This policy explains what personal data Babil collects about you, why, how long we keep it, who we share it with, and what you can do about it. It is drafted with the GDPR in mind. Contact details for the data controller are in the Imprint.
1. Who is responsible for your data
The data controller is Murmures โ SCOP SARL, the French cooperative that operates Babil (full details and contact information in the Imprint). We decide why and how personal data on this service is processed.
2. What we collect and why
Account data
When you sign up: your email address, a chosen username, a display name, and a password (stored only as a salted hash, never in plain text). Optionally: an avatar URL and a short bio.
Why: to create and authenticate your account. Legal basis: performance of the contract between you and Babil (Art. 6(1)(b) GDPR).
Content you publish
Posts, comments, reactions, direct messages, follows, bookmarks, hashtags. Anything you upload or write on the service.
Why: to run the service โ show your content to the audience you chose. Legal basis: performance of the contract.
Mentions
When another user writes @yourUsername in a post, comment or direct message, a mention record is stored and you receive a notification. You can disable this at any time from the Settings page โ with it off, you won't appear in mention suggestions and no mention notifications are sent to you. Existing mention records are kept as part of the original content.
Interaction data ("behavioural events")
To power the recommendation algorithm, Babil records what you do on the service: which posts you viewed, how long you looked at them, what you reacted to, what you scrolled past. This is the raw material the algorithm uses to build the signals you can see and adjust in the Your algorithm section.
Why: to deliver a personalised, transparent feed that you can inspect and control. Legal basis: our legitimate interest in operating the transparent, user-controlled recommendation algorithm that is the core of the service (Art. 6(1)(f) GDPR). You can object at any time (Art. 21), in two ways: switch to a purely chronological feed, which stops these signals being used to rank what you see (they are still recorded, so your transparency page stays complete), or use "Stop tracking my behavior" on your Portrait page, which deletes your recorded events and stops collection entirely.
Technical data
IP address, user-agent, timestamps, basic device information. We use this for security, abuse prevention and standard server logs.
Legal basis: our legitimate interest in keeping the service online and safe (Art. 6(1)(f) GDPR).
3. Embeddings and the algorithm
To recommend posts we turn text into numerical vectors ("embeddings"). Today this runs entirely on our own infrastructure using a self-hosted open-source model: the source text (your posts, your interactions) is not sent to any third-party embeddings provider. If that ever changes, we will update this policy and the sub-processor list first. See the sub-processors section below for the providers we do use.
4. What we do not collect
- We do not run third-party advertising or tracking pixels.
- We do not sell your personal data.
- We do not build a profile of you for use by advertisers, and we do not plan to introduce one.
5. Who we share data with (sub-processors)
We rely on a small number of service providers to run Babil. They process personal data on our behalf, under a data-processing agreement, only for the purposes listed:
- Hosting / VPS: OVH (France) hosts the backend, database and recommendation service.
- Media storage: Cloudflare R2 (Cloudflare, Inc., a US company; data stored in the EU), to store media you upload.
- legal.privacy.share.list.embeddings
- Email: Google Workspace (United States), for account-verification and security emails. As a US provider, this involves a transfer outside the EU/EEA โ see the international-transfers section below.
We keep this list of sub-processors and their locations current in the Imprint.
5b. Federation: sharing with the Fediverse
When federation is enabled, the content you publish publicly โ your posts, public replies, reactions and your public profile โ is delivered to remote servers on the Fediverse (the open network of services that speak the ActivityPub protocol) so that people there can follow and interact with you. Private messages are never federated. Federation is enabled by default, so that people who follow you from other servers actually receive your public content โ and you can turn it off for your account at any time; see the controls below.
These remote servers are operated by third parties we neither own nor control. Once your content reaches them, each one is an independent data controller: it sets its own retention, decides who can see what it received, and may be located outside the EU/EEA, where the safeguards we apply to our own sub-processors (Art. 46 GDPR) do not extend. We cannot guarantee that a remote server will delete content when you do.
Legal basis: our legitimate interest, and yours, in an open, interoperable social network (Art. 6(1)(f) GDPR). Because this is a legitimate-interest basis, you can object: you can disable federation for your account at any time from Settings, which stops new outbound federation of your content.
6. International transfers
Some sub-processors process data outside the EU/EEA โ in particular Google Workspace (United States), which handles our account-verification and security emails. Cloudflare and Sentry store our data in the EU but are US-headquartered companies, so a transfer to their US parent cannot be ruled out. In all these cases we rely on the European Commission's Standard Contractual Clauses or an equivalent adequacy mechanism under Art. 46 GDPR (such as the EUโUS Data Privacy Framework) to ensure an appropriate level of protection.
Separately, when federation is enabled, content you choose to share publicly may be delivered to remote ActivityPub servers located anywhere in the world, including outside the EU/EEA. These servers are independent controllers we do not select, and the Art. 46 safeguards above do not apply to them. See the federation section above and the user controls it links to.
6b. Remote users and federated profiles
When you interact with someone on another Fediverse server, Babil caches a limited copy of their public profile so we can render the interaction: their handle, display name, avatar, public key, and the public profile fields their server publishes (such as a short bio).
Source: this information comes from the person's home server, which publishes it as part of the ActivityPub protocol. We do not collect anything that their server does not make public.
Why: to display federated posts, replies and follows correctly on Babil. Legal basis: our legitimate interest in operating an interoperable service (Art. 6(1)(f) GDPR).
Retention: a cached remote profile is purged automatically once no local user follows that account and the cache has been stale for more than 90 days.
If you are a remote user and want the copy Babil holds about you corrected or removed sooner, write to the data-protection contact in the Imprint.
7. How long we keep it
- Account data: for as long as your account exists. If you delete your account, your personal profile data is erased immediately, in the same transaction โ and in any case within 30 days โ except where we are legally required to keep it longer.
- Content (posts, comments): hidden from everyone immediately when you delete it. The text remains in our database until you delete your account, at which point it is scrubbed (see the deletion section below); backup copies age out within 90 days.
- Interaction data: retained for the life of the account because the algorithm's transparency depends on it. You can export a full copy at any time from Settings โ Data, and deleting your account purges it.
- Technical logs: 30 days, unless a longer retention is needed for a security incident.
Deleting your account
You can delete your account at any time from Settings โ Danger zone โ Delete account. The action is final: there is no recovery window. Concretely, when you delete your account:
Removed immediately, in the same transaction:
- Your email address, display name, bio, avatar URL and social links are erased from your profile.
- Your password hash is destroyed; no future login can succeed.
- All your sessions are revoked (refresh tokens deleted on the server, browser cookie cleared).
- Your behavioural-event history (everything in Your algorithm) is deleted.
- Your reactions, follows, reposts, direct-message participation, notifications, search profiles, and personalised algorithm profile are deleted.
Self-deletion does not blacklist your email โ if you change your mind later you can register a new account with the same address. (Email blacklisting is reserved for accounts banned by a moderator for breach of the Terms of Service; in that case a one-way hash of the email is kept so the same address cannot re-register.)
Content you wrote:
- Your posts and comments are removed from the service and their text is erased from our database. Empty placeholder rows are kept so that replies and threads other people wrote don't break โ they carry no content, and the author is shown as "[deleted]".
- Direct messages you sent are removed from every participant's inbox when your account is deleted. Messages other participants sent in those conversations stay in their own inboxes.
Retained for legal reasons:
- Server-side technical logs (IP, user-agent, timestamps) for up to 30 days, longer if a security incident is being investigated.
- Encrypted database backups age out within 90 days; we cannot rewrite past backups, but a restore would re-apply the same deletion if it ever occurs.
When you delete your account, Babil sends a deletion request to every federated server known to have received your content. Babil cannot guarantee that remote servers honor it โ this is a structural limitation of the Fediverse, shared by every federated network.
8. Your rights
If you are in the EU/EEA (and equivalently in most other jurisdictions with data-protection law), you have the right to:
- Access your personal data โ you can export your full behavioural history from Settings at any time.
- Rectify inaccurate personal data.
- Erase your personal data ("right to be forgotten") โ account deletion does this for all the data Babil holds; the mechanics and the federation caveat are described in the deletion section above.
- Restrict or object to certain kinds of processing.
- Data portability โ receive your data in a machine-readable format (JSON export).
- Withdraw consent, where processing was based on consent, at any time.
- Lodge a complaint with a supervisory authority.
To exercise any of these, write to the contact email in the Imprint. We aim to respond within 30 days.
9. Security
We use industry-standard measures: passwords hashed with a strong algorithm, HTTPS in transit, refresh tokens stored as HttpOnly SameSite=Strict cookies and SHA-256 hashed at rest. We rotate refresh tokens on every use. No system is perfectly secure, and we will notify affected users of any personal-data breach in accordance with Art. 33โ34 GDPR.
10. Children
Babil is not intended for children below the age set in the Terms of Service. If you believe a child has given us personal data without appropriate consent, contact us and we will delete it.
11. Changes to this policy
If we make material changes, we will flag them in-app and update the "Last updated" date above. Non-material clarifications may be made without notice.