Poured

Privacy

Poured is operated by Royal Runtimes GmbH and hosted in the EU on Google Cloud (europe-west3). This page explains what we store and why.

No ad tracking

Poured uses no advertising or third-party website analytics. Identity Platform keeps the browser signed in, and governed pages may use short-lived access cookies after a password or email check. Ordinary link-public pages do not set a visitor identity cookie.

Your account

We store your sign-in email, verification state, profile name and picture, the public handle/name you choose for apps, and recent sign-in time. Tokens and connected-app credentials are stored only as hashes or revocable records.

Your pages

We store the HTML and media you publish, immutable versions, app records, and governance metadata such as title, tags, access and expiry in EU-hosted Google Cloud services. Deleted pages remain recoverable in Trash for 30 days, count toward storage, and are then purged from the database and object storage.

Views and sharing

Useful owner analytics retain granular view events for 90 days: a purpose-specific rotating IP hash, country, referrer host, device class, share-link reference and, for an email-gated link, the verified viewer email. Compact daily totals remain for 400 days. Viewer grants remain while their link is active and are purged 180 days after that link is revoked or expires.

Apps and consent

A data app stores the contributions you submit and a per-app consent record. Apps normally show a private pairwise handle rather than your email. Leaving an app immediately removes your name and picture from earlier contributions and stops future signed-in writes; the contribution content stays under that private handle unless the app owner or you delete it.

Operations and abuse

Email delivery records contain a short recipient hash and no message body and are kept 30 days. In-app notifications are kept 180 days, resolved abuse reports up to 400 days, and governance/security audit events up to two years. Password-attempt counters and sign-in handoffs are short-lived.

Sharing with providers

We do not sell personal data. We disclose it only to processors needed to run the service (primarily Google Cloud/Identity Platform and, when configured, the transactional email provider), or when legally required.

Your rights

You can access, correct, export, or delete your data. Email contact@royalruntimes.com and we will respond.