PebblesBeta

Last updated July 27, 2026

Privacy Policy

Pebbles is an early-stage, free beta run by a solo developer. This policy explains what the current product collects and how that information is handled.

1. Information Pebbles collects

If you create or manage a Pebble, Pebbles collects the email address used for your account. If you sign in with Google, Google and Supabase process the information needed to authenticate you.

When you participate, Pebbles stores an internal account or session identifier, your membership in that Pebble, a generated alias, and when you joined. It also stores the content and activity you choose to create, including prompts, submissions, comments, replies, votes, comment reactions, timestamps, and moderation status.

Discussion pages use temporary Supabase Realtime presence data to count active viewers. Pebbles does not display viewer identities, and presence is not stored as discussion history.

Pebbles uses browser storage to maintain sessions and remember temporary product state, such as drafts and reading position. The application does not currently set its own analytics cookies.

Pebbles does not store IP addresses or device identifiers in its primary application database. Infrastructure and authentication providers may process routine technical information, including IP addresses, browser information, and request data, when delivering and securing their services.

2. How the information is used

Information is used to authenticate organizers, keep participants in the correct Pebbles, generate stable aliases, save contributions, show voting and discussion activity, support moderation, and operate and secure the service.

Pebbles does not currently use advertising or third-party analytics, and it does not sell personal information.

3. Anonymous participation and its limitations

Participant-facing pages use a generated adjective-and-animal alias, such as “Curious Otter.” Other participants are not shown your real name, email address, or Google account.

This is pseudonymous participation, not complete anonymity. Your alias and activity are connected internally to an account or session identifier. Pebbles’ service operator may access internal identifiers when necessary to operate, secure, or troubleshoot the service. Organizers can see participant aliases, contributions, and moderation information available through the product. Technical service providers may also process connection information.

Avoid sharing identifying, confidential, or sensitive information in submissions or discussions if you do not want other people with access to the Pebble to see it.

4. Who can access discussion content

An active Pebble is link-accessible. Anyone who receives a valid Pebble link may be able to join and access the content allowed by that Pebble’s participation rules. Links can be forwarded, so treat them as invitations rather than private passwords.

When an organizer closes a Pebble, new participants cannot join, but people who already joined may continue to review and participate. The content available to participants depends on the type and status of the Pebble.

Organizers can see submissions, discussion content, voting results, participant aliases, and moderation information for Pebbles they created. Organizers can moderate content, and may continue to view content they have hidden.

5. Third-party service providers

Pebbles currently relies on:

  • Supabase for the database, authentication, anonymous accounts, realtime updates, and magic-link sign-in.
  • Google when you choose Google sign-in.
  • Vercel to host and deliver the web application.
  • The email provider configured through Supabase to deliver sign-in links.

These providers process information under their own terms and privacy practices. Pebbles does not currently include a separate advertising, product-analytics, or error-monitoring service.

6. Data retention and deletion

Pebbles does not currently apply an automatic deletion schedule. Information remains stored until content, a Pebble, or an account is deleted, or until it is removed in response to a valid deletion request.

Participants can delete supported submissions, comments, and replies they authored. Organizers can moderate content and delete Pebbles they created. Deleting an account may also delete Pebbles and content associated with that account. Some content may remain after an account is deleted when necessary to preserve the context of a discussion, but it may no longer be associated with the deleted account.

Provider logs or backups may remain according to the service provider’s own retention practices. To request deletion or ask about your data, email pebblesdev@proton.me.

7. Security limitations

Pebbles uses authentication and database access controls to limit access, but it is an early beta and no online service can guarantee perfect security. A person with a valid Pebble link may be able to join while the Pebble is open, and participants can copy or share content they can see.

Do not use Pebbles for passwords, financial information, health records, government identifiers, or other highly sensitive information.

8. Children and minimum age

Pebbles is intended only for people who are at least 18 years old. Do not use Pebbles if you are under 18.

9. Changes to this policy

This policy may change as the beta evolves. The updated version will be posted on this page with a new “Last updated” date.

10. Contact information

Questions, privacy concerns, and deletion requests can be sent to pebblesdev@proton.me.