Privacy
What we collect, and what we do not.
People Commons is a small site run by one person. This page says plainly what happens to your data, in the order you are likely to meet it.
Version 1.2 · 16 August 2026
1. Who runs this site
Registration number: 60701721
Tax number: 91232878-1-33
Registered address: Huszka Mihály utca 22/B, 2143 Kistarcsa, Hungary
Email: hello@peoplecommons.com
People Commons is a side project, not a company. There is no team behind it and no investor. A data protection officer is not required for an operation of this size and none has been appointed. Every question about your data comes to the address above, and I answer it myself.
2. What this page covers
This page covers peoplecommons.com and the tools on it. It does not cover other sites you reach from here. The Gazette links out to articles on other people's websites, and once you follow one of those links you are on their site under their rules.
3. What happens, situation by situation
The short version: browsing collects nothing, an account collects your email, and the AI tools send your text to Anthropic to produce the answer but do not keep it here.
You are just reading
Nothing is collected by us. No cookies are set, no tracking script runs, and no analytics are loaded on the public pages. The hosting provider records the request in its server log, in the same way every web server does. See section 8.
You join the newsletter list
Your email address is stored so that a newsletter can be sent to it. Nothing else is stored with it, not a name and not where you signed up from. The list itself sits in this site's own database, not at the company that does the sending.
No newsletter has been sent yet. The list exists and people are on it, but the first issue has not gone out. The company that will send it is Brevo, and it is named in section 6 now rather than after the first send. The newsletter will come from news@peoplecommons.com and every issue will carry an unsubscribe link.
You create an account
An account stores your email address and your password. The password is handled by Supabase Auth, which stores it as a hash. It is never visible to me, and it cannot be read back out of the database. You may add a first name so the site can greet you properly. That field is optional and you can change or empty it at any time on your account page.
An account also means the site has to send you the occasional email: the message that confirms your address when you register, and the link that lets you set a new password if you forget it. These come from no-reply@peoplecommons.com and go out through Brevo, which is listed in section 6. They are not marketing. Nothing else is sent to you unless you joined the newsletter list separately.
You use an AI tool
The post drafter, the Writing Desk, the job description writer, the job advert writer and the Document room send the text you typed to the Anthropic API, which produces the answer and sends it back. This is what makes the tool work. Your text passes through the server on the way and is not written to the database on the way through.
The two writers that accept a file, the job description writer and the job advert writer, read that file in your browser. The file itself is never uploaded. What is sent onwards is the text that was pulled out of it, and only when you press the button that writes the document. The same is true of a logo: it is used to build the Word file on your own device and never reaches the server.
What is written down is a usage record: which tool ran, which model, how many tokens went in and out, the estimated cost, and who ran it. The record does not contain your text and it does not contain the answer. It exists so the running cost of the site can be tracked and so the monthly allowance can be counted.
A habit worth having.
When you paste something into an AI tool, replace anything you would not want leaving your organisation with a made up placeholder. Write [Company] instead of the real employer, [Manager] instead of a colleague, [Country] instead of the site, and a round number instead of a real figure.
The draft comes back with the placeholder still in it. You then replace it once, in your own document, after the text has left this site. It costs a few seconds, the output is just as good, and the version with the real names in it never travels anywhere.
The same habit helps later: a document written with placeholders is easy to reuse for a different team, a different country or a different year.
You download a file
The site records which file you took and when. That record is also your library, which is why the file stays available to you afterwards and why taking the same file twice does not cost you a second download.
You save your work
Nothing you write is saved automatically. A draft, a policy or a carousel is stored only when you press Save, and then the title, the text and the settings are stored under your account. You can open, download or delete any saved item from your account page.
4. The full list
| What | Why | Legal basis | How long |
|---|---|---|---|
| Email address, password hashAccount | To let you sign in and to keep your work attached to you | ContractGDPR 6(1)(b) | While the account exists |
| First name, optional | To greet you by name | ContractGDPR 6(1)(b) | While the account exists |
| Writing style note, optionalFree text you write about how your posts should sound | So the post drafter matches your voice on every device | ContractGDPR 6(1)(b) | While the account exists, or until you clear it |
| Saved drafts, policies and carousels | So you can come back to your work | ContractGDPR 6(1)(b) | While the account exists, or until you delete the item |
| Download records | Your library, and the monthly download count | ContractGDPR 6(1)(b) | While the account exists |
| Usage recordsTool, model, token counts, cost, credits | To track what the site costs to run and to count your allowance | Legitimate interestGDPR 6(1)(f) | The link to your account is removed after 12 months. The cost figures stay as anonymous records. |
| Guest identifierA random id kept in your browser | To count the free monthly run for people without an account | Legitimate interestGDPR 6(1)(f) | 12 months in the usage record. In your browser until you clear it. |
| Hashed IP address | A daily ceiling, so one machine cannot run the tools hundreds of times | Legitimate interestGDPR 6(1)(f) | 30 days |
| Newsletter email address | To send the newsletter | ConsentGDPR 6(1)(a) | Until you unsubscribe or ask to be removed |
| Email delivery recordHeld at Brevo: the address, the subject, whether it arrived | To see whether a confirmation or a password link actually reached you when it did not seem to | Legitimate interestGDPR 6(1)(f) | Held under Brevo's own retention rules, not ours |
The IP address is never stored as an IP address. It is turned into a one way hash with a secret key before it is written down, which means it can be compared against another request from the same machine on the same day but cannot be turned back into an address.
Where the data sits in this site's own database, the retention periods above are enforced by a scheduled job, not by someone remembering to run it. The last row is the exception: those records live at Brevo and are kept to Brevo's rules.
5. Who can see your saved work
This deserves a plain answer rather than a careful one.
Your saved documents sit in a database that I administer. That means I hold the keys and can technically read them, in the same way that anyone running any web service can read their own database. There is no arrangement that makes this untrue, and any service telling you otherwise is either using end to end encryption, which this site does not, or is being loose with words.
What I can promise is the practice rather than the impossibility. I do not read saved documents as a matter of course. There are two situations where I would open one: you ask me to because something has gone wrong with it, or I am investigating a specific abuse of the service. Nothing is read for curiosity, for research, or to build anything.
If that is not comfortable enough for a particular piece of work, and for some HR material it should not be, then do not press Save, and use the placeholder habit in section 3. The tools work perfectly well without saving anything.
6. Who else handles the data
The site runs on other people's infrastructure. These are the companies involved and what each one does.
| Who | What they do | Where |
|---|---|---|
| Supabase | The database, the sign in system and the file storage | EU region |
| Vercel | Hosting, the domain and the server side functions | United States company, EU infrastructure |
| Anthropic | The AI model that produces the drafts | United States |
| Brevo | Sends the mail this site has to send: the address confirmation, the password link, replies to your questions, and the newsletter when it starts | France |
| ImprovMX | Forwards mail sent to hello@peoplecommons.com to a personal mailbox | France |
None of these companies is allowed to use your data for their own purposes. They process it to provide their service and nothing else.
Two content networks, on five pages only
The Document room, the Writing Desk, the job description writer, the job advert writer and the carousel editor load a few software libraries from two public content networks, jsDelivr and Cloudflare, at the moment you open them. Loading a file from those networks means your browser makes a request to them, and a request carries your IP address. This happens only on those five pages and only for the software, never for your content.
Everything else, including the fonts and the sign in library, is served from peoplecommons.com itself. Google Fonts was removed from this site in August 2026 for exactly this reason.
7. Data that leaves the EU
When you use an AI tool, your text goes to Anthropic in the United States. There is no way to offer the tool without this transfer.
Anthropic's published policy for its API is that inputs and outputs are deleted from its systems within 30 days, and that data sent through the API is not used to train its models. Their own statement is here: how long Anthropic stores organisation data. The transfer is covered by the standard contractual clauses in Anthropic's commercial terms.
This is the single most important thing on this page for an HR reader, which is why the placeholder habit in section 3 is worth the few seconds it takes.
8. Server logs
Vercel, the hosting provider, writes a line into its log for every request that reaches the site. That line contains the IP address, the time, the page requested and the browser's user agent string. This is automatic, every web server does it, and it cannot be switched off without switching off the site.
These logs are used to see whether the site is working and to look into an error. They are held under Vercel's own retention rules, not ours, and they are not joined up with anything else on this page.
9. Analytics
There is no analytics on the public pages. No page view counter, no heatmap, no advertising pixel, no social media tracker.
Vercel Analytics runs on three administrative pages that only I can open. It never sees a visitor.
10. What is stored in your browser
This site sets no cookies. Not one, not even a functional one. That is why there is no cookie banner: there is nothing to ask you about.
The site does use your browser's local storage, which is a different mechanism. Local storage stays on your device, is never sent to a server on its own, and is not readable by any other website. Everything kept there is needed for the site to work:
| What is stored | Why |
|---|---|
| Your sign in sessionSet by Supabase Auth | So you stay signed in between pages and visits |
pc-guest-id |
A random id that counts the free monthly run when you have no account |
pc-carousel-draft-v1 |
Your unsaved carousel, so a closed tab does not lose it |
pc-drafter-prefs, pc-writingdesk-settings, pc-jd-settings |
Your last choices in those tools, so you do not set them again every time. pc-jd-settings is shared by the job description and job advert writers and holds your company name, your font choice and, if you added one, your logo |
pc-open-draft, pc-open-policy, pc-open-jd, pc-open-carousel, pc-handoff-post, pc-market-doc |
Short lived hand overs, used when one tool passes a piece of work to another. Each is cleared as soon as it has been picked up. |
You can clear all of it at any time through your browser settings. Signing out clears the session. Clearing the rest costs you your unsaved carousel, your tool preferences and your stored logo, and nothing else.
11. Your rights
Under the GDPR you may ask for any of the following, and you do not have to give a reason:
- Access. A copy of what is held about you.
- Rectification. Correction of anything wrong. Your email and first name you can change yourself on the account page.
- Erasure. Deletion of your account and everything attached to it. See section 12.
- Restriction. A pause on processing while something is disputed.
- Portability. Your saved work in a machine readable file. You can also download any saved item yourself.
- Objection. An objection to the processing that rests on legitimate interest, which here means the usage records and the abuse ceiling.
- Withdrawal of consent. For the newsletter, at any time, with no effect on anything else.
Write to hello@peoplecommons.com. You will get an answer within 30 days, and usually much sooner. If a request is unclear I may ask you one question to confirm what you want, and I may need to confirm that the request comes from the account holder.
12. Deleting your account
There is no delete button on the account page yet. It is on the list, and until it exists the route is manual, which is slower for you and honest about where the site is.
Send an email from the address on the account to hello@peoplecommons.com with the word Delete in the subject. Within 30 days the following will be removed: your sign in record, your profile, your saved documents and your download history.
One thing stays behind. The usage records lose their link to you and remain as anonymous cost figures, with no way to connect them back to a person. Those rows are how the running cost of the site is known, and without them the cost history is destroyed by a single deletion.
Deleting the account also takes you off the newsletter list if you are on it.
13. Security
- Everything travels over HTTPS. There is no unencrypted version of the site.
- Passwords are stored as hashes by Supabase Auth and are not visible to me.
- The database uses row level security, so one account cannot read another account's rows even if a request is crafted by hand.
- Downloadable files sit in a private bucket. A download link is signed and expires after 60 seconds, so a copied link is useless a minute later.
- The keys that can read the whole database exist only on the server and are never sent to a browser.
No site can promise it will never be broken into. If something happens that puts your data at risk, you will hear about it from me, and the authority will be notified where the law requires it.
14. Children
This site is built for people doing HR work and is not intended for children. Please do not create an account if you are under 16.
15. If you are not happy
Tell me first. Most things are a misunderstanding or a mistake, and both are quicker to fix directly.
You also have the right to complain to the Hungarian supervisory authority at any time, without going through me:
Postal address: 1363 Budapest, Pf. 9
Phone: +36 1 391 1400
Email: ugyfelszolgalat@naih.hu
Website: naih.hu
If you live in another EU country you may also complain to your own national authority.
16. Changes to this page
This page carries a version number and a date at the top. When something changes that affects you, such as a new provider or a new kind of data, the version goes up and the change is described here before it takes effect, not after.
The site is under active development and things will be added to it. Anything that would change what happens to your data will appear on this page first.