Privacy & Data Retention Policy
We Drew Art. is a collaborative art installation. This document describes what data we collect, why, how it is stored on your device, and how you can exercise your rights under the GDPR.
Data Controller
We Drew Art. is the data controller for personal data processed through the public drawing experience.
For privacy requests and questions about this policy, contact us at privacy@wedrew.art.
What We Collect
Session data
- A hashed fingerprint derived from your IP address, user agent, screen resolution, and timezone offset at session creation. The raw IP address is never stored in our database. This hash cannot be reversed to recover your IP address but may be consistent across sessions from the same device and network.
- Your country (derived from IP at session creation via hosting headers, then the IP is discarded from our records).
- Drawing tool preference and activity timestamps.
- A session token stored in your browser so you can continue drawing and submit work.
Artwork data
- Stroke data (normalized coordinates, colors, tools) for cells you draw in.
- Cell snapshots (PNG images) generated from your strokes upon submission or expiry.
- Crossing metadata describing how your artwork connects to neighbouring cells.
- An optional contributor pseudnonym if you choose to provide one when submitting (for public credit). This is voluntary.
Event logs
- Append-only technical events (stroke start/end, undo, submit, abandon) for quality analysis and abuse prevention.
Website analytics
We use Cloudflare Web Analytics to understand aggregate traffic and page performance (for example page views, Core Web Vitals, and country-level breakdowns). Cloudflare states that this product does not use cookies, localStorage, or fingerprinting for analytics purposes. IP addresses may be processed transiently at the edge for geolocation but are not stored for analytics profiling.
If our domain is proxied through Cloudflare, Cloudflare may also process standard edge request logs and set strictly necessary security cookies (such as __cf_bm or cf_clearance) to protect the site from bots and abuse. These are not used for advertising or cross-site tracking.
Cookies and Browser Storage
We do not use advertising cookies or third-party marketing trackers.
| Storage | Purpose | Consent required? |
|---|---|---|
localStorage session token | Keep you signed in to your anonymous drawing session | No; strictly necessary for the service you requested |
| Cloudflare Web Analytics beacon | Aggregate, privacy-oriented site metrics | No; cookieless; no client-side identifiers stored |
| Cloudflare security cookies (if proxied) | Bot and abuse protection | No; strictly necessary for security |
We do not show a cookie consent banner because we do not use non-essential tracking cookies. You can still clear site data at any time through your browser settings, though doing so will end your current session.
What We Do Not Collect
- Raw IP addresses in our application database (IP is used only transiently to compute the fingerprint hash and country, and for rate limiting at the edge).
- Email addresses or account credentials for the public drawing experience (sessions are anonymous).
- Precise geolocation beyond country level.
- Cross-site behavioural profiles or ad targeting data.
Why We Process Data
| Purpose | Data involved | Legal basis |
|---|---|---|
| Operating the collaborative drawing experience | Session token, strokes, snapshots, crossings | Performance of a service you choose to use |
| Abuse prevention and rate limiting | Fingerprint hash, country, event logs, IP (transient) | Legitimate interest in keeping the installation fair and available |
| Optional public credit on submission | Contributor name | Consent — only collected if you enter it and submit |
| Aggregate site analytics and performance | Page views, Web Vitals, country (via Cloudflare) | Legitimate interest in understanding how the site is used and improving performance |
| Long-term gallery dataset | Anonymised stroke data and exports | Legitimate interest in preserving and studying the collaborative artwork |
Retention
- Active session metadata: Until the session expires or you request erasure
- Completed cell strokes: Indefinitely (anonymised artwork for the gallery)
- Event logs: 24 months
- Closed canvas exports: Indefinitely (public gallery)
- Optional contributor name: Retained with the submitted cell for as long as the artwork is published
- Cloudflare analytics: Per Cloudflare's retention schedule for the analytics product in use
Your Rights
You may request erasure of your session data at any time.
This nulls your fingerprint and country on the session record. Your strokes are retained because they are not linked to identifiable information after erasure and are required for artwork integrity and the collaborative installation.
To exercise other rights (access, rectification, portability, restriction, objection), or to withdraw consent for an optional contributor pseudonym, contact [privacy@wedrew.art](mailto:privacy@wedrew.art).
Automated ProcessingA
We may use automated checks (together with human review) to detect abuse, spam, or content that violates our Code of Conduct. Repeated violations may result in a session being blocked from further contributions.
Data Processors
We use the following service providers to operate the site. They process data on our instructions and under appropriate agreements:
- Supabase (EU region): database, authentication, realtime
- Vercel: application hosting
- Cloudflare: Web Analytics, CDN/security (when proxied), and R2 object storage for images
- Upstash: rate limiting
Some processors may process data outside the EU/EEA (for example in the United States).
Changes
We will update this document when our data practices change. Last updated: July 2026.