Back to home

Privacy Policy

Last updated 12 July 2026

Overview

Corgi is a community-governed Bluesky feed. This Privacy Policy explains what data we collect, how we use it, and your rights. We collect the minimum necessary to operate the feed and respect community governance.

Corgi connects via Bluesky app passwords. We never receive your main Bluesky password, and you can revoke access at any time from your Bluesky settings.

Data we collect

When you sign in and participate in governance, we collect:

  • Your Bluesky DID and handle — used to identify your account and associate your vote.
  • Vote preferences — weight sliders, keyword preferences, topic preferences. These are stored per governance round and used solely to calculate aggregated community weights.
  • Research consent status — whether you have opted in, opted out, or not yet decided. Stored with a timestamp and version number.
  • Session information — a server-side session used to authenticate your requests. Expires when you sign out or revoke your app password.
  • Waitlist submissions — the Bluesky handle and optional note you provide when requesting pilot voting access. The request is retained after it is approved or rejected as part of the governance record; contact us to request its deletion.

We do not collect your Bluesky password, your post content, your social graph, or any off-platform behaviour.

How we use your data

  • Feed governance — your votes are aggregated (never exposed individually) to set feed ranking weights for each round.
  • Audit trail — operator actions (not participant votes) are logged in the public audit log, including the operator’s DID.
  • Research (opt-in only) — if you have consented, anonymised interaction data may be shared with academic research partners studying community-governed recommendation systems.

We do not sell, rent, or share your personal data with third parties for advertising or commercial purposes.

What is publicly visible

Corgi is built on a transparency principle. The following is always public:

  • The aggregated weights applied each round (not individual votes).
  • The operator audit log (operator DID, action type, timestamp — not vote data).
  • Per-post score breakdowns (the math behind why any Corgi-scored post ranked as it did).

Your individual vote is never public. Aggregate statistics (e.g. total vote count, participation rate) may be surfaced on the dashboard, but cannot be traced back to you.

Data retention

Governance votes are retained per round and archived when a round closes. We retain historical round data indefinitely to support the audit trail. You may request deletion of your participation data by contacting us.

Session data is deleted on sign-out or app password revocation.

Your rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your participation data and waitlist submission.
  • Withdraw research consent at any time (this does not affect your ability to vote).
  • Object to or restrict certain processing.

To exercise any of these rights, email hello@corgi.network.

Security

We use industry-standard practices to protect your data, including encrypted sessions and parameterised database queries. We do not store your Bluesky app password — only a server-side session token, which is revocable at any time.

If you discover a security issue, please disclose it responsibly to hello@corgi.network.

Changes to this policy

We may update this Privacy Policy. Material changes will be announced on the dashboard. The “Last updated” date at the top reflects the most recent version.

Continued use of the Service after a policy update constitutes acceptance of the revised policy. If we make a material change to how we handle research data, we will re-request your consent.