Skip to the wall

Privacy Policy

Last updated: 12 August 2026

This policy explains what we hold about you, why, for how long, and what you can make us do about it.

It is longer than we would like. That is because this is a place where people write private things, and you deserve to know exactly where those words go.


1. Who is responsible for your information

The Don’t Hold Back Project
ABN 40 366 975 511
PO Box 3103, Newport, Victoria 3015
Australia

Contact: yay@dontholdbackproject.com

Under the European General Data Protection Regulation we are the data controller for the information described here. Under the Australian Privacy Act 1988 we handle personal information in accordance with the Australian Privacy Principles.

If you have a question about anything in this policy, write to the address above. A person reads it.


2. What we collect, why, and on what legal basis

2.1 Information you give us

What Why we need it Legal basis (GDPR)
Your first name It appears inside your own declaration — I, [name], am going to… — and we use it when we write to you Performance of a contract
Your chosen name The only name shown publicly on the wall Performance of a contract
Your email address To send you your password link, to tell you when somebody stands with you, and as the way back into your account Performance of a contract
Your declaration It is the thing you came here to publish Performance of a contract
Your by-when date, if you give one To ask you, later, whether you went Performance of a contract
Your answer when you return I did · I did not · not yet Performance of a contract
Words of encouragement you leave To show them under somebody else’s declaration Performance of a contract
Your notification preferences To send only what you asked for Consent

2.2 Information collected automatically

  • Server logs. Every visit records an IP address, browser type, operating system, the page requested and a timestamp. This happens on every website in the world and is necessary to run and secure ours. Legal basis: legitimate interests — keeping the site working and defending it from attack.
  • A cookie that holds your unfinished declaration, so your words are not lost if your phone locks or your connection drops.
  • A cookie that remembers which declarations you have stood with, so the marks you tapped stay lit when you return.

We do not use advertising cookies, tracking pixels, or third-party analytics that profile you across other websites.

2.3 Information we deliberately do not collect

  • We do not store your surname.
  • We do not store your card details. They go directly to Stripe and never touch our servers.
  • We do not ask for your date of birth, gender, location, phone number, or anything else we do not need.

3. Your declaration is public, and what that means

When you publish a declaration, it is visible to anyone on the internet. It can be read by people who do not have an account, found by search engines, and shared as a link.

We show your chosen name, not your real name — unless you use the per-declaration switch to publish fully unnamed, in which case no name is shown at all.

Special category information

Some declarations reveal things that data protection law treats as especially sensitive — health, sexual orientation, religious or philosophical belief, or information about your relationships.

I am going to get the test results. I am going to tell my parents who I am. I am going to leave him.

Where that happens, our legal basis under Article 9(2)(e) of the GDPR is that you have manifestly made the information public yourself, by choosing to publish it.

Please think before you publish. We give you the unnamed option and we screen what other people say to you, but we cannot make a public sentence private again once it has been read, copied, or shared. If a declaration would put you at risk — for example if leaving a relationship safely depends on nobody knowing — consider whether publishing it here is the right step, or use the unnamed option.


4. Automated processing

Two things on this site are decided by software rather than a person. Data protection law requires us to tell you plainly.

Colour. When you publish, our system reads your declaration and assigns it a colour according to the kind of leap it is. Nobody is asked to classify their own hope. This has no consequence beyond how your declaration looks.

Screening. Declarations and words of encouragement are checked automatically before they appear, for abuse, threats, sexual content, spam, and for anything that advises, warns, corrects or diminishes rather than encourages. Content that fails is returned to you with an invitation to try again, not a penalty.

Neither of these produces a legal or similarly significant effect on you. If something of yours is held or returned and you think that is wrong, write to yay@dontholdbackproject.com and a human being will look at it. You have the right to that review.


5. Who else handles your information

We keep this list as short as we can. Each of these is a company we pay to do one job.

Who What they do Where What they receive
Hostinger Hosts the website and the database [SERVER REGION — check hPanel] Everything stored on the site
Stripe Takes your payment United States, Ireland Your name, email and card details, direct from you
MailerSend Sends our emails European Union / United States Your email address and the contents of emails to you

We do not sell your personal information. We do not share it for advertising. We do not disclose it to anyone else unless we are legally required to, or unless it is necessary to protect somebody from serious harm.


6. Information going overseas

We are based in Australia. The companies above operate in the United States and the European Union, so your information will be transferred, stored and processed outside your own country.

For transfers out of the European Economic Area and the United Kingdom, we rely on the Standard Contractual Clauses approved by the European Commission, which each of the above providers has entered into.

For Australian users, under Australian Privacy Principle 8 we have taken reasonable steps to ensure these overseas recipients handle your information consistently with the Australian Privacy Principles.


7. How long we keep things

What How long
Published declarations Indefinitely, unless you delete them. The wall is an archive and does not fade.
Your account Until you delete it
Unfinished drafts, never published 30 days, then deleted automatically
Payment records 7 years, because tax law requires it
Server logs 30 days
Email delivery records 90 days

When you delete your account, your declarations and everything attached to them are deleted with it. Payment records are kept for the period above because we are legally required to, and they contain no declaration content.


8. What you can make us do

Wherever you live, you can ask us to:

  • Show you everything we hold about you
  • Correct anything that is wrong
  • Delete your account and everything in it
  • Send you a copy of your information in a portable format
  • Stop processing your information, or restrict it
  • Object to processing based on legitimate interests
  • Withdraw consent at any time, where we relied on consent. This does not make what we did before unlawful.

Write to yay@dontholdbackproject.com. We will answer within 30 days, and free of charge.

If you are in the European Economic Area or the United Kingdom, you also have the right to complain to your national data protection supervisory authority.

If you are in Australia, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au. We ask that you come to us first, so we have the chance to put it right.

If you are in California, you have the rights above, and we confirm we have not sold or shared your personal information in the preceding twelve months. We will not discriminate against you for exercising any right.


9. Security, and being honest about it

We use encrypted connections (HTTPS) throughout. Passwords are stored hashed and are never readable, by us or anyone else. Card details never reach our servers. Access to the database is limited to those who need it to run the site.

No system is perfectly secure, and we will not pretend otherwise. If a breach occurs that is likely to result in serious harm to you, we will notify you and the relevant regulator without undue delay, and in any event within 72 hours of becoming aware of it where the GDPR applies, and as required by the Notifiable Data Breaches scheme in Australia.


10. Children

This site is not for people under 18, and we do not knowingly collect information from them. If you believe a child has created an account, write to us and we will delete it.


11. Changes

If we change this policy in a way that materially affects you, we will email you before it takes effect. The date at the top always shows the current version.


This policy is written to be read rather than to be survived. If any part of it is unclear, that is our failing — tell us and we will rewrite it.