HIGHPORT policies · highport.space

Privacy Policy

Last updated: 2026-09-05 · Read this as Markdown

This policy explains what personal data Highport handles, why, and what rights you have. We’ve written it in plain language; where the law forces a technical term, we explain what it means in practice.

Who is responsible for your data (the “controller”)

Nick Gerakines, operating Highport, based in Ohio, USA.
Contact: hello@highport.space.
Our servers are located in Germany.

1. What we collect, why, and our legal basis

You don’t need to give us your name or email address to use Highport. You sign in with your AT Protocol identity, and for most of what the service does, that’s all we hold. We ask for an email address in exactly two situations, both described below, and you can use Highport’s free tier without either.

Under GDPR we have to tell you our “legal basis” for each use of your data. Here it is, in a table you can actually read:

What we collect Why Legal basis (GDPR)
Your email address — only if you opt in to notifications To send you the alerts you asked for (for example, a warning when you reach 90% of your bandwidth quota), and to reach you if we ever moderate or restrict your content Your consent — Article 6(1)(a). You can withdraw it at any time, and we make that as easy as giving it.
Your name and email address — only when you buy bandwidth To take payment, issue a receipt, and handle anything that comes up about that purchase Performance of our contract with you — Article 6(1)(b)
Your AT Protocol handle and DID document To connect your account to your identity and serve your content. These are already public on the AT Protocol network. Contract and our legitimate interests — Article 6(1)(b) and 6(1)(f)
Visitor authentication data (when a visitor proves an AT Protocol identity) Only to set the data parameters for hosted sites Our legitimate interests — Article 6(1)(f)
Access logs relayed to site owners — authenticated identities, which sites they access, and request patterns So site owners can gate access to their sites and manage their bandwidth quotas Our and site owners’ legitimate interests — Article 6(1)(f)
Traffic logs we keep — IP address, authenticated identifier (DID), requested sites, and common access-log fields (URL, response status code, request size, response size) Security, abuse prevention, and running the service Our legitimate interests — Article 6(1)(f). Keeping security logs is a recognized legitimate interest (GDPR Recital 49).
Permissioned space records and membership (only where a site owner has granted us permission to read them) To serve sites that require authentication and to check whether an authenticated identity belongs to the space Processed on the site owner’s instructions as their processor — the site owner determines the purpose and legal basis. See section 2.

About email addresses. We only ever have your email if you gave it to us — by opting in to notifications, or by buying bandwidth. If you opt in to notifications, we ask you to confirm the address first, so we don’t send your usage information to someone else’s inbox. You can turn notifications off, or ask us to delete the address, at any time, and we will.

We never share your name and email address with partners or integrators.

About your handle and DID document: these are public information on the AT Protocol network. Because we don’t control that network, keeping that public information under control is your responsibility, not ours.

About the access logs we relay to site owners: we do not include your IP address in what we relay to site owners.

2. We are an independent controller — and so are site owners

This matters, so we’re spelling it out.

Highport is not responsible for what a site owner does with the access logs we relay to them. If you visit a hosted site, that site owner is responsible for their own use of your data.

Permissioned spaces work differently. If a site owner uses permissioned spaces (see the Terms, section 12) and gives us permission to read their site and tile records, we read those records on their instructions and for their purposes. For that processing we act as the site owner’s processor, not as an independent controller. The site owner remains the controller and decides what goes in the space and who may see it. We enter into a written data processing agreement with site owners who use this feature.

3. Where your data is

Your data is stored and processed on our servers in Germany, and it stays there. We do not transfer or transmit your personal data outside the EU.

Highport is run by one person, based in Ohio, USA. When we access the servers to operate and maintain the service, we are reaching our own infrastructure in Germany — your data is not copied or moved out of the EU to do it. We secure that access as required by GDPR Article 32.

If this ever changes — for example, if we start using a service provider located outside the EU — we will update this policy and put a lawful transfer mechanism in place first.

4. How long we keep your data

5. Your rights

These rights apply to everyone who uses Highport, wherever you live. You can ask us to:

To exercise any of these, email hello@highport.space. You also have the right to complain to your local data protection authority, if there is one where you live. We’d rather you came to us first so we can fix it, but you don’t have to.

6. AT Protocol data, and the honest limits of deletion

Your sites, tiles, and DID document live in your own PDS and on the public AT Protocol network, which we do not own or control.

If you ask us to delete your data, we will delete our own copies and stop serving your content. But we cannot erase what lives in your PDS or anywhere else on the public AT Protocol network — that is outside our control. You control that data at its source, in your PDS.

7. The opt-out record

As explained in the Terms, you can permanently opt out by publishing a space.highport.policy record with optOut set to true. Doing so is a public, permanent, and voluntary act that permanently blocks your identity from Highport.

8. Children

Highport is for adults only. We do not knowingly collect data from anyone under 18 (or under 13 in the US, per COPPA). If you believe a child has given us data, contact hello@highport.space and we will delete it.

9. Data breaches

If a data breach is likely to create a risk to you, we will notify the relevant authority within 72 hours of becoming aware of it, and we will tell you directly when the risk to you is high. We apply the 72-hour standard to every breach, for every user, wherever you live.

10. Changes to this policy

We may update this policy. When we do, we’ll change the “Last updated” date and, for significant changes, take reasonable steps to let you know.