Legal
Privacy
Last updated: 10 October 2026
1. Who is responsible
The controller of the personal data described here is Lucian Medrihan, a private individual based in Rome, Italy. Contact: hello@im.center. There is no data protection officer.
im.center is for people aged 18 and over. We don't knowingly collect data about minors; if you think a minor created a profile, write to us and we'll remove it.
2. What is public
Everything on a profile is public by design: name, handle, tagline, bio, photo, tags, links and link cards, colour theme, ranks (unless the owner turns them off on the profile page) and the reigns it held (also listed in the hall of fame, by name, even after a profile is gone, unless we hid it). The total is public too: it shows on the leaderboards, tag pages, the home page and the profile's boost page, not on the profile page. Supporters' names and messages are not public: only the profile owner sees them. The same public details appear in the profile's link preview card, share posters and badge.
3. What we collect and why
- Profile owner's email: to send sign-in links, the "you're live" email, rank alerts, messages left with boosts and weekly stats (contract; alerts, messages and stats can be turned off). Never shown publicly.
- Payments: Stripe processes card and wallet details; we receive the amount, status and the payer's email, which we store only as a keyed hash to count distinct supporters (contract; legal obligations for accounting).
- Invite codes: if you created your profile with one, which code it was and the version of the terms you accepted (contract).
- Withdrawal-right consent: the wording you agreed to, its version, when you agreed, the version of the terms shown, and a keyed hash of your IP address (never the address itself), linked to the payment (legal obligation; legitimate interest in proving the order if a payment is disputed).
- Disputes: if a payment is disputed, we send Stripe and the bank the order and delivery records: the consent above, the payer's name and email as Stripe collected them, when the placement went live and its rank history, the emails we sent to the payer, and the profile's visits and clicks since the payment. A copy is kept with the payment record (legitimate interest: defending legal claims).
- Visits and clicks: counted per profile and per link per day, without cookies. To count a visitor once and filter bots, we use a keyed hash of the network (IP) address, salted with the day so it changes every day, kept for at most 24 hours in Cloudflare's cache, never in our database (legitimate interest: showing owners their stats).
- Where visits come from: when a profile is visited, your browser tells us the name of the site you came from (for example instagram.com), never the full address. We only keep which group it falls in (Instagram, TikTok, X, WhatsApp, Facebook, im.center, direct or other) as a daily count per profile. We also count visits per country, as a daily total per profile, from the country Cloudflare reports for the visit; your IP address is not stored (legitimate interest: showing owners where their visitors come from).
- Site statistics: daily counts of visits per kind of page (home, a tag, the sign-up page, profiles), and of steps such as seeing the pay panel, starting a payment, sharing, a field that stopped the sign-up form and saving changes, split by browser type and by phone, tablet or computer. We also count how many visitors im.center has each day, as one total for the whole site. Each counts a visitor once a day, the same way as visits, and nothing that identifies anyone is kept. It shows how many visitors go on to create a profile and where they get stuck (legitimate interest: running and improving the service).
- Messages with boosts: the name you choose and your message are stored with the payment, checked automatically, emailed to the profile owner and shown in their dashboard, never on the profile (contract).
- Link cards and site icons: when an owner turns a link into a card, our server fetches the title and preview image of that page; for each link to a site that isn't a known platform, it also fetches that site's icon once. The site sees a request from Cloudflare, not from a visitor. We check these images, resize them with Cloudflare Images and keep copies (contract).
- Security: IP addresses are used transiently for rate limits and the human check (Cloudflare Turnstile) (legitimate interest).
- Reports: the reason and details you write, and a keyed hash of your IP address and browser to stop duplicate reports (legitimate interest).
4. Who processes data for us
- Cloudflare (Cloudflare, Inc., USA): hosting, database, file storage, content delivery, the human check (Turnstile), making link preview images (Browser Run) and resizing link card pictures and site icons (Cloudflare Images).
Data: IP addresses and request data of every visit, and everything we store: profiles, owner emails, payment and consent records, messages, reports. To make a link preview image, Browser Run receives the profile's public name, photo, rank and total.
Where: Cloudflare's global network; stored data mainly in the United States and the European Economic Area. Transfers outside the EU rely on the EU-US Data Privacy Framework where the provider is certified, otherwise on the European Commission's Standard Contractual Clauses.
Privacy policy · Data processing agreement - Stripe (Stripe Payments Europe, Limited, Ireland, with Stripe, LLC, USA): payments and fraud prevention (Radar).
Data: payment details, the payer's name, email, address and IP address as entered on Stripe Checkout, and, if a payment is disputed, the evidence described above.
Where: the United States and other countries where Stripe operates. Transfers outside the EU rely on the EU-US Data Privacy Framework where the provider is certified, otherwise on the European Commission's Standard Contractual Clauses.
Privacy policy · Data processing agreement
For some purposes Stripe is not our processor but an independent controller: fraud monitoring and prevention, preventing financial loss, meeting its legal and anti-money-laundering obligations, and improving its services. For that processing Stripe's own privacy policy applies. - Resend (Plus Five Five, Inc. (trading as Resend), USA): email delivery.
Data: the recipient's email address and the content of the emails we send.
Where: mainly the United States. Transfers outside the EU rely on the EU-US Data Privacy Framework where the provider is certified, otherwise on the European Commission's Standard Contractual Clauses.
Privacy policy · Data processing agreement - OpenAI (OpenAI Ireland Ltd, Ireland, with OpenAI OpCo, LLC, USA): automatic content moderation.
Data: profile text (name, handle, tagline, bio, link labels) and photos when a profile is created or edited, uploaded center backgrounds, the names and messages people leave with boosts, and the titles and images of link cards.
Where: the United States. Transfers outside the EU rely on the EU-US Data Privacy Framework where the provider is certified, otherwise on the European Commission's Standard Contractual Clauses.
Privacy policy · Data processing agreement
OpenAI's API data policy states that data sent to its API is not used to train its models, and that requests to the moderation endpoint we use are not retained for abuse monitoring. - Google Web Risk (Google Cloud Italy S.r.l., Italy, with Google LLC, USA): checking links against Google's lists of unsafe sites.
Data: the web addresses (URLs) added to profiles. No other personal data.
Where: Google's infrastructure, including the United States. Transfers outside the EU rely on the EU-US Data Privacy Framework where the provider is certified, otherwise on the European Commission's Standard Contractual Clauses.
Privacy policy · Data processing agreement
5. Cookies and local storage
Two cookies, only for profile owners, both scoped to our own API and lasting up to 30 days: a session cookie when you sign in with an emailed link, and, on the device where you create a profile, one naming the profiles made there, so that device can manage them before and after paying without an email. Your browser's local storage keeps your theme, view and sound choices, which profiles, kinds of page and steps you've already been counted for today, a profile you saved on that device but haven't paid for yet (its name, handle, tag and email, so you can finish paying later; removed once it's paid, or on your next visit after 48 hours), and, for signed-in owners, the name and photo shown on the "My profile" button. No advertising or analytics cookies.
6. How long we keep it
- Profiles that never went live (not paid for, no invite code): deleted after 48 hours.
- Live profiles: until the owner asks us to delete them (write to hello@im.center) or we remove them.
- Payment records, consents and dispute records: 10 years.
- Messages with boosts: with the payment record. Uploaded center backgrounds: until the owner chooses another background or the profile is hidden or removed. Link card copies: until the owner turns the card off or the profile is removed. Site icons: until no link of the profile points to that site any more, or the profile is removed.
- Link preview images: replaced ones are deleted 30 days after they are replaced; a hidden profile's image is deleted at once.
- Visit, visitor, click, source, country, page and step counts: daily totals with no personal data, kept for statistics.
- Email delivery log: 90 days. Daily rank history: 120 days. Sign-in links: they expire after 30 minutes (7 days for the one in the "you're live" email).
- Backups: deleted data can remain in backups for up to 30 days.
7. Your rights
You can ask for access, correction, deletion, restriction and portability, and object to processing based on legitimate interest, by writing to hello@im.center. Every email has a one-click unsubscribe link. You can also complain to a data protection authority; in Italy that is the Garante per la protezione dei dati personali.
8. Changes
When this policy changes, the new version is published here with its date. If a change matters to profile owners, we tell them by email before it applies.