Privacy Policy

Last updated: July 2026

1. Information We Collect

When you create an account on Kleia, we collect:

  • Email address — Used for authentication and account recovery.
  • Username — Your public display name on the platform.
  • Avatar — An optional profile picture you upload.
  • Account credentials — Your password, stored as a SHA-256 hash. We never store plaintext passwords.

When you use Kleia, we automatically collect:

  • Content you create — Posts, comments, chat messages, CTF submissions, and event responses.
  • Interaction data — Likes, conversation memberships, and attendance records.
  • Presence information — Your online/offline status and last active timestamp.

2. How We Use Your Information

We use your information to:

  • Provide and maintain the Kleia platform and its features.
  • Authenticate your identity and secure your account.
  • Display your content and profile to other users.
  • Show real-time presence and messaging features.
  • Track participation in CTF challenges and leaderboards.
  • Detect and prevent abuse, fraud, or policy violations.
  • Improve the platform through usage analysis.

3. Data Sharing

We do not sell your personal information to third parties.

We share data only with the following service providers necessary for platform operation:

  • Supabase — Database and authentication. Your profile, content, and messages are stored in Supabase.
  • Cloudinary — File hosting. Avatar images and uploaded files are stored on Cloudinary.
  • Vercel — Hosting and deployment infrastructure.

We may disclose your information if required by law or to protect the rights and safety of our users or the public.

4. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we delete your profile data and anonymize your content. Some data may be retained in backups for up to 30 days. Audit logs are retained for 90 days.

5. Your Rights

You have the right to:

  • Access — Request a copy of the data we hold about you.
  • Correction — Update or correct your profile information.
  • Deletion — Delete your account and associated data.
  • Objection — Object to the processing of your data for certain purposes.

To exercise any of these rights, contact the project maintainer.

6. Cookies

Kleia uses HTTP-only session cookies for authentication. These cookies are essential for the platform to function and do not track you across other websites. We do not use analytics cookies or third-party tracking cookies.

7. Children's Privacy

Kleia is not directed at individuals under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will delete it.

8. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page, and the "Last updated" date will be revised. Continued use of Kleia after changes constitutes acceptance of the updated policy.

9. Contact

If you have questions about this Privacy Policy, please contact the project maintainer through the GitHub repository.