Privacy
How Get My Identity handles data
Get My Identity (GMI) provides personal profile pages. This notice explains the information involved in operating the service and our privacy-first profile analytics.
Account and profile information
When you create or manage a profile, GMI processes the account details supplied through our authentication provider and the profile content you choose to provide. Published profile content is public at the profile address. Do not publish information you want to keep private.
Profile analytics
When analytics collection is enabled, GMI measures visible visits to published profile pages and activations of eligible outbound, email, and telephone links. Navigation, sharing controls, editor previews, Markdown requests, and recognized automated traffic are excluded from owner-facing profile metrics.
Analytics records may include a random event and page-instance identifier, profile and stable link identifiers, server time, referring hostname, validated campaign tags, broad device category, and country code supplied through trusted Cloudflare infrastructure. We do not store full referring URLs, arbitrary page content, raw IP addresses, or full user-agent strings in profile analytics tables.
Daily visitor estimates
GMI creates a profile-specific daily identifier from the visitor address normalized by our trusted proxy, the user agent, and a random secret that rotates by UTC day. Only the resulting keyed hash is stored in analytics. Profile analytics does not use cookies, local storage, or cross-day identifiers to recognize visitors.
These figures are estimates, not identities or exact counts of people. Shared networks may combine visitors, while network, browser, VPN, or IPv6 address changes may split one visitor into more than one estimate.
Access and retention
Profile analytics reports are available only to the authenticated profile owner. Free accounts receive a limited summary; supporter accounts may receive up to one year of history and detailed source, campaign, link, device, and country reports. Contact and booking link clicks show intent, not completed enquiries or bookings.
Raw profile analytics events and daily hashing secrets are retained for approximately 90 days. Aggregated daily summaries are retained for approximately 13 months. Deleting the relevant profile or account removes its associated profile analytics according to the service deletion workflow.
Infrastructure and operational logs
Cloudflare processes requests before they reach GMI and may provide the originating address and country to our server. Supabase hosts application data; Clerk provides authentication; and Cloudflare R2 may store profile images. These providers process data under their own terms and policies.
Although raw addresses are not stored in profile analytics tables, security, proxy, application, and provider logs may contain IP addresses, request paths, timestamps, and diagnostic information for reliability and abuse prevention.
Payments
Supporter subscriptions use Stripe Checkout and Stripe’s customer portal. Payment details are entered directly with Stripe; GMI does not store card numbers or other payment-card details. To operate a subscription, GMI stores the Stripe customer and subscription identifiers, subscription status, selected billing period, and relevant renewal or cancellation dates. Stripe processes payment information under its own privacy policy.
Questions and requests
For privacy questions or requests concerning your GMI account, email [email protected]. We may need to verify account ownership before acting on a request.