# Privacy Policy for teal.town \ o / | / \ **Last updated January 9, 2026** See History: https://github.com/teal-fm/teal-town/commits/main/legal/privacypolicy.txt This Privacy Notice explains how teal computing LLC ("Teal", "we", or "us") collects and treats information through the teal.town ATProto Personal Data Server (PDS), our website teal.town, and the services we offer (collectively, our "Services"). This Privacy Notice is governed by and part of our Terms of Service. Any terms defined in the Terms of Service have the same meaning when used in this Privacy Notice. You consent to our privacy practices described in this Privacy Notice by accessing the Services or allowing us to process Personal Data following receipt of a notice from us that your Personal Data is included in our records. If you do not agree with this Privacy Notice, do not access or use our Services. ## PRIVACY SUMMARY Our Services provide Users with ATProto account hosting and related services. We offer this summary of our privacy practices to give you a quick overview of how we treat your data: **Your ATProto Data.** When you create an account on teal.town, your ATProto data (posts, media, profile information, etc.) is public by design and accessible to anyone via the ATProto protocol. This is a fundamental feature of the decentralized ATProto network. **Your Private Data.** Your private information, such as your email address and password, is kept confidential on our servers and is not shared with third parties or sold to advertisers. Your direct messages (DMs) are stored on Bluesky's servers; your ATProto account credentials provide access to those messages. **Teal as Controller.** When we process Personal Data for our own purposes (such as providing the Services to you), we do so as a data controller. This Privacy Notice primarily describes this type of processing. **Your Privacy Rights.** We welcome your requests to restrict our use or processing of your Personal Data as provided under your privacy rights (see Section 6). **Children's Privacy.** Our Services are not intended for children under 13. We do not knowingly collect Personal Data from children under 13, and we will delete that information if we learn we have collected it. If you believe we have received information from a child under 13 or other unauthorized information, please contact legal@teal.fm. **Updates.** We may update this Privacy Notice from time to time. All changes are effective immediately when posted and apply to all access to and use of our Services. Your continued use of our Services following the posting of changes constitutes your acceptance of such changes. If you have questions about this Privacy Notice or any of our Services, please contact us at legal@teal.fm. ## PERSONAL DATA As used in this Privacy Notice, "Personal Data" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. Personal Data falls within certain categories, for example: - Identifiers (e.g., name, email, username, handle); - Sensitive Personal Data (e.g., government identification number; precise geolocation; racial or ethnic origin; religious beliefs; health data; contents of messages when we are not the recipient); - Legally protected information (e.g., race, citizenship, marital status, sex); - Biometrics (e.g., DNA, face/voice prints, health data) and audio, electronic, visual, thermal, or olfactory information; - Commercial information (e.g., products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies); - Internet or other similar activity (e.g., browsing history; content interactions; server logs); and - Inferences drawn from Personal Data to create a profile about preferences, characteristics, trends, predispositions, behavior, attitudes, intelligence, and aptitudes. Not all information is protected as Personal Data under privacy laws. Information may not be covered by the privacy laws applicable to you if it is: (a) publicly available; (b) aggregated information, meaning data summaries or reports with the Personal Data removed; or (c) anonymized or de-identified. ## COLLECTION AND USE OF PERSONAL DATA We may collect Personal Data with your consent, with a legitimate interest, or as authorized or required by law. We only collect, use, retain, and disclose Personal Data as is adequate and relevant to the specific, express purposes described below or as reasonably necessary and proportionate to provide our Services or for other purposes that we disclose to you and are compatible with the context of how we collected your Personal Data. **Categories of Personal Data:** Over the last 12 months, we have collected identifiers, internet or similar activity, and public content created through the ATProto protocol. **Sources of Collection:** We collect Personal Data through our website, your account, and your use of our Services, as detailed below: **Your Account.** Users create an ATProto account to use the Services. We collect your email address, authentication credentials (password/encryption keys), and account preferences. By creating an account, you consent to us collecting and processing your Personal Data. We collect this information with your consent, and we use it to provide you with the Services you request, run analytics, and improve our Services. **Public ATProto Data.** When you create posts, upload media, or otherwise publish content through your teal.town account, this data becomes publicly accessible through the ATProto protocol via API endpoints. This includes your profile information, posts, likes, follows, blocks, and any media you share. This is a fundamental characteristic of the ATProto network and is necessary to provide you with decentralized social networking services. **Direct Messages.** Your direct messages (DMs) are stored on Bluesky's servers, not on teal.town servers. We provide the authentication mechanism that allows you to access those messages, but we do not store, process, or have access to the content of your DMs. **Usage Data and Server Logs.** We automatically collect technical data from your use of the Services, such as your IP address, access times, API requests, and server interaction logs. We use this information for operational purposes, including security monitoring, troubleshooting, and service improvement. **Technical Data and Cookie Use.** We automatically collect technical data from your use of the website, such as your browser type, operating system, device details, and pages visited. We use essential cookies and related technology to collect and process this data, including: - Authentication cookies for user identification - Session cookies for maintaining your logged-in state We do not use any non-essential cookies or tracking technologies. We will not collect additional categories of Personal Data or use already collected Personal Data for purposes that are materially different, unrelated, or not reasonably necessary or compatible with the original purpose without notice and consent to you as required by law. We might also use your Personal Data to: - Monitor your compliance with any of your agreements with us - Protect your privacy and enforce this Privacy Notice - If we believe it is necessary, to identify, contact, or bring legal action against persons or entities who may be causing injury to you, to us, or to others - Comply with a law, regulation, legal process, or court order - Fulfill any other purpose to which you consent ## DATA DISCLOSURES We will only disclose Personal Data to third parties as described in this section, with permission, or as required by law. In the preceding 12 months, we have disclosed Personal Data for business purposes to the following recipients: **Public ATProto Network.** By design, your ATProto data (posts, profile, media, follows, etc.) is publicly accessible to anyone via the ATProto protocol and API endpoints. This data is federated across the ATProto network and may be accessed by other PDS providers, applications, and services that interact with the ATProto protocol. **Backup Services.** We perform nightly backups of our servers, including your account data, to ensure data integrity and recovery capabilities. These backups may be stored with third-party backup service providers who are subject to contractual agreements that protect your Personal Data. **Service Providers.** Our third-party service providers (e.g., hosting providers, data backup services, security vendors) may have access to your Personal Data to perform their contractual obligations to us. The type of information that we disclose to a service provider will depend on the service that they provide to us. Our service providers are subject to contractual agreements that protect your Personal Data, and we require all service providers to maintain confidentiality standards and organizational measures to ensure the security of your Personal Data. Our service providers are prohibited from selling or disclosing the Personal Data we provide. **Affiliates.** We may disclose the information we collect from you to our affiliates or subsidiaries following applicable privacy laws. **Other Third Parties, as permitted by applicable law.** For example: if we go through a business transition (e.g., merger, acquisition, or sale of a portion of our assets); to comply with a legal requirement or a court order; when we believe it is appropriate to take action regarding illegal activities or prevent fraud or harm to any person; to exercise or defend our legal claims; or for any other reason with your consent. **Law Enforcement, and other governmental agencies,** at our sole discretion only in connection with an investigation of any matter that is illegal or that could expose us or our affiliates or subsidiaries to liability. We reserve the right to disclose aggregated, anonymized, or de-identified information about any individuals with non-affiliated entities for research, product development, marketing, or other purposes, without restriction. ## DATA RETENTION The data we collect and process is retained as an essential asset to our provision of Services as long as it serves a legitimate interest. If we learn that any data is inaccurate or stored or used unlawfully, we will correct or delete that data as required by law and our company policies. **Active Accounts.** Personal Data associated with your account is retained while that account remains active on teal.town. **Inactive or Migrated Accounts.** If your account becomes deactivated or you migrate your account to another PDS, your data may be deleted after 30 days if server resources are needed. If you wish to ensure deletion of your data, please delete your account when you migrate to another PDS or decide to no longer use the service. **Server Logs.** We retain server logs and usage data for operational and security purposes for up to 24 months. **Backups.** Backup data is retained according to our backup retention policies, which may extend beyond the active retention period for your account data. We reserve the right to retain data, including Personal Data, for longer periods if it is critical to our business operations, legal compliance, or dispute resolution, and we securely store that retained data. We regularly review and delete or deidentify unnecessary data. ## YOUR PRIVACY CONTROLS We provide the following methods to directly control how we collect and use your Personal Data, including but not limited to: **Your Account.** You can access, correct, or update the Personal Data associated with your account at any time through the Services or by contacting us at legal@teal.fm. **Account Migration.** You have the right to migrate your ATProto account to another PDS provider at any time. This is a core feature of the ATProto protocol that ensures your data portability and freedom of choice. **Account Deletion.** You may delete your account at any time. Upon deletion, we will remove your private data from our active servers. Please note that your public ATProto data may persist on other servers in the ATProto network, as it has been federated according to the protocol design. **Emails.** If you inquire about our Services, we may use your contact information to send you service-related or marketing emails in compliance with applicable law. You can opt-out of receiving marketing communications at any time by clicking the "Unsubscribe" button contained in any email or by sending a request to legal@teal.fm. **Device Settings.** You can control the data we collect through automated means by adjusting your device settings, such as blocking cookies or installing a third-party plugin to control how cookies interact with your device. If you block essential cookies, the Services may not function. **Do Not Track.** Do Not Track signals are signals sent through a browser informing us that you do not want to be tracked. Currently, our systems do not recognize browser "do-not-track" requests. You may, however, disable certain tracking as discussed above. **Submit a Privacy Request.** To exercise your privacy rights, express concerns, lodge a complaint, or request information, please contact us at legal@teal.fm. We can only fulfill a Privacy Request where we are the controller of the Personal Data and when we have sufficient information to verify that the requester is the person or an authorized representative of the person about whom we have collected Personal Data, and to properly understand, evaluate, and respond to the request. We do not charge a fee to process or respond to a request unless we have legal grounds to do so. We endeavor to respond to Privacy Requests following the requirements of the law applicable to your jurisdiction. We will fulfill privacy requests as required by applicable law. If you disagree with our decision regarding fulfillment of your request, you can submit an appeal to legal@teal.fm. ## NOTICE OF PRIVACY RIGHTS ### United States Consumer Privacy Rights In the United States, consumer privacy is governed by federal privacy laws covering specific industries or data uses and state privacy laws providing general consumer privacy rights. This section provides a notice of privacy rights under the privacy laws of U.S. states that provide consumer privacy protections. Residents of states offering privacy protections (each a "Consumer") may have some or all the following rights over their Personal Data: **Right to Correct.** If you become aware that the Personal Data that we hold about you is incorrect, or if your information changes, please inform us and we will update our records. **Right to Deletion.** You may request that we delete the Personal Data that we collected and retained, with certain exceptions. We may permanently delete, deidentify, or aggregate Personal Data in response to a request for deletion. Please note that public ATProto data may persist on other servers in the federated network. **Right to Access.** You may request confirmation that we have collected Personal Data about you and that we provide you with access to that Personal Data. If you submit an access request, we will provide you with copies of the requested pieces of Personal Data in a portable and readily usable format. Please note that we may be prohibited by law from disclosing certain pieces of Personal Data, and we may be limited in the number or frequency of requests we must fulfill. **Right to Disclosure.** You may have the right to request that we disclose information to you about our collection and use of your Personal Data, such as: (i) the categories of Personal Data we have collected about you; (ii) the categories of sources for the Personal Data we have collected about you; (iii) our business purpose for collecting, using, processing, sharing or selling that Personal Data, as applicable; (iv) the categories of third parties with whom we share that Personal Data; and (v) if we sold or shared your Personal Data under applicable law, two separate lists stating: (y) sales or sharing, identifying the Personal Data categories that each category of recipient purchased; and (z) disclosures for a business purpose, identifying the Personal Data categories that each category of recipient obtained. Certain laws may limit the number or frequency of requests we must fulfill. **Limited Use and Disclosure of Sensitive Personal Data.** You may have the right to opt out or limit our use of your sensitive Personal Data. Please note that we do not purposely collect Personal Data that qualifies as "sensitive" under privacy laws and in no case would we disclose sensitive Personal Data for the purpose of inferring characteristics about you. **Selling or Sharing Personal Data.** Some states entitle consumers to opt out of the sale or sharing of Personal Data or targeted advertising practices. We do not sell your Personal Data or share your Personal Data with third parties for cross-contextual behavioral advertising purposes. **Right to Nondiscrimination.** We will not discriminate against you for exercising your privacy rights. For example, unless permitted by law we will not: (i) deny you goods or services; (ii) charge you different prices or rates for goods or services; (iii) provide you a different level or quality of goods or services; (iv) retaliate against you as an employee, applicant for employment, or independent contractor for exercising your privacy rights; or (v) suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services, because you exercised a right under applicable privacy laws. **Health Data Rights.** Some state laws entitle consumers to certain details about health data collected about them. We do not intend to collect any health data. **Right to Disclosure of Marketing Information.** California's Shine the Light Act (Civil Code sections 1798.83-1798.84) entitles California residents to request certain disclosures regarding Personal Data sharing with affiliates and/or third parties for marketing purposes. Consumers may exercise these rights by submitting a verifiable privacy request to legal@teal.fm. We will respond within the legally required timeline to the extent the applicable law applies to you and our business activities. If your Privacy Request is not addressed in a timely manner, you can appeal it by contacting legal@teal.fm. ### Canadian Privacy Rights This notice of Canadian Privacy Rights relates to Canada's Personal Data Protection and Electronic Documents Act ("PIPEDA"). This section applies solely to residents of Canada where PIPEDA applies. PIPEDA grants specific rights regarding Personal Data offering details on an identifiable person without the inclusion of name, title, telephone number, and business address of an employee of a business or organization. The following paragraphs describe PIPEDA rights and explain how to exercise those rights. **Right to know why we collect, use, and distribute the Personal Data we process.** We have set the required notices in this Privacy Notice. We may provide you with additional notices about other ways we process your Personal Data, such as by sending you a notice via email or by other means of communication. **Right to expect us to collect, use, or disclose Personal Data responsibly and not for any other purpose other than which you consented.** We set your expectations in this Privacy Notice and collect express or implied consent at various stages of collection or processing. If we collect or use your Personal Data based on your consent, we will also notify you of any changes and will request your further consent as needed. You may withdraw your consent at any time with reasonable notice by contacting us at legal@teal.fm. **Right to accuracy of your Personal Data.** Please notify us if your Personal Data on our systems is not current, complete, and accurate. We will reasonably assist you to ensure that your Personal Data is accurate in our systems and with our service providers. **Right to access your Personal Data.** Upon written request and identity authentication, we will provide you with copies of your Personal Data under our control, information about the ways in which that information is being used and a description of the individuals and organizations to whom that information has been disclosed. Some Personal Data may be unavailable if we are limited by law or determine there is a potential for infringement on another's privacy rights. If we must refuse an access request, we will notify you in writing, document the reasons for refusal, and outline further steps that are available to you. ### European and United Kingdom Privacy Rights We adopted this section to comply with the General Data Protection Regulations ("GDPR") and its counterpart regulation applicable to residents of the United Kingdom. This section applies solely to residents of the European Economic Area and the United Kingdom. If you are subject to GDPR protections, you have the following privacy rights: **Right to know how we process your Personal Data.** We have set the required notices in this Privacy Notice, and we may provide you with additional notices about other ways we process your Personal Data. **Right to rectify your Personal Data.** Please notify us if you become aware that the Personal Data that we hold about you is incorrect or if your information changes and we will update our records. **Right to restrict processing of your Personal Data.** You can request that we restrict the processing of your Personal Data if: (i) the data is inaccurate; (ii) the processing is unlawful; (iii) we no longer need the Personal Data; or (iv) you exercise your right to object. **Right to access your Personal Data.** You can request to access your Personal Data. Upon request, we will provide you with a copy of your Personal Data, along with details about the types of Personal Data we process, why we process it, and any third parties we work with to collect Personal Data on our behalf. We may have one or more legally valid reasons to refuse your request in whole or in part, for example, to protect the rights of other individuals. **Right to erasure (a.k.a. the "right to be forgotten").** Upon request, we will delete your Personal Data under certain circumstances and where required by law. This right is not absolute, and we may be entitled to retain and process your Personal Data despite your request. If you make this request, we balance certain legal, contractual, and business interests against your right to request the deletion of your Personal Data. Please note that public ATProto data may persist on other servers in the federated network. **Right to data portability.** In some circumstances, we are required to provide your Personal Data to another organization at your request and in a structured, commonly used machine-readable format, so that the other organization can read and use it. The ATProto protocol provides native support for account migration and data portability. **Right to object to certain processing of your Personal Data.** Upon your request, and in certain circumstances and where we are required to do so by law, we will limit our processing of your Personal Data as you request. **Right to not be subject to Automated Decision-Making ("ADM").** We do not use ADM in a manner that produces legal effects concerning or significantly affecting any individual. If you are subject to GDPR protections and you believe we are unlawfully processing your Personal Data, you have the right to complain to your local data protection supervisory authority. If you are a resident in Switzerland, you have the right to complain to the Swiss data protection authorities. ### Supplemental Notices In addition to the above notices of privacy rights and details about our privacy practices described in this Privacy Notice, we provide the following supplemental notices of privacy practices for the jurisdictions listed below: **France.** In addition to the European Union Privacy Rights listed above, you have the right to provide us with general or specific instructions for the retention, deletion, and communication of your Personal Data after your death. The specific instructions are only valid for the processing activities mentioned therein and the processing of these instructions is subject to your specific consent. You may amend or revoke your instructions at any time. You may designate a person responsible for the implementation of your instructions. This person will be informed of your instructions in the event of your death and be entitled to request their implementation from us. In the absence of designation or, unless otherwise provided for, in the event of the death of the designated person, their heirs will have the right to be informed of your instructions and to request their implementation from us. To issue instructions, contact legal@teal.fm. **Mexico.** This Personal Notice is available in Spanish upon request. In case of dispute, the Spanish version of this Personal Notice shall prevail. The type of Personal Data we use, purpose of processing, and cookie information is listed above in this Personal Notice. In general, we do not require your consent to transfer your Personal Data. By using the Services and providing us with your Personal Data, you agree to the data transfers detailed in this Personal Notice that require your consent. The above descriptions of privacy rights to access, rectification, erasure, and object apply to residents of Mexico, as does the right to restrict processing to storage only (which includes the limitation to the use and disclosure of your Personal Data), and advertising. You also have the right to revoke the consent that you have provided us to process your Personal Data. To exercise any of your rights, contact legal@teal.fm. **Hong Kong.** As a Hong Kong data subject, you have legal rights in relation to the Personal Data we hold about you (to the extent permitted under applicable laws and regulations). You are entitled to make a Privacy Request to receive a copy of the Personal Data we process about you, a data correction request as well as a right to reject the use of your Personal Data for direct marketing purposes. We may charge a fee for a Privacy Request for access. **China Mainland.** We will only collect and use your Personal Data with your consent or with another lawful basis as described in this Personal Notice. You can withdraw your consent anytime. When you withdraw consent, the Personal Data processing based on your previous consent remains valid. We protect your Personal Data subject rights under PRC privacy laws, which includes the right to access, rectify, erase, copy Personal Data, and the like. For more information, see Your Privacy Controls above. **Russia.** If you are using any Services from Russia, by doing so you consent to: (i) the processing of your information in accordance with this Personal Notice for the purposes of the Russian Federal Law No. 152-FZ dated 27 July 2006 "On Personal Data" (as amended) or any replacement regulations; (ii) if legitimate interests, optimization of the Services or carrying out of the contract are mentioned herein, you agree that, for the purposes of Russian law, the consent so provided can be considered an additional ground for processing (meaning that the processing is conducted with your consent) and this consent also covers the processing of any cookies (to the extent that those qualify as personal data under Russian law); (iii) the cross-border transfer of your information to any country where we have databases or affiliates, in particular United States or other jurisdictions; (iv) for the purposes of Article 152.1 of the Russian Civil Code, the processing of your image in accordance with this Personal Notice; and (v) for the purposes of Federal Law "On Marketing/Advertising", that we may share advertising/marketing communications with you, unless you have opted-out from such communications. You have the rights to access, rectification, erasure/deletion, restrict processing to storage only, object, and you can control the use of your Personal Data for advertising purposes. We will update this posting if we materially change this Personal Notice and we may request you to acknowledge such changes. Unless we require your acknowledgment, you shall be deemed to have agreed to the changes if you continue using the Services after the updated posting and any required notification. As regards the representative for Russia, you can contact us at legal@teal.fm. Please include the word "Russia" in the subject line. ## DATA SECURITY We have implemented and maintain reasonable and appropriate security procedures and practices to help protect your Personal Data from unauthorized or illegal access, destruction, use, modification, or disclosure. Our security measures are appropriate to the volume, scope, and nature of the Personal Data processed and designed to meet our duty of care with respect to your Personal Data. The Services are designed with data security in mind to continuously protect your data and our systems. We maintain internal policies to govern the collection, processing, and handling of data. Access to Personal Data is limited to employees and contractors as needed to perform their job functions. Anyone with this access is subject to strict contractual confidentiality obligations and may be disciplined or terminated if they fail to meet these obligations. We also ensure that our employees, contractors, and agents responsible for handling privacy inquiries are informed of applicable legal requirements and we restrict access to those who need that information to process it. Please note that no transmission of data over the internet is 100% secure, and we cannot guarantee that unauthorized third parties will not defeat our security measures or use your Personal Data for improper purposes. Users are responsible for maintaining the confidentiality of their login credentials and account access. **ATProto Network Considerations.** Because your public ATProto data is federated across the decentralized ATProto network, it may be stored on and accessible through other PDS providers and services. We cannot control the security practices of other servers in the ATProto network. ## SERVICE PROVIDER AND LOCATION The teal.town PDS is hosted with third-party infrastructure providers in the United States. We perform regular backups of the server to ensure data integrity and availability. The specific infrastructure provider and location may change as we optimize our Services. ## CROSS-BORDER DATA TRANSFERS We are owned and operated in the United States. We use technical infrastructure in the United States and potentially other jurisdictions to provide our Services to Users wherever they are located. This means data must sometimes be transferred across jurisdictional boundaries. When your information is moved from your home country to another country, the laws and rules that protect your Personal Data in the country to which your information is transferred may be different from those of the country where you live. For example, if your information is in the United States, it may be accessed by government authorities in accordance with U.S. law. We are committed to transferring Personal Data using a lawful data transfer mechanism. Specifically, when we transmit data from the EU, UK, or Switzerland to the U.S. or other jurisdictions, we do so pursuant to the standard contract clauses approved by the European Commission and employ those security measures required by the country in question to secure the data. Any such transfer is performed on the legal basis that the transfer is necessary to provide you with the Services. Additionally, the ATProto protocol is designed as a federated, decentralized network, which means your public data is inherently distributed across multiple servers and jurisdictions worldwide. By using our Services, you acknowledge and consent to this federated architecture. We do not warrant that the Services are appropriate or authorized for use in any other jurisdictions. Each User is solely responsible for determining whether their use of our Services complies with applicable laws. Your use of our Services constitutes your consent to the transfer and processing of your Personal Data as described in this section. ## THIRD-PARTY PLATFORMS The Services integrate with the ATProto network and may be used in conjunction with various ATProto client applications (such as Bluesky). We are not responsible for and have no ability to control the privacy and data collection, use, and disclosure practices of any third party. Use of third-party applications or platforms is subject to the third party's privacy policies and practices, not ours. We have no control over any third party's privacy practices. Please review the privacy policies of such applications and platforms before using them to access your teal.town account. **Direct Messages.** Your direct messages are stored on and processed by Bluesky's servers, not teal.town servers. The privacy and security of your DMs are subject to Bluesky's privacy policy and practices. ## METRICS DISCLOSURE CHART Pursuant to the California Consumer Privacy Act, teal computing LLC provides the following Consumer Requests Metrics for teal.town. "Requests" refers to all of the following type of requests: - Requests to Delete - Requests to Know - Requests to Know what personal information was sold or shared, and to whom it was sold or shared - Requests to opt out of the sale or sharing of personal information - Requests to limit the use and disclosure of sensitive personal information **Requests received from consumers in 2026:** 0 **Requests complied with in whole or in part in 2026:** 0 **Requests denied in 2026:** 0 **Median days taken to respond substantively to Requests in 2026:** 0 --- **Contact Information** If you have questions about this Privacy Policy, please contact us at: **Email:** legal@teal.fm