TLTE Civic Mail is designed to hold as little personal data as possible while still functioning as a real civic identity system. This page describes what we collect, why, and what you control.
What we collect
- Account: alias, hashed password, chosen locale, sign-up timestamp
- Recovery: the external email you provide, hashed backup codes, verification timestamps
- Optional profile: display name, bio, country, pronouns, generation, beliefs, tradition, and astrology fields you choose to share
- Operational: audit logs of sign-ins, password resets, and steward actions; IP addresses of recovery attempts and reports (for abuse prevention)
What we do not do
- Sell or rent your data to any third party
- Show ads or run behavioural tracking
- Read the contents of your inbox for advertising or profiling
Recovery emails
Your recovery email is only used to send you password-recovery codes and security notifications. It is never displayed publicly and never shared with other members. You may change or remove it any time from your profile.
Retention
Audit records are retained for as long as your account is active plus twelve months. Recovery attempt logs older than 30 days are aggregated and pseudonymised. Deleted accounts are purged from active tables within 30 days; pseudonymised audit rows may be preserved for legal integrity.
Your rights
You may access, correct, or delete your data from your profile. For a full export or to exercise other data-protection rights, write to stewards@tlte.cloud.
Security
Passwords are hashed using the underlying auth provider's industry-standard scheme and checked against known-breached-password lists. Backup codes are hashed at rest and shown to you only once at generation. All transport is TLS-encrypted.
Contact
Privacy questions and data-subject requests: stewards@tlte.cloud.