Privacy & Data Retention Policy

We Drew Art. is a collaborative art installation. This document describes what data we collect, why, how it is stored on your device, and how you can exercise your rights under the GDPR.

Data Controller

We Drew Art. is the data controller for personal data processed through the public drawing experience.

For privacy requests and questions about this policy, contact us at privacy@wedrew.art.

What We Collect

Session data

  • A hashed fingerprint derived from your IP address, user agent, screen resolution, and timezone offset at session creation. The raw IP address is never stored in our database. This hash cannot be reversed to recover your IP address but may be consistent across sessions from the same device and network.
  • Your country (derived from IP at session creation via hosting headers, then the IP is discarded from our records).
  • Drawing tool preference and activity timestamps.
  • A session token stored in your browser so you can continue drawing and submit work.

Artwork data

  • Stroke data (normalized coordinates, colors, tools) for cells you draw in.
  • Cell snapshots (PNG images) generated from your strokes upon submission or expiry.
  • Crossing metadata describing how your artwork connects to neighbouring cells.
  • An optional contributor pseudnonym if you choose to provide one when submitting (for public credit). This is voluntary.

Event logs

  • Append-only technical events (stroke start/end, undo, submit, abandon) for quality analysis and abuse prevention.

Website analytics

We use Cloudflare Web Analytics to understand aggregate traffic and page performance (for example page views, Core Web Vitals, and country-level breakdowns). Cloudflare states that this product does not use cookies, localStorage, or fingerprinting for analytics purposes. IP addresses may be processed transiently at the edge for geolocation but are not stored for analytics profiling.

If our domain is proxied through Cloudflare, Cloudflare may also process standard edge request logs and set strictly necessary security cookies (such as __cf_bm or cf_clearance) to protect the site from bots and abuse. These are not used for advertising or cross-site tracking.

Cookies and Browser Storage

We do not use advertising cookies or third-party marketing trackers.

StoragePurposeConsent required?
localStorage session tokenKeep you signed in to your anonymous drawing sessionNo; strictly necessary for the service you requested
Cloudflare Web Analytics beaconAggregate, privacy-oriented site metricsNo; cookieless; no client-side identifiers stored
Cloudflare security cookies (if proxied)Bot and abuse protectionNo; strictly necessary for security

We do not show a cookie consent banner because we do not use non-essential tracking cookies. You can still clear site data at any time through your browser settings, though doing so will end your current session.

What We Do Not Collect

  • Raw IP addresses in our application database (IP is used only transiently to compute the fingerprint hash and country, and for rate limiting at the edge).
  • Email addresses or account credentials for the public drawing experience (sessions are anonymous).
  • Precise geolocation beyond country level.
  • Cross-site behavioural profiles or ad targeting data.

Why We Process Data

PurposeData involvedLegal basis
Operating the collaborative drawing experienceSession token, strokes, snapshots, crossingsPerformance of a service you choose to use
Abuse prevention and rate limitingFingerprint hash, country, event logs, IP (transient)Legitimate interest in keeping the installation fair and available
Optional public credit on submissionContributor nameConsent — only collected if you enter it and submit
Aggregate site analytics and performancePage views, Web Vitals, country (via Cloudflare)Legitimate interest in understanding how the site is used and improving performance
Long-term gallery datasetAnonymised stroke data and exportsLegitimate interest in preserving and studying the collaborative artwork

Retention

  • Active session metadata: Until the session expires or you request erasure
  • Completed cell strokes: Indefinitely (anonymised artwork for the gallery)
  • Event logs: 24 months
  • Closed canvas exports: Indefinitely (public gallery)
  • Optional contributor name: Retained with the submitted cell for as long as the artwork is published
  • Cloudflare analytics: Per Cloudflare's retention schedule for the analytics product in use

Your Rights

You may request erasure of your session data at any time.

This nulls your fingerprint and country on the session record. Your strokes are retained because they are not linked to identifiable information after erasure and are required for artwork integrity and the collaborative installation.

To exercise other rights (access, rectification, portability, restriction, objection), or to withdraw consent for an optional contributor pseudonym, contact [privacy@wedrew.art](mailto:privacy@wedrew.art).

Automated ProcessingA

We may use automated checks (together with human review) to detect abuse, spam, or content that violates our Code of Conduct. Repeated violations may result in a session being blocked from further contributions.

Data Processors

We use the following service providers to operate the site. They process data on our instructions and under appropriate agreements:

  • Supabase (EU region): database, authentication, realtime
  • Vercel: application hosting
  • Cloudflare: Web Analytics, CDN/security (when proxied), and R2 object storage for images
  • Upstash: rate limiting

Some processors may process data outside the EU/EEA (for example in the United States).

Changes

We will update this document when our data practices change. Last updated: July 2026.