Privacy

Effective 5 Sep 2026 · operator: Createrra s.r.o., Senec, Slovakia · contact: admin@inocracy.com

The core: anonymity by architecture

Inocracy is built so that your group never sees who you are. Identifying data (e-mail addresses, check-in days, payments) lives in a separate "vault". For every group you join, the vault mints a random pseudonym — and only that pseudonym ever appears on your ideas and judgments. Pseudonyms from different groups cannot be linked to each other. The vault never sees content; the app never sees identity.

What we store

  • E-mail addresses you verify — for signing in and proving group membership.
  • Place check-in days. When you check in at a place, your position is verified inside your own browser and is never sent or stored. The vault records only that your account was at that place on that day — no time, no position — and uses it for one thing: telling a visitor from a regular (three separate days within 30). These records are deleted after 60 days. Neither the place's creator nor other members ever see who checked in.
  • Credits and payments. Who bought credits and who paid for a topic. Card details are handled by Stripe; we keep only the payment reference, the amount and the invoice.
  • Content — ideas, judgments, and topics, always under a pseudonym only.

Accountability

The one exception to anonymity is a topic's creator: the vault records who opened and paid for a topic, and that person is accountable for the wording of that topic. They are not accountable for the ideas and judgments other members contribute — those stay anonymous, and even to us their author is only a pseudonym.

Automated content screen

When an idea or topic is submitted, its text is checked in two ways:

  • Similarity to existing ideas is computed by a small language model running on our own server. Nothing leaves our infrastructure for this.
  • Content rules are judged by a model from Anthropic through its API. Only the text of the idea or topic and the titles of a few of the most similar existing ideas in the same topic are sent — never your identity, e-mail, pseudonym or IP address. The model decides one thing: whether the text breaks the rules (hate speech, incitement to violence, doxxing, spam, an illegal purpose) or is a near-copy of an existing idea. It does not judge quality or opinion, does not profile users, and remembers nothing between checks. Under Anthropic's API terms this data is not used to train models.

The "anonymize my wording" feature runs only when you press its button: the text is rewritten into a neutral style, the original draft is stored nowhere, and only what you approve is published.

Cookies and traffic measurement

We use a single, strictly necessary cookie that keeps you signed in. No tracking or advertising cookies — and therefore no cookie banner. Traffic is measured with Plausible (EU), a cookieless analytics tool that stores aggregate visit counts only, never personal data.

Where and who

All data is stored in the EU (server in Germany). E-mail is sent via Websupport (SK). Payments are processed by Stripe. The content-rules check runs through Anthropic's API as described above.

Your rights

You have the right to access, correct, and erase your data (GDPR). Erasure destroys all your identifying data; the group's anonymous contributions remain — with no link to you whatsoever. Write to admin@inocracy.com.