Privacy
Last updated October 3, 2026
We collect as little as a paid message board can run on. We never sell your data, and there are no ad networks or trackers on Toptag.
Who is responsible
The controller of your personal data is Samuel Pop, who runs Toptag from Spain. Write to contact@millerio.com or use the contact form. Toptag doesn't need a data protection officer; Samuel answers data questions himself.
What we collect
Account: your email, name, @handle, profile photo if you add one, a scrambled version of your password (handled by our sign-in provider: we never see it), the date you accepted the terms and that you're 16 or older. What you put on Toptag: your posts and their amounts, top-ups, reports, feedback and contact messages, and the waitlists you join. Credit: every movement of your wall credit (welcome credit, gifts, posts, refunds, purchases). Security: a check from Cloudflare that you're a person when you sign up or sign in, and, when you send a form, a scrambled version of your network address that can't be turned back into it. Card payments, when they open, are handled by the payment provider: we never see or store your card.
Why, and on what legal basis
To give you an account and run the walls, take your posts, move your credit and process refunds: the contract with you (GDPR art. 6.1.b). To review every post before it goes up, handle reports, stop spam, fraud and abuse and keep Toptag safe: our legitimate interest in a safe service (art. 6.1.f) and our duties as a hosting service under the EU Digital Services Act (art. 6.1.c). To keep payment and credit records: tax and accounting law (art. 6.1.c). To email you when a wall you're waiting for opens, or to answer your message: your consent, which you can withdraw at any time (art. 6.1.a). Sign-in emails (confirm your email, reset your password) are part of the contract.
What is public
Everything you post is public: the text, the amount, your name, @handle and photo, and your profile page with your posts. Anyone can see it, share it and link to it, and search engines may show it. Think about that before you post, and never post anyone else's private details (the rules forbid it).
Who helps us (processors)
Supabase (database, accounts and sign-in; servers in the EU, Ireland). Vercel (hosting the website). Cloudflare (Turnstile, the check that you're a person). Resend (sending emails, once it's switched on). A card payment provider, once card payments open. Two services are called directly by your browser, so they see your network address: Open-Meteo, for the weather shown on a city's wall, and Photon by Komoot, for the city search. Each processes data only on our instructions or to provide that function. We may also have to share data with courts or authorities when the law requires it. Nobody else.
Outside the EU
Some of these providers are US companies (Vercel, Cloudflare, Resend). Where data leaves the European Economic Area it is protected by the EU-US Data Privacy Framework (the European Commission's adequacy decision) or the European Commission's standard contractual clauses.
How long we keep it
Your account and posts: while you have the account. A post stays on its week's board, which stays readable after it closes, until you delete it or your account. If you delete your account your posts come off every board, their text is erased and your profile is anonymised. Payment and credit records: up to six years, as Spanish accounting and tax law requires, without your name once your account is gone. Waitlist emails: until the wall opens and we've told you, or until you ask. Contact messages: until they're answered, then deleted within a year. Scrambled network addresses: a day. Records of moderation decisions: as long as needed to handle complaints and repeat abuse.
Your rights
You can access, correct and delete your data, restrict or object to how we use it, take it with you (portability) and withdraw consent at any time. On your account page you can download everything we hold about you, or delete your account, yourself. For anything else write to contact@millerio.com or use the contact form; we answer within a month. If you think we've got it wrong you can complain to the Spanish data protection authority, the Agencia Española de Protección de Datos (www.aepd.es).
Decisions about you
No decision about you is made by a machine alone. A person reads every post before it goes up and decides every report and suspension. Software only helps: it flags posts that look like they contain links, phone numbers or emails so a person checks them first.
Ages
Toptag is for people aged 16 and over. If we learn that an account belongs to someone younger, we delete it.
Security
Connections are encrypted (HTTPS). Passwords are stored scrambled by the sign-in provider. Only staff can see the review queue, and staff accounts are protected with a second sign-in step. Database access is limited to what each part of the site needs.
Cookies and your device
We only use what the site needs to work: a sign-in cookie if you have an account, and on your device your language, your draft post and the waitlists you've joined. Cloudflare's check may store what it needs to tell people from bots. These are strictly necessary, so they don't need your consent (Spanish LSSI art. 22.2). There are no analytics, advertising or tracking cookies. If that ever changes we'll ask you first.
Changes
If we change this notice we'll update the date at the top, and if the change matters we'll tell you on the site or by email before it applies.
Questions about any of this? Write to us and a person answers.Contact us →