Privacy Policy
Last updated: 12 August 2026
This policy explains what we hold about you, why, for how long, and what you can make us do about it.
It is longer than we would like. That is because this is a place where people write private things, and you deserve to know exactly where those words go.
1. Who is responsible for your information
The Don’t Hold Back Project
ABN 40 366 975 511
PO Box 3103, Newport, Victoria 3015
Australia
Contact: yay@dontholdbackproject.com
Under the European General Data Protection Regulation we are the data controller for the information described here. Under the Australian Privacy Act 1988 we handle personal information in accordance with the Australian Privacy Principles.
If you have a question about anything in this policy, write to the address above. A person reads it.
2. What we collect, why, and on what legal basis
2.1 Information you give us
| What | Why we need it | Legal basis (GDPR) |
|---|---|---|
| Your first name | It appears inside your own declaration — I, [name], am going to… — and we use it when we write to you | Performance of a contract |
| Your chosen name | The only name shown publicly on the wall | Performance of a contract |
| Your email address | To send you your password link, to tell you when somebody stands with you, and as the way back into your account | Performance of a contract |
| Your declaration | It is the thing you came here to publish | Performance of a contract |
| Your by-when date, if you give one | To ask you, later, whether you went | Performance of a contract |
| Your answer when you return | I did · I did not · not yet | Performance of a contract |
| Words of encouragement you leave | To show them under somebody else’s declaration | Performance of a contract |
| Your notification preferences | To send only what you asked for | Consent |
2.2 Information collected automatically
- Server logs. Every visit records an IP address, browser type, operating system, the page requested and a timestamp. This happens on every website in the world and is necessary to run and secure ours. Legal basis: legitimate interests — keeping the site working and defending it from attack.
- A cookie that holds your unfinished declaration, so your words are not lost if your phone locks or your connection drops.
- A cookie that remembers which declarations you have stood with, so the marks you tapped stay lit when you return.
We do not use advertising cookies, tracking pixels, or third-party analytics that profile you across other websites.
2.3 Information we deliberately do not collect
- We do not store your surname.
- We do not store your card details. They go directly to Stripe and never touch our servers.
- We do not ask for your date of birth, gender, location, phone number, or anything else we do not need.
3. Your declaration is public, and what that means
When you publish a declaration, it is visible to anyone on the internet. It can be read by people who do not have an account, found by search engines, and shared as a link.
We show your chosen name, not your real name — unless you use the per-declaration switch to publish fully unnamed, in which case no name is shown at all.
Special category information
Some declarations reveal things that data protection law treats as especially sensitive — health, sexual orientation, religious or philosophical belief, or information about your relationships.
I am going to get the test results. I am going to tell my parents who I am. I am going to leave him.
Where that happens, our legal basis under Article 9(2)(e) of the GDPR is that you have manifestly made the information public yourself, by choosing to publish it.
Please think before you publish. We give you the unnamed option and we screen what other people say to you, but we cannot make a public sentence private again once it has been read, copied, or shared. If a declaration would put you at risk — for example if leaving a relationship safely depends on nobody knowing — consider whether publishing it here is the right step, or use the unnamed option.
4. Automated processing
Two things on this site are decided by software rather than a person. Data protection law requires us to tell you plainly.
Colour. When you publish, our system reads your declaration and assigns it a colour according to the kind of leap it is. Nobody is asked to classify their own hope. This has no consequence beyond how your declaration looks.
Screening. Declarations and words of encouragement are checked automatically before they appear, for abuse, threats, sexual content, spam, and for anything that advises, warns, corrects or diminishes rather than encourages. Content that fails is returned to you with an invitation to try again, not a penalty.
Neither of these produces a legal or similarly significant effect on you. If something of yours is held or returned and you think that is wrong, write to yay@dontholdbackproject.com and a human being will look at it. You have the right to that review.
5. Who else handles your information
We keep this list as short as we can. Each of these is a company we pay to do one job.
| Who | What they do | Where | What they receive |
|---|---|---|---|
| Hostinger | Hosts the website and the database | [SERVER REGION — check hPanel] | Everything stored on the site |
| Stripe | Takes your payment | United States, Ireland | Your name, email and card details, direct from you |
| MailerSend | Sends our emails | European Union / United States | Your email address and the contents of emails to you |
We do not sell your personal information. We do not share it for advertising. We do not disclose it to anyone else unless we are legally required to, or unless it is necessary to protect somebody from serious harm.
6. Information going overseas
We are based in Australia. The companies above operate in the United States and the European Union, so your information will be transferred, stored and processed outside your own country.
For transfers out of the European Economic Area and the United Kingdom, we rely on the Standard Contractual Clauses approved by the European Commission, which each of the above providers has entered into.
For Australian users, under Australian Privacy Principle 8 we have taken reasonable steps to ensure these overseas recipients handle your information consistently with the Australian Privacy Principles.
7. How long we keep things
| What | How long |
|---|---|
| Published declarations | Indefinitely, unless you delete them. The wall is an archive and does not fade. |
| Your account | Until you delete it |
| Unfinished drafts, never published | 30 days, then deleted automatically |
| Payment records | 7 years, because tax law requires it |
| Server logs | 30 days |
| Email delivery records | 90 days |
When you delete your account, your declarations and everything attached to them are deleted with it. Payment records are kept for the period above because we are legally required to, and they contain no declaration content.
8. What you can make us do
Wherever you live, you can ask us to:
- Show you everything we hold about you
- Correct anything that is wrong
- Delete your account and everything in it
- Send you a copy of your information in a portable format
- Stop processing your information, or restrict it
- Object to processing based on legitimate interests
- Withdraw consent at any time, where we relied on consent. This does not make what we did before unlawful.
Write to yay@dontholdbackproject.com. We will answer within 30 days, and free of charge.
If you are in the European Economic Area or the United Kingdom, you also have the right to complain to your national data protection supervisory authority.
If you are in Australia, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au. We ask that you come to us first, so we have the chance to put it right.
If you are in California, you have the rights above, and we confirm we have not sold or shared your personal information in the preceding twelve months. We will not discriminate against you for exercising any right.
9. Security, and being honest about it
We use encrypted connections (HTTPS) throughout. Passwords are stored hashed and are never readable, by us or anyone else. Card details never reach our servers. Access to the database is limited to those who need it to run the site.
No system is perfectly secure, and we will not pretend otherwise. If a breach occurs that is likely to result in serious harm to you, we will notify you and the relevant regulator without undue delay, and in any event within 72 hours of becoming aware of it where the GDPR applies, and as required by the Notifiable Data Breaches scheme in Australia.
10. Children
This site is not for people under 18, and we do not knowingly collect information from them. If you believe a child has created an account, write to us and we will delete it.
11. Changes
If we change this policy in a way that materially affects you, we will email you before it takes effect. The date at the top always shows the current version.
This policy is written to be read rather than to be survived. If any part of it is unclear, that is our failing — tell us and we will rewrite it.