Privacy Policy
Last updated 2 September 2026
This policy explains what information accord collects, how we use it, and the controls you have. Privacy isn’t a feature we bolted on. It’s the reason the product is shaped the way it is. If anything here surprises you, that’s a bug; tell us.
accord is in beta. That doesn’t change how we treat your data, but it does mean the product is still moving: if we start collecting something new, we’ll say so here and update the date above.
Who we are
accord (“we”, “us”) operates the accord.social service. For any privacy question, or to exercise a right described below, contact us at [email protected].
What we collect
- Account details. Your email address and authentication credentials, which are handled by our authentication provider (see below). If you sign in with Google, Apple or Microsoft, we receive a basic identifier from them, not your password.
- Profile. Your display name, handle, optional bio and avatar. Your display name, handle and avatar make up your public-facing identity: they are shown to anyone who can see something you’ve made public, including logged-out visitors. Your bio is only ever shown to your connections.
- Content you create. Your lists, list items, rankings, tiers, notes and custom fields.
- Your graph. Your connections, and the friend groups you create.
- Technical data. The minimum needed to operate and secure the service (e.g. server logs). We do not use advertising or cross-site tracking.
How we use it
We use your information to provide the service: to store and display your lists, to enforce your visibility choices, to connect you with people you know, and to keep the service secure. We do not sell your personal data, and we do not run behavioural advertising.
How your content is shared
Every list has a single visibility setting that you control:
- Private: visible only to you.
- Public: visible to anyone, including logged-out visitors, showing only your public-facing identity (display name and avatar). Public means genuinely public: these lists can be opened by anyone with the link, without an account, and can be indexed by search engines such as Google. Your public-facing profile page, which lists your Public lists and nothing else, works the same way. If you don’t want something to be findable that way, don’t set it to Public.
- All friends: visible to every one of your connections.
- A friend group: visible to the connections in a group you choose. The group’s name and membership are never revealed to viewers, including the members themselves.
Seeing someone’s name on a shared or public surface never unlocks their profile. Full profile access requires a mutual connection.
Being found by other people
Other signed-in members can search for you by your display name or handle. A search result shows your public-facing identity (display name, handle and picture) and how many connections you have in common with the person searching. It never shows your lists, your bio, or who you are connected to, and finding you does not give anyone access to your profile: that still requires a mutual connection.
This is on by default, because a service where nobody can find each other doesn’t work. You can turn it off at any time in Settings → Privacy. Turning it off doesn’t hide your existing connections or your Public lists, and your invite link keeps working.
Separately, you can choose whether your connections may see your other connections, so that friends of friends can find each other. That is also in Settings and is on by default; connections you already share with someone are always visible to them.
Anonymous rankings
accord can show site-wide rankings of what’s popular among real people, and a page for each book, film or place showing how many people have it. Your items only ever contribute to these counts if you opt in, which is off by default. We only display a figure once enough people have contributed to keep individuals unidentifiable (a minimum-count threshold), and below that threshold we show no number at all.
Even when you have opted in, items on your Private lists are never counted. Counts are of distinct people, never of names: the rankings contain no owner information, and individual list membership is never exposed through them. If you are signed in, an entity page also shows which of your own connections have that thing, but only from lists you could already open.
Catalogue data
When you add a book or a place, we fetch details and cover art from open data sources: OpenLibrary for books, and OpenStreetMap (via Photon) for places. Your search terms are sent to the relevant source to return results, and we cache what we display. Other kinds of list are free text, so nothing leaves accord when you add to them. If we switch more list types to a catalogue we’ll name the source here.
Service providers
- Supabase: our authentication provider and database host. Your account credentials and multi-factor / passkey settings are managed by Supabase.
- Open catalogue sources: as listed above, for search and cover art.
- Sentry: error and performance monitoring, so we find out when something breaks. We have configured it not to collect personal data: no IP addresses, no cookies, no request headers, and no session recording.
- Vercel (website hosting), Microsoft Azure (our API) and Cloudflare (network and security). These handle your requests in order to serve the site.
Cookies and local storage
We don’t use advertising cookies, we don’t track you across other websites, and we don’t use third-party analytics. accord itself keeps its state in your browser’s local storage rather than in cookies, for things the app needs in order to work the way you left it:
- Your sign-in session, stored by our authentication provider so you stay signed in. Without it you would have to sign in on every page.
- Your preferences: light or dark mode, the view each list opens in for you, whether you’ve dismissed the setup checklist, and the status you last used when adding a recommendation.
- An invite code, briefly, if you open an invite link before signing up, so the connection still works after you create your account.
Clearing your browser storage signs you out and resets those preferences. Nothing is lost from your account.
You may still see a small number of cookies in your browser. Those come from the services that put the site in front of you rather than from accord itself: Cloudflare, which sets cookies to tell real visitors from bots, and Vercel, which hosts the site. Our error monitoring also stores a short-lived identifier so several errors from one visit can be grouped together. None of these are used for advertising or to follow you around the web.
Retention and deletion
We keep your information for as long as your account exists. You can delete your account at any time from your settings; doing so removes your profile, lists, connections and groups, and deletes your credentials from our authentication provider. Some minimal records may persist briefly in backups before being overwritten on the normal backup cycle.
Your rights
Depending on where you live, you may have rights to access, correct, export or delete your personal data, and to object to certain processing. You can exercise most of these directly in the app (profile and settings), or by emailing [email protected].
Children
accord is not directed at children under 13 (or the minimum age in your country), and we do not knowingly collect their data.
Changes
We may update this policy as the product evolves. We’ll change the “last updated” date above and, for material changes, tell you in the app.
See also our Terms of Service and About page.