Privacy Policy
Last updated: August 30, 2026
This Privacy Policy explains how Tell The World (“we,” “us,” “the Platform”) collects, uses, and protects your personal data when you visit telltheworld.io or use the Platform, in accordance with the EU General Data Protection Regulation (GDPR).
Who is responsible for your data
The data controller is:
Giulia Consonni
Operating “Tell The World” as an individual / sole proprietor
Neumayerstr. 19, Neustadt an der Weinstraße, Germany
You can reach us with any privacy question or request via our contact form.
What data we collect
a) If you just browse the site or join the waitlist
- Email address (waitlist signup only)
- Standard technical data (IP address, browser type, pages visited) via server logs
b) If you apply for membership (creator, journalist, expert, organisation, communications specialist, or other)
- Full name, email, desired role, bio, website URL
- Role-specific details you provide: e.g. platform/audience size and content language (creators/journalists), affiliation and credibility link (experts), org name/size/mission (organisations), publication and reporting beat (journalists)
- Internal admin notes and review status (visible only to us, not to you)
c) If you’re an approved member
- Everything from your application, now stored as your profile: display name, avatar, bio, availability status, preferred language, and the role-specific fields above
- Authentication data from Supabase Auth: when you sign in with Google or LinkedIn, we receive your email and basic profile info from that provider; if you use magic link, we only use your email to send the sign-in link. We do not receive or store passwords.
- Content you publish: posts (videos, articles, papers, quotes, resources) and any text/links you submit
- Questions and answers you post on briefs
- Messages: when you send or receive a contact request, we store the sender, recipient, subject, and body of that message
What we don’t collect
We don’t run advertising trackers, and we don’t sell or rent your data to anyone.
Why we process your data (legal basis)
| Purpose | Legal basis |
|---|---|
| Reviewing your application | Steps taken at your request prior to a contract (Art. 6(1)(b)) |
| Providing the Platform to approved members (profiles, briefs, directory, messaging) | Performance of a contract (Art. 6(1)(b)) |
| Authenticating you via Google, LinkedIn, or magic link | Performance of a contract / your consent to the OAuth provider (Art. 6(1)(b)) |
| Sending you transactional emails (approval/rejection notices, contact request notifications) | Performance of a contract (Art. 6(1)(b)) |
| Keeping the Platform secure, preventing abuse, basic analytics | Legitimate interest (Art. 6(1)(f)) |
| Complying with legal obligations (e.g. tax records) | Legal obligation (Art. 6(1)(c)) |
International data transfers
Our database, authentication, and file storage (Supabase) are hosted in the EU (Ireland). Some of our other processors (Vercel, Resend, Google, and LinkedIn) may store or process data outside the EU/EEA, including in the United States. Where this happens, we rely on appropriate safeguards such as the EU-US Data Privacy Framework or Standard Contractual Clauses (SCCs), as provided by these vendors.
How long we keep your data
- Rejected applications: deleted or anonymised after 12 months, kept only long enough to handle appeals or repeat applications.
- Approved member profiles: kept for as long as your account is active, plus 30 days after you delete your account, to handle immediate recovery requests.
- Content posts, Q&A, quotes: kept until you delete them or your account is closed, since they form part of the Platform’s shared knowledge base. Removal on account deletion is handled on request (see Section 7).
- Messages: kept for as long as either party’s account is active.
- Server/access logs: kept for 90 days for security purposes, then deleted.
Your rights
Under the GDPR, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase your data (“right to be forgotten”), subject to legal or legitimate-interest exceptions
- Restrict processing in certain circumstances
- Data portability: receive your data in a structured, machine-readable format
- Object to processing based on legitimate interest
- Withdraw consent at any time, where processing is based on consent (e.g. OAuth sign-in), without affecting prior processing
- Lodge a complaint with a supervisory authority: either your own country’s data protection authority, or ours, the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz (Rhineland-Palatinate, Germany), since that’s where the Platform is operated from
To exercise any of these rights, reach us via our contact form. We’ll respond within one month, as required by GDPR.
Security
We use industry-standard measures to protect your data, including encrypted connections (HTTPS), access-controlled admin tools, and provider-level security (Supabase’s built-in row-level security and authentication). No system is 100% secure, but we take reasonable steps to protect your information against unauthorised access, loss, or misuse.
Children
Tell The World is intended for professional use by adults: content creators, journalists, researchers, and organisations. It is not directed at, and we do not knowingly collect data from, anyone under 16.
Changes to this policy
We may update this policy as the Platform evolves (e.g. when multilingual support or new features launch). We’ll update the “Last updated” date above and, for material changes, notify active members by email.
Contact
Questions about this policy or your data: use our contact form.