Legal
TERMS & PRIVACY
Last updated: April 2026. These terms are open source under CC BY-SA 4.0.
THE SHORT VERSION
- Your data is yours. We don't sell it. Ever.
- We collect only your email and what you choose to share.
- You can delete your account and all data with one click.
- No tracking pixels. No analytics cookies. No third-party scripts.
- The platform is free. The code is open source.
- We're aligned with POPIA (South Africa) and GDPR (EU).
1. WHAT WE COLLECT
When you browse (no account)
Nothing. No cookies, no fingerprinting, no analytics. The skill tree is fully public.
When you register
- Email address — for OTP authentication only
- Display name — can be a pseudonym
- Country — optional, for community features
When you use the platform
- Skill self-assessments — which skills you've claimed and at what level
- Evidence submissions — portfolio items you choose to upload
- Peer reviews — reviews you give and receive
- Practice logs — optional journal entries
2. WHAT WE DON'T COLLECT
- Passwords (we use OTP only)
- Social media profiles (no social login)
- Location data beyond country (optional)
- Browsing behaviour, clicks, or session recordings
- Device fingerprints or advertising identifiers
3. HOW WE USE YOUR DATA
- To authenticate you (email + OTP)
- To display your skill profile (only if you opt in to public visibility)
- To match you with peers and mentors (only if you opt in to connections)
- To send you OTP codes (no marketing emails unless you explicitly opt in)
We never: sell your data, share it with advertisers, use it for profiling, or give it to third parties without your explicit consent.
4. DATA STORAGE
Data is stored on Cloudflare D1 (SQLite at the edge). OTP codes are sent via Resend (transactional email only). No data is stored in jurisdictions you haven't consented to.
5. YOUR RIGHTS
- Access — download all your data at any time
- Correction — update your profile and skill assessments
- Deletion — one-click account deletion removes all your data permanently
- Portability — export your skill profile in JSON format
- Objection — opt out of any feature without losing your account
6. VISIBILITY & PRIVACY DEFAULTS
Your profile is private by default. You must explicitly choose to:
- Make your profile public
- Appear in the people finder
- Accept connection requests
- Be available for mentorship
You can change these at any time in your settings.
7. OPEN SOURCE
The 2nth.me platform code is open source. The skill definitions are open source. These terms are open source under CC BY-SA 4.0. You are free to fork, modify, and redistribute.
8. NO LOCK-IN
2nth.me is a neutral platform. It is not required to use any other 2nth product (2nth.ai, 2nth.io, etc.). There are optional bridges to the wider ecosystem, but they are always user-initiated and never forced.
9. COOKIES
We use exactly one cookie: 2nth_me_session — an httpOnly, secure, SameSite cookie that stores your authentication session. It contains no personal data. It expires after 7 days. That's it.
10. CHANGES
We'll notify registered users by email before making material changes to these terms. The full history is available in the open-source repository.
11. CONTACT
Questions about privacy or data: [email protected]
Data protection officer: Craig Leppan, [email protected]
POPIA & GDPR: This platform is designed to comply with the Protection of Personal Information Act (South Africa) and the General Data Protection Regulation (EU). We process data on the lawful basis of consent (registration) and legitimate interest (platform operation).