Turnstile — bot protection on access request and signup forms

We do not use advertising cookies or third-party analytics SDKs. Because cookies in use are limited to essential operation and security, we do not show a non-essential cookie consent banner.

4. Processors and hosting

  • Public site hosting (e.g. Vercel)
  • Self-hosted Hub/backend (database and uploaded files on Jacob’s server)
  • Cloudflare (bot checks; optional network edge)
  • Transactional email via SMTP and/or Resend when configured
  • Optional Hub mailbox on Migadu (hub.walkerjacob.com) when your role includes mailbox access — message content for that address is stored at Migadu, not in Hub. Hub may create or rotate the mailbox through the mail host API. Browser webmail is Migadu’s; sign in with the mailbox password (shown once after create/rotate, not your Hub password). Desktop clients use IMAP/SMTP with that same mailbox password. Account → Mail shows the address and client settings.
  • Twilio (optional) for phone verification SMS when configured

These providers process data only as needed to deliver the service. We do not sell personal information.

5. Sharing

Content and profile details are visible according to the visibility settings you choose (private / unlisted / public, and profile visibility). Email and phone on your Hub profile are private by default and only shown when you opt in and verify them. Approved credits may appear on shared or public content. Share links you create can be used by anyone who has the link. We may disclose information if required by law or to protect the site, users, or others from serious harm or abuse.

6. Retention

  • Account data is kept while your account is active
  • If you delete your own account from Account settings, sign-in is disabled immediately and we retain your account data (including drops, media you created, DMs, and related records) for 30 days, then permanently delete it. During that window you may contact us to request restoration. Operator-initiated hard deletes (for abuse or operational reasons) may remove data sooner. Backups may persist for a limited operational period after purge.
  • Access requests are kept for review and abuse prevention
  • Public comments are kept until removed by moderation or site maintenance
  • Soft-hidden Hub media comments and library items remain stored so helpers/staff can restore them; they are not shown in normal browse
  • Role-gated Hub mailboxes live at Migadu. Hub does not create, disable, or delete them automatically. Message data is retained according to Migadu until the mailbox is removed there. Hub may keep a local record of the address for Account → Mail.
  • Member reports, moderation action logs, and account review signals are kept for abuse review and operations
  • Timed posting restricts expire automatically; the reason may remain in the action log

7. Your rights and choices

  • Update profile, email, phone, password, and notification preferences in Account settings
  • If your role includes a Hub mailbox, open webmail from Hub (Mail / Account → Open webmail) and sign in at Migadu with the mailbox password set in Migadu admin, or view the address and client settings under Account → Mail. Signing out of webmail does not sign you out of Hub. Mailbox mail bodies are stored at Migadu
  • Delete your own account from Account settings (password required); access ends immediately, with a 30-day retention window before permanent deletion as described in Retention
  • Request access, correction, or deletion by emailing jacobwalker@walkerjacob.com
  • Turn off optional notification emails in preferences
  • Turn off browser / device notifications in Account → Preferences (or in your OS / browser settings); that removes the push subscription for this device

If you are in a region with additional privacy rights (for example GDPR or CCPA), contact us and we will respond within a reasonable time. We do not sell or “share” personal information for cross-context behavioral advertising.

8. Children

Accounts and access requests are intended for people 13 years of age or older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided information, contact us and we will delete it.

9. Security

Passwords are stored hashed. Sessions use HttpOnly cookies. Access is gated (invite or approved request — no open signup). No method of transmission or storage is perfectly secure; use strong unique passwords and treat share links as sensitive.

10. Changes

We may update this policy. The effective date above will change when we do. Continued use of accounts after an update means you accept the revised policy. Material changes affecting accounts may also be noted in Hub or by email.

11. Contact

Privacy questions or requests: jacobwalker@walkerjacob.com. See also the Terms of Use.