claudehohl / Stikked

An advanced and beautiful pastebin written in PHP
991 stars 219 forks source link

GDPR Privacy Policy #487

Closed gschwepp closed 6 years ago

gschwepp commented 6 years ago

Hey,

I didn't find any issue concerning the upcoming General Data Protection Regulation (GDPR https://www.eugdpr.org/) so I would like to start a conversation what is needed, to comply the regulations . This issue will affect most websites.

I an 'privacy policy' page needs to be added to the seems, this must have some customizable text. Also there must be one of the anoying cookie notifications to inform the user that cookies are used and what they are used for (perferable an customizeable text as well).

Are any user-related information saved in a paste, except the username? Does anything of stikked like the captcha (or so) rely on external services that could gather information?

I am sorry to start this discussion and not being able to contribute code myself. I am currently very short on time.

Cheers

claudehohl commented 6 years ago

Also there must be one of the anoying cookie notifications to inform the user that cookies are used and what they are used for (perferable an customizeable text as well).

In no way am I going to add that annoying cookie-bullshit-notification. It's a sign of no-balls and "attorneys, please don't hurt us"-behaviour that just pisses off users.

Users are free to enter or omit any information and use the pastebin for whatever they see fit. If you use the Google captcha, then of course Google will collect data from it. That decision is up to everyone who hosts an instance of Stikked. (There is a non-Google captcha too).

Also you could create a privacy policy page, although it needs a bit messing with the source code (create another page like "api", including routes etc). I won't add it in the near future, since "conforming with laws" has the lowest priority on my list. Especially when the laws are annoying and useless.

gschwepp commented 6 years ago

I just wanted to bring this topic to your attention. You stated a clear position, thats fine for me.

I think we will run into a wave a attorneys trying to squeeze all the money they can get out of the GDPR. So getting some awareness out there isn't too bad.

Cheers