Privacy policy.Plain words, no tricks.
What mysociale.net collects, why, for how long, and how you stay in control of your data.
Last updated September 29, 2026
1. Who we are
mysociale.net is the website of Sociale, a community chat room on xat.com (xat.com/Sociale) run by a volunteer Italian staff team. Sociale is not operated by, or affiliated with, the xat company.
The data controller is mysociale.net. You can reach us for anything about your data through the contact form — choose any topic and write “Privacy” in your message.
2. What data we collect
- Account (only if you register): username, email address, password (stored only as an irreversible argon2id hash — we never see it), and optionally your xat ID, display name, a short bio and a profile picture. We record when you accepted the room rules and this policy, and whether you want event news by email.
- Log in with Google or Discord (if you choose it): your account ID at that service, your email address and public name.
- Sessions: when you log in we store a session with its creation and expiry time, your IP address and browser type, to keep you logged in and spot abuse.
- Log-in history and security: for each log-in attempt to your account we record date, IP address, browser and whether it succeeded, so you can check it in “My account → Login & security” and we can stop attacks. If you turn on two-step verification we store the secret key (encrypted) and your backup codes (only as irreversible hashes).
- Privacy choices, followers and blocks: who can see your profile (public, members only, private), which details you show, the members you follow, who follows you, follow requests and the members you blocked.
- Notifications, Respect, achievements and birthday: the notifications we show you on the site and whether you saw or opened them, so the staff can see how many members read an announcement (they are deleted with your account), the Respect you give and receive (one a day, the count is public on your profile), the achievements you unlock, and — only if you add it — your birthday as day and month (no year), used to show a badge and give you a gift on that day.
- Wall, private messages and support: your wall posts (text and an optional photo, re-encoded without location data) are checked by the staff and, once approved, shown on your profile with the same visibility as the rest of your profile. Private messages can be exchanged only between members who follow each other; they are stored encrypted and the staff does not read them, unless you report a message: then its text is copied into your support request. Support requests (what you write and the staff’s answers) are visible only to you and to the staff who handle them. All of this is deleted with your account and included in your data download.
- Consents: your choices about emails (events and giveaways, reminders, news from Sociale), with the date and IP address of each change, so we can prove your consent.
- Sociale Card: if you request the card, we store the xat name and ID you give us (checked by the staff) and your request, the actions that earn XP (check-ins, quiz answers, poll votes, comments, events joined or attended, news read, approved ideas, friends invited, XP given by the staff) with date and result, and the rewards you request. Your level, XP and Super Powers are read from MewBots. If you ask to move your XP to a new xat account, we store the request (old and new xat name and ID, your reason, the staff’s decision) and send the two IDs to MewBots, which moves the XP only after an admin approves.
- Daily missions: your answer to the quiz of the day and your vote in the poll of the day. Poll results are shown only as totals, never with names.
- Comments: the comments you write under news and events, with date and time. They are public, with your username and picture. The staff can hide or delete comments that break the room rules.
- Event ideas: the ideas you send on the ideas page. If the staff approves an idea, its title, text and your username become public.
- Invite a friend: your personal invite code and, if someone signs up with it, which account invited them (to give the XP to the right person). The person who invited you can see your username, whether your profile basics are complete (photo, bio, country, language) and whether they received the XP. To stop fake accounts we compare the IP address used at sign-up with the inviter’s recent log-in addresses; if they match, a staff member checks the invite before any XP is given.
- Profile customisation (all optional): headline, country, languages, interests, links to your social profiles, background, colour, photo frame and the looks you unlock (title, name colour, card design, showcase and favourite event). They are public on your profile, like your badges (calculated from your activity: events, ideas, invites, streak) and, if you leave the option on, your Sociale Card level and tier.
- Events: the events you join with “I’m in!”. Your username and profile picture appear in the event’s public list of participants.
- Contact form: the name and email you enter, the topic and message, your IP address and browser type (to fight spam) and, if you are logged in, your account.
- Public profile: your username, display name, bio, picture, xat ID, the optional details above, your activity numbers and joined events are visible at mysociale.net/u/your-username. If you are part of the room staff, your rank is shown too. Your email is never public.
- Technical data: like every website, our servers log requests (IP address, date and time, page, browser) for security and troubleshooting.
- Statistics: only if you allow them in the cookie banner (see the cookie policy).
We do not sell your data, we do not show ads and we do not build advertising profiles.
3. Why we use it (legal bases)
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Creating and running your account, profile, event sign-ups and Sociale Card | Contract — providing the service you asked for (6.1.b) |
| Answering your messages and support requests | Your request / our legitimate interest in replying (6.1.b, 6.1.f) |
| Your wall, private messages between friends, follows, Respect, achievements and notifications | Contract — the community features you choose to use (6.1.b) |
| Checking wall posts, comments and ideas before they are public, and handling reports | Legitimate interest in keeping the community safe and in line with the room rules (6.1.f) |
| Counting how many members saw or opened an announcement or the What’s new guide (and anonymous totals for visitors) | Legitimate interest in knowing if important news reaches members (6.1.f) |
| Security, preventing spam, bots and abuse (incl. the “are you human?” check), server logs, backups | Legitimate interest in keeping the site and community safe (6.1.f) |
| Event news by email | Your consent, which you can withdraw in “My account” (6.1.a) |
| Loading the xat chat and optional statistics | Your consent via the cookie banner (6.1.a) |
| Keeping records when the law requires it | Legal obligation (6.1.c) |
4. The xat chat and xat passwords
The chat room on our pages is an embedded widget served by xat.com. When it loads (only with your consent, or when you click “Load the chat room”), xat receives your IP address and browser data and may set its own cookies. What you write in the chat is processed by xat as an independent controller under xat’s own privacy policy and terms (published on xat.com), not by us.
Your mysociale.net account is separate from your xat account. We never ask for your xat password: never use it on mysociale.net or anywhere outside xat.com. The xat ID you may add to your profile is a public number used for giveaways.
5. Who else handles the data
We use a small number of providers that process data on our behalf, under their data-processing terms:
- Hetzner Online GmbH (Germany) — hosts our servers and database in its Helsinki, Finland data centre (EU).
- Cloudflare, Inc. — delivers the site and protects it from attacks (DNS, CDN, firewall, bot protection); every request passes through its network. On the log in, sign-up, comment, event idea and contact forms, Cloudflare Turnstile checks that you are human by looking at technical signals from your browser (no tracking cookies, no ads).
- MewBots (the bot of the Sociale room) — only if your Sociale Card is active: our server sends it your xat user ID and the XP to credit for each action, and reads your level and XP.
- Google and Discord — only if you choose to log in with them, and Google Analytics / Google Tag Manager only if you allow statistics.
Staff members see account data only as needed to run the community: moderators and editors check wall posts, comments and ideas; admins answer support requests and contact messages. Nobody on the staff reads private messages, except a message you report, which is copied into your support request. We may disclose data to authorities when required by law.
6. Transfers outside the EU
Our servers are in the EU. Cloudflare, Google, Discord and xat may process data in the United States or other countries. Where that happens, transfers rely on the EU-US Data Privacy Framework and/or the European Commission’s Standard Contractual Clauses.
7. How long we keep it
- Account and profile: until you delete your account (“My account” → Delete my account), which erases your profile, sessions and event sign-ups immediately. Accounts inactive for 3 years may be deleted.
- Comments, ideas, quiz answers and poll votes: until you delete them or your account (deleting the account deletes them too; approved ideas stay public without your name).
- Log-in history: 12 months, then deleted. Consent records: as long as the account exists and up to 24 months after a consent is withdrawn.
- Sessions: 24 hours, or 30 days with “Remember me”; expired sessions are deleted automatically.
- Contact messages: up to 24 months, then deleted. Support requests: until you delete your account; closed requests are deleted 24 months after the last message.
- Wall posts: until you delete them or your account; posts that were not approved are deleted after 90 days. Private messages: until you or the other person delete the account.
- Notifications: until you delete your account. Announcement statistics for visitors are anonymous totals, with no personal data.
- Server logs: rotated automatically when they reach a fixed size, so older entries are overwritten — at current traffic, after a few weeks to a few months.
- Backups: database backups, stored on our EU server, are kept for up to 6 months, then overwritten; deleted data disappears from them within that time.
8. Security
The site uses HTTPS everywhere, passwords are hashed with argon2id, the database is not reachable from the internet, and access to the servers is restricted to the administrators. No system is perfect: if a breach affecting your data happens, we will inform you and the authority as the GDPR requires.
9. Your rights
Under the GDPR (articles 15–22) you can ask to access your data, correct it, delete it, restrict or object to its use, receive it in a portable format, and withdraw consent at any time (without affecting what happened before). Most of this you can do yourself in My account (for example “My data” lets you download everything in one file, and “Email & consents” lets you change each consent); for everything else use the contact form. We reply within one month.
You can also lodge a complaint with a data protection authority — in Italy the Garante per la protezione dei dati personali, or the authority where you live.
10. Minors
You must be at least 14 years old (or the minimum age for digital consent in your country, if higher) to create an account. If you are younger, ask a parent or guardian. If we learn that an account belongs to a child below that age, we delete it.
11. Changes
We update this policy when the site changes. The date at the top shows the latest version; if a change is important, we will tell registered users.