Privacy.

The short version: we don’t keep your data. The apps on this site run in your browser and write to your own account. There is no CultureBlocs server holding a copy, and no account with us to delete.

Applies to: I went · Pocket Totem · Easel · the wall, catalogue and event pages · last updated 6 October 2026 (who-went lists and the Bluesky feed added)

When you sign in

Signing in uses ATProto OAuth with your own account provider — Bluesky, Blacksky, Eurosky, a server you run, or any other. You type your password on their page, never ours. They give your browser a token that lets the app write to your account; what it may write is shown on their approval screen. I went asks only to write beads, plus one post and an image for its link card if you choose to post to Bluesky. Some account providers don’t yet support permissions that narrow, and then ask for general access instead — the app still only writes what you see it write.

The token, and the key it is bound to, are kept in your browser’s own storage on this device. They are never sent to us. Signing out (or clearing this site’s data in your browser) removes them; you can also revoke access from your account provider’s settings at any time.

What gets published

When you press publish, a record is written to your account’s repository. Records in an ATProto repository are public: anyone can read them, as with a post. A bead from I went holds the event it points at, the day you chose, the kind of moment and your note. It does not hold your location, the time of day, or anything about your device. If you also post to Bluesky, that post is public in the usual way.

Your records are yours. You can delete them with any ATProto tool, or with Loom. Deleting a bead does not delete a post you made alongside it — remove that from Bluesky as normal.

What we see

Nothing about you, by design. Pages read public records straight from the network in your browser. We use no analytics, no advertising and no tracking cookies. The site is hosted on Vercel, which, like any web host, may keep short-lived technical request logs (such as IP addresses) to run and protect the service.

Pages that show published records — an event’s page, someone’s wall — only ever show what was already public in that person’s repository. Event pages list the public beads that point at an event, found through Constellation, an open index of the network, and read from each person’s own account as the page loads. Delete a bead and it disappears from these lists. If you’d like something left off them while it stays in your account, get in touch and we’ll hide it.

The Frieze Week feed on Bluesky works the same way: it lists public posts that link to these pages or carry the CultureBlocs tags, found through Constellation and Bluesky’s public search. It keeps no copy and no record of who reads it. The same hide list applies.

Questions

CultureBlocs is a geekyoto project. Get in touch through geekyoto.com or GitHub.