Privacy Policy
What we collect, why we collect it, and the rights you have over it. Written in plain English.
1. Who we are
2050planet.com (“2050planet”, “we”, “our”) is a cradle-to-grave platform for the world being built toward 2050. We operate from the United Arab Emirates and serve users globally. For the purposes of this policy we are the data controller for any personal data described below.
If you have questions about this policy or want to exercise your rights, contact us at privacy@2050planet.com.
2. The short version
- You can read 2050planet without signing in. We don't track you.
- If you sign in with Google, we store your email, display name, and avatar URL.
- If you chat with TERRA (our AI), we count the messages but do not store the conversations themselves.
- For free-tier rate limiting we keep a hashed version of your IP for up to 48 hours, then delete it.
- We never sell your data. We never use TERRA conversations to train AI models.
- You can delete your account and everything associated with it at any time by emailing us.
3. What we collect, and why
3.1 If you only read the site (no sign-in)
We collect nothing identifying. The site is statically generated and served from a CDN. We don't run analytics, advertising trackers, or fingerprinting on public pages.
If you use TERRA without signing in, we store a SHA-256 hash of your IP address for up to 48 hours so we can enforce the 3-message free limit. The hash is salted and is not used for any purpose other than the limit. Raw IPs are never written to our database.
3.2 If you sign in with Google
We receive from Google and store:
- Your email address
- Your display name (as set in your Google profile)
- The URL of your Google profile picture (we don't copy the image — we link to it)
- A unique account identifier issued by Supabase Auth
This information is stored in Supabase (see Section 5). The lawful basis under UAE PDPL Article 5 and GDPR Article 6(1)(b) is contract — we need it to give you a functioning account.
3.3 When you chat with TERRA
Your messages are sent to a third-party AI infrastructure provider for processing and the response is returned to you. 2050planet does not retain the content of your TERRA conversations. We store only:
- The number of messages you sent (for usage analytics)
- A timestamp
- Your account ID (if you're signed in)
That provider is named, with its processing location and the safeguards that apply, in our sub-processor register. It processes your messages under its own published privacy terms and does not use API inputs or outputs to train its models by default, per its commercial terms.
3.4 Server logs (operational)
Our hosting provider (Vercel) generates short-lived logs for every request: the URL accessed, HTTP status, response time, and originating region. These logs help us diagnose errors and detect abuse. They are retained according to Vercel's default retention (typically 7-30 days for the standard plan) and are not used for any other purpose.
4. What we don't collect
- We do not run advertising or third-party trackers
- We do not sell or share data with marketers
- We do not store TERRA conversation content
- We do not use your data to train AI models — ours or anyone else's
- We do not collect payment information (the platform is free)
5. Who processes your data on our behalf
We use the following processors. Each is bound by a data processing agreement and is GDPR-ready.
| Processor | What they do for us | Where data sits |
|---|---|---|
| Supabase | Authentication, profiles database, TERRA usage counts | EU (Frankfurt) by default |
| AI infrastructure provider named in the register | TERRA inference (the AI engine) | United States |
| Vercel | Web hosting, edge CDN, server logs | EU (Frankfurt) for compute; global CDN edges for static |
| Upstash | Rate limiting (request counts only — no identifying data) | EU |
| OAuth sign-in (you authenticate with Google, then we receive the data listed in 3.2) | Global |
6. International data transfers
Our AI infrastructure provider operates from the United States. When you use TERRA, your messages cross from the EU/UAE to the US. This transfer happens under Standard Contractual Clauses (GDPR Art. 46) and the equivalent controller-to-processor safeguards under UAE PDPL Art. 22. By using TERRA you consent to this transfer.
The provider's identity, its processing location and the specific safeguards relied on are set out in full in our sub-processor register, which forms part of this policy.
7. Your rights
Under UAE PDPL and GDPR you have the right to:
- Access — ask us for a copy of the data we hold about you
- Correction — ask us to correct inaccurate data
- Erasure — ask us to delete your account and all associated data
- Restriction — ask us to pause processing while we resolve a query
- Portability — ask us to send your data to you in a machine-readable format
- Objection — object to processing where we rely on legitimate interest
- Withdraw consent — at any time, where we rely on consent
To exercise any of these, email privacy@2050planet.com. We respond within 30 days. There is no fee unless your request is manifestly unfounded or excessive.
If you believe we have not handled your data properly, you may complain to the UAE Data Office or, if you are in the EU, your national supervisory authority.
8. Data retention
- Account data (email, profile): kept while your account exists; deleted within 30 days of account deletion
- TERRA usage counts: 24 months for product analytics, then deleted
- Hashed IPs (free-tier counter): up to 48 hours, then deleted by automated cleanup
- Server logs: per Vercel default retention (typically 7-30 days)
9. Children's privacy
Parts of 2050planet are designed for young readers (Generation 2050 sections starting at age 2). The site itself is freely readable without any account. You must be 16 or older to create an account.If we learn that we have inadvertently created an account for someone under 16 without verifiable parental consent, we will delete it.
Parents who want their child to access TERRA can do so under their own account. Educators using 2050planet in classrooms should refer to our For Schools guide.
10. Security
We follow industry-standard security practices: TLS 1.2+ for all transport, security headers including HSTS and CSP, row-level security on all database tables, rate limiting on public endpoints, and a vulnerability disclosure programme described in our Security Policy.
No system is perfectly secure. If you believe you've found a vulnerability, please follow the coordinated disclosure process in our Security Policy.
11. Cookies
We use only the cookies strictly necessary for authentication (Supabase session cookies). We don't use analytics, advertising, or tracking cookies. Because all our cookies are necessary for the service you requested, we don't show a cookie banner — there's nothing for you to opt out of.
12. Legal basis for processing
Under UAE Federal Decree-Law No. 45 of 2021 (Personal Data Protection Law), and the corresponding GDPR articles where they apply to you, we process personal data on these bases:
- Consent — when you create an account, or send a message to TERRA and thereby consent to the international transfer described in Section 6.
- Contractual necessity — when processing is required to deliver a functioning account (PDPL Art. 5, GDPR Art. 6(1)(b)), as described in Section 3.2.
- Legitimate interest — for abuse prevention and service integrity: the hashed-IP free-tier counter, endpoint rate limiting, and short-lived server logs. We do not rely on legitimate interest for advertising, profiling or analytics, because we do none of those (Sections 3.1, 4 and 11).
- Legal obligation — when disclosure or retention is required by UAE law.
13. AI-specific disclosures
- TERRA's responses are AI-generated output. They are presented as such and are not professional, legal, medical or financial advice.
- We do not use your data — conversations included — to train foundational AI models.
- AI features process your data solely to deliver the response you asked for. Conversation content is not retained by us after the response is returned (Section 3.3).
- The provider performing that inference is disclosed in our sub-processor register.
14. Changes to this policy
If we make material changes we will update the “Last updated” date at the top and, for signed-in users, notify you by email at least 30 days before the change takes effect.
15. Contact
Questions, requests, or complaints: privacy@2050planet.com.
For security-specific reports, see the Security Policy or email security@2050planet.com.