diff --git a/html/priv.ejs b/html/priv.ejs
index 05146e9c..d2b19524 100644
--- a/html/priv.ejs
+++ b/html/priv.ejs
@@ -411,14 +411,20 @@
When you request any resource from the Poke API (for example: thumbnails, API endpoint) information about the request may be logged.
- Information about a request is limited to:
+
+ Information logged per request
+
+ The information recorded for each API or resource request is strictly limited to the following items — and nothing else:
+
- the time the request was made
- the status code of the response
- the method of the request
- the requested URL
- - how long it took to complete the request.
+ - how long it took to complete the request
+
+
No identifying information is logged, such as the visitor’s cookie, user-agent, or IP address.
@@ -439,26 +445,58 @@
-
- Legal Bases for Processing (GDPR)
-
- - Legitimate interests: Running Poke smoothly while collecting exactly zero personal data.
- - Consent: If we ever invent an optional feature that needs info, we’ll ask. But right now? There’s nothing to consent to.
- - Legal obligation: Even if someone waves a fancy piece of paper at us, we literally have nothing personal to hand over. Empty pockets.
-
-
+
+ Legal Bases for Processing (GDPR / EU Law)
+
+ The Poke Project and its primary instance (poketube.fun) operate under the jurisdiction of the
+ European Union and comply with the principles of the
+ General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679).
+ The project’s hosting structure is based in Germany, where data protection is taken seriously.
+
+
+ -
+ Legitimate interest: Operating the Poke service safely and efficiently while collecting no personal data whatsoever.
+
+ -
+ Consent: If one day we add an optional feature that needs personal information, you’ll be clearly asked — not tricked — before it’s ever processed.
+ Currently, no such data collection exists.
+
+ -
+ Legal obligation: Even if an authority asks for user data, there’s nothing to hand over.
+ We don’t store IPs, cookies, or user identities — so there’s nothing to surrender under German or EU law.
+
+
+
+ This section is here for compliance transparency only — Poke simply doesn’t process or retain personal data in the first place.
+
+
+
+
+
+ Your Privacy Rights
+
+ Because Poke doesn’t collect or store personal info, there’s really nothing about you that we can give, sell, or lose.
+ You won’t need to ask for “export my data” or “delete my profile” — we just don’t have any of it.
+
+
+ Poke accounts don’t require your name, email, or any identifying detail — you literally can’t add them even if you tried.
+
+
+ But outside Poke, you *do* have rights and tools to protect your privacy. Here are a few ideas:
+
+
+ - Switch your search engine from a tracker-heavy one (like Google) to a privacy-respecting one — for example, DuckDuckGo, which doesn’t track your search history and doesn’t log your activity.
+ - Use privacy-oriented browsers or extensions that block trackers, fingerprinting, and unwanted scripts.
+ - Enable HTTPS everywhere (many sites support it), avoid untrusted WiFi, and keep your software up to date.
+ - Review your device permissions (location, microphone, camera), disable or restrict ones you don’t need.
+ - Use VPNs or encrypted services if you want an extra layer of anonymity (especially on public networks).
+ - Opt out of ad tracking and analytics where possible — many companies provide “do not track” or preference settings.
+
+
+ These steps won’t make you invisible, but they do shift the balance back toward u!!!!!
+
+
-
-
- Your Privacy Rights
-
- Since Poke doesn’t collect or store personal data, there’s basically nothing for us to give, sell, or lose about you.
- You don’t have to worry about “export my data” or “delete my profile” requests because we don’t have anything on you in the first place.
-
-
- Poke Accounts don’t require an email, name, or any other identifying info — and there’s no way to add that kind of data even if you wanted to.
-
-