Privacy Policy
Last updated 20 September 2026
Where We're At is an annual survey of the people building on the AT Protocol. Taking part is voluntary, it needs an AT Protocol account, and this page describes every piece of data that involves.
Who is responsible
The controller under Article 4(7) GDPR is Louis Escher, Marsweilerstrasse 20, 88255 Baindt, Germany, who runs this survey as an independent project. Reach the controller at privacy@where-were.at. There is no statutory data protection officer, because the thresholds in section 38 BDSG are not met.
What signing in provides
Signing in uses AT Protocol OAuth. Your password is entered on your own PDS and never reaches this site. What the survey receives and stores about your account is:
- your DID, the stable identifier for your account
- your handle at the time you signed in
- your PDS host and your DID method, read from your DID document
- the creation date of your account, read from the PLC audit log, which exists to make a wave of accounts created the week the survey opens visible
- when you first signed in and when you were last seen
- your display name and avatar for the current browser session, fetched from the public Bluesky API
Your DID also ties your answers to one response, which is what keeps a single person from filling the survey in twenty times.
OAuth tokens for your account are stored so the session survives a page reload. They are deleted when you sign out.
What the survey stores
Your answers are saved as you go, one section at a time, so you can close the tab and come back. Alongside the answers themselves, each response carries when it was started, when it was last changed, how long it took, how complete it is, whether you finished it, and whether you consented to the public dataset.
Free text is yours to fill. Anything you type into a comment box or a free-text question is stored exactly as you wrote it, so please leave out anything you would not want a human reviewer to read.
The pseudonym
Each response also carries a pseudonym: an HMAC-SHA256 of your DID under a secret key that only the operator holds. Once the 2026 report is published, your DID, handle, PDS host and DID method are deleted and the pseudonym stays, so the 2027 edition can tell whether the same person answered twice without holding an identifier that points back at you. The pseudonym is still personal data under the GDPR and is treated as such.
Cookies and browser storage
One cookie, astro-session, holds a session identifier so the server can find your sign-in. It is strictly necessary under section 25(2) TDDDG, which is why there is no cookie banner. It disappears when you sign out.
The theme switch stores your choice of day or dusk in localStorage under the key sky. It never leaves your browser.
There is no analytics, no advertising and no tracking of any kind on this site.
Who else is involved
Cloudflare
The site runs on Cloudflare Workers, with Cloudflare D1 for the database and Workers KV for sessions. Cloudflare acts as a processor under Article 28 GDPR and handles connection data including your IP address, and request logs are kept for operational monitoring. Processing can happen on servers outside the EU, covered by Cloudflare's data processing addendum and the standard contractual clauses.
Your PDS and the PLC directory
Signing in makes the server talk to your own PDS and, for did:plcaccounts, to plc.directory to resolve your identity. Public profile data comes frompublic.api.bsky.app. These requests come from the server, so those hosts see the survey rather than you.
Handle search on the sign-in page
While you type a handle on the sign-in page, your browser queries the public typeahead service at typeahead.waow.tech for matching accounts, and any avatar it returns is loaded from the Bluesky CDN. Those hosts see your IP address and what you have typed so far. Turning off JavaScript stops it, and the field still works.
Fonts
Both typefaces are served from this domain. Your browser makes no request to Google Fonts.
What gets published
The report published in January 2027 contains aggregate numbers. No individual response appears in it.
The anonymized row-level dataset published alongside it contains only responses whose author ticked the consent box on the submit page. In that file your identity is replaced by a random per-edition id that has no connection to your DID or your pseudonym, free text appears only where it was matched to a known tool, and rare combinations of country, role and company size are coarsened before release.
Comments you leave on individual questions may be quoted in the report, as you wrote them, after a moderation pass. Leave the comment box empty if you would rather not be quoted.
The participation badge
If you tick the badge box before submitting, one record is written to your own repo in the collection at.where-were.participation, holding the edition, a timestamp and a link. It holds nothing about your answers. The record lives in your repo, which makes it as public as the rest of that repo, and you can delete it with any AT Protocol client.
How long things are kept
- Session and OAuth tokens
- Until you sign out, or until the token expires.
- Your response, with your DID attached
- Until the 2026 report is published in January 2027.
- Your account details
- Deleted at the same point. Handle, PDS host, DID method and account creation date go with the DID.
- Your answers under a pseudonym
- Kept for as long as the survey runs as an annual series, so editions can be compared. The retention is reviewed at the start of each edition.
- Free text awaiting normalization
- Raw text is kept in a normalization table so the mapping from what people wrote to a known tool stays reproducible. It carries no identifier.
- The published report and dataset
- Permanent. Both are anonymous and cannot be withdrawn once published.
Legal bases
- Your answers are processed on your consent under Article 6(1)(a) GDPR, given by answering, and withdrawable at any time.
- Publishing your answers in the open dataset rests on the separate consent you give with the checkbox on the submit page.
- Writing the participation record to your repo rests on the separate consent you give with the badge checkbox.
- Your DID, handle, PDS host, DID method, account creation date and the timestamps rest on legitimate interests under Article 6(1)(f) GDPR: running a survey that cannot be trivially stuffed, and being able to exclude a coordinated batch of responses.
- Operating the site securely, including Cloudflare's connection logs, rests on the same legitimate interest.
Nothing here involves automated decision-making or profiling within the meaning of Article 22 GDPR.
Your rights
You can, at any time:
- delete your response yourself while you are signed in, fromthe deletion page, which is also how you withdraw your consent
- ask for a copy of everything held about you, under Article 15
- have anything inaccurate corrected, under Article 16
- have your data erased, under Article 17
- have processing restricted, under Article 18
- receive your answers in a machine-readable form, under Article 20
- object to the processing based on legitimate interests, under Article 21, on grounds relating to your situation
Withdrawing consent leaves everything done before the withdrawal lawful. Aggregate figures already published cannot be pulled back out, because they no longer identify anyone.
Send any of these to privacy@where-were.at. Requests are answered within one month.
Complaints
You can complain to a supervisory authority, in the member state where you live, where you work, or where you think something went wrong. The authority responsible for the controller is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany.
Minimum age
The survey is for people aged 16 and over, the age at which consent under Article 8 GDPR is valid in Germany.
Changes
This policy changes when the survey changes. The date at the top says when it was last revised, and the full history is in the project's public repository.