The Tribe

Privacy

Last updated 8 September 2026

Plain English first: we only ask for what we need to welcome you and help you, we never sell your data, and we run no advertising networks or third-party trackers. This page describes exactly what the site collects, why, how long we keep it, and the rights you have over it. It is written to match what the code actually does, not aspirations.

Who is responsible for your data

The Tribe is built and run by its founder, who chooses to stay anonymous. For data-protection purposes the controller is the founder team, operating as “The Tribe”. You can always reach a real person at admin@thetribe.cloud or on WhatsApp +971 58 157 9344.

Honest note: a named, registered legal entity is not yet in place. Forming one is planned. Until then the controller is the founder team behind The Tribe, contactable at the address above. We would rather tell you this plainly than name a company that does not exist yet.

What we collect, and why

Account data (when you create an account):

  • Name / display name: so a real person can greet you and so others can recognise you.
  • Email address: to sign you in, verify your account, reset your password, and reply to you.
  • Handle (@username): your public identity for your profile at /u/your-handle.
  • Date of birth: collected once at signup to confirm you are 18 or older (The Tribe is adults-only). It is stored privately, never shown publicly, and cannot be changed after signup.
  • Password: stored only as a salted scrypt hash; we never see or keep your actual password.

Profile data (optional, you choose what to add): a short bio, city, occupation, interests, links, and an avatar image. Avatars are re-encoded and stripped of EXIF/GPS metadata before they are stored.

Door forms (volunteer, athletes, careers, marriage, support, only what you submit): name, email, phone and WhatsApp number, postal/home address (optional), occupation, your reason for getting in touch, and a CV if you choose to upload one. Home address is always optional. CVs are stored in private storage that is not reachable from the public web.

Marriage / matchmaking (opt-in and firewalled): if (and only if) you open the marriage door, we store your marriage intent, who you seek, any notes you send with a “like”, matches, and blocks/reports. This data is kept separate from your social profile and is never shown on /u/, /members or in search. Your age here is derived from the date of birth you already gave; the site ignores any age typed into a form.

Content you post: posts, comments, discussion threads and replies, reactions/votes, community memberships, event RSVPs, and direct messages you send.

First-party analytics (only after you accept, see below): a 1×1 tracking pixel (/px.gif) and a random visitor id stored in your browser as tribe_vid, plus a per-visit session id. With these we record the page you viewed, the referring page, your browser’s user-agent string, and a best-effort bot flag, and a few product events (page views, and whether a door form was started or submitted). This is all first-party: it stays on our own server. There are no third-party analytics, no advertising pixels, and no cross-site trackers.

Server access logs: like virtually every website, our web server keeps short-lived access logs that include your IP address and request details, used only to keep the service running and to prevent abuse.

Our legal bases (GDPR Article 6)

  • Contract / your request: to create and run your account and to act on the door forms and applications you send us.
  • Consent: for the non-essential analytics pixel and visitor id (you opt in via the banner and can withdraw any time), and for the sensitive matchmaking data you choose to provide.
  • Legitimate interests: to keep the site secure, prevent spam and abuse, and operate the basic service. We keep this to the minimum needed.
  • Legal obligation / safety: to enforce the 18+ age floor and to remove and, where required, report illegal content.

Cookies & tracking

We use one essential cookie to keep you signed in, plus browser storage for your theme choice and your privacy choice. The analytics pixel and tribe_vid visitor id are non-essential and load only after you accept. Full detail, including how to change your choice, is on our Cookies & tracking page.

How long we keep it

  • Account & profile, applications, CVs, messages, posts: kept while your account is active, and removed when you delete your account (or ask us to).
  • Analytics (visits & events): kept in aggregate to understand how the site is used; on account deletion any link to your user id is removed so the rows are no longer tied to you.
  • Backups: encrypted off-site backups are kept on a rotating schedule (7 daily + 4 weekly) and then overwritten, so deleted data can persist in backups for up to about a month before it rotates out.
  • Server access logs: short-lived, kept only as long as needed for security and troubleshooting.

Who we share it with (sub-processors)

We do not sell your data and we do not share it for advertising. We rely on a small number of infrastructure providers to run the service:

  • Hostinger: hosts the server, database, and email in Frankfurt, Germany (EU).
  • Hetzner: stores our encrypted off-site backups (Germany, EU).
  • Email delivery: account and notification emails are sent from our own admin@thetribe.cloud mail server.

If you contact us by WhatsApp, that conversation is handled by WhatsApp/Meta under their own terms.

Where your data is processed

Our servers and backups are located in the European Union (Germany). If you use The Tribe from outside the European Economic Area, your data is transferred to and processed in the EU, which applies strong data-protection standards.

Your rights

Wherever you live, we aim to honour these rights:

  • Access: ask what we hold about you.
  • Portability / export: download your own data as JSON from Settings, or via the /api/me/export endpoint when signed in.
  • Rectification: correct your profile and account details yourself in Settings.
  • Erasure: delete your account (and its data) yourself in Settings, or by emailing us.
  • Restriction / objection: in particular, decline the analytics pixel in the consent banner, or clear your choice at any time.
  • Withdraw consent: you can change your analytics choice whenever you like.
  • Complain: you have the right to lodge a complaint with your local data-protection supervisory authority.

How to exercise your rights

Most of this is self-serve: sign in and open Settings to export your data, edit your profile, or delete your account, and use the consent banner to accept or decline analytics. Or email admin@thetribe.cloud from the address you signed up with and a real person will help, usually within a few days.

Children

The Tribe is an adults-only community. You must be 18 or older to use it. Nothing here is designed for or directed at children.

How we protect your data

Passwords are stored only as salted scrypt hashes. Your session uses an HttpOnly, Secure, SameSite cookie. The whole site is served over TLS with HSTS. Uploaded CVs are stored outside the public web root, and uploaded images are re-encoded with EXIF/GPS metadata stripped.

Changes to this policy

If we change what we collect or how we use it, we will update this page and its “last updated” date. Material changes will be made clear.

Contact

admin@thetribe.cloud · WhatsApp +971 58 157 9344.

← Back to The Tribe