PRIVACY POLICY
This site is a directory of Fake Rare Pepe artwork. It runs no analytics, no advertising, and no tracking cookies. This page explains the little data that does move, and what rights you have over it under the GDPR.
Who is responsible
The controller for the processing described here is [CONTROLLER_LEGAL_NAME], [ADDRESS], contactable at [PRIVACY_CONTACT_EMAIL].
// The contact details shown elsewhere on this site are a joke and are not a route to the controller.
No Data Protection Officer has been appointed; the site does not carry out large-scale or systematic monitoring that would require one.
What we collect
Browsing this site does not require an account and does not build a profile of you.
- Server logs. Our hosting provider records the usual request data — IP address, timestamp, requested URL, user agent — to serve pages and to detect abuse.
- Theme preference. Choosing light or dark stores the value
themein your browser's local storage. It never leaves your device and is not read by us. - Administrator sign-in. If you sign in at
/loginwith an Arweave wallet, we store a signed session cookie namedfr_sessioncontaining your wallet address and an expiry. This only happens after you deliberately sign a challenge. - Contact form. The form on the home page is not connected to any backend. Nothing you type into it is transmitted or stored anywhere.
Cookies and local storage
We set no advertising, analytics or profiling cookies, so no consent banner is required. Only two items are ever written:
fr_session— strictly necessary. HttpOnly, SameSite=Lax, cryptographically signed, expires after 7 days. Set only when an administrator signs in, never for ordinary visitors.theme— a local storage entry holding your light/dark choice. Functional, set only when you use the toggle, and removable by clearing site data.
Third parties that see your IP address
Some content is loaded directly from other servers. Your browser contacts them itself, which necessarily reveals your IP address, user agent and referring page to them. We do not control what they log.
fakeraredirectory.comandarweave.net— card artwork shown in the gallery.trisha.hsd.services— the radio audio stream, contacted only when you start playback.brooklyn.hsd.services— the events timeline data on the history page.arweave.app— the wallet connector, contacted only on the administrator sign-in page.
Links to sites such as xchain.io are ordinary links: nothing is requested from them until you click.
// Fonts are served from this site, not from a font CDN, so no request is made to a third party to render text.
Why we are allowed to do this
- Legitimate interests (Art. 6(1)(f)) — serving pages, keeping the site available, and protecting it from abuse. Server logs and the third-party content above rest on this basis.
- Contract / pre-contract (Art. 6(1)(b)) — maintaining an administrator session for people authorised to edit the directory.
- Consent (Art. 6(1)(a)) — where you actively choose something, such as starting the radio stream. You can withdraw it by stopping playback.
How long we keep it
- Server logs: retained by our host for [RETENTION_PERIOD], then deleted.
- Administrator sessions: 7 days, or immediately when you sign out or your wallet is removed from the authorised list.
- Theme preference: until you clear your browser storage.
Your rights
Where we process your personal data you may request access, rectification, erasure, restriction, portability, and you may object to processing based on legitimate interests. Write to [PRIVACY_CONTACT_EMAIL].
You also have the right to complain to a supervisory authority in the EU or EEA country where you live or work.
// In practice we hold almost nothing that identifies you. If you have not signed in as an administrator, we are unlikely to be able to link any record to you, and we will not collect extra data purely to try.
Transfers, security and children
Depending on where our host and the services above operate, data may be processed outside the EEA. Where that happens we rely on the safeguards those providers put in place. Hosting is provided by [HOSTING_PROVIDER].
Traffic is served over HTTPS. Administrator access is proven by wallet signature — we never ask for, receive, or store a password, seed phrase or private key. No one operating this site will ever ask you for a seed phrase.
This site is not directed at children under 16.
Changes
If this policy changes materially we will update the date at the top of this page. Continuing to use the site after a change means the revised policy applies.