Skip to content

Opening it to others

An instance for yourself needs little care. As soon as friends, family or strangers have an account, a few things matter more.

Under the GDPR, you become the data controller for their accounts: you answer for what is stored, for how long, and for their requests to see or delete it.

The legal pages that come with Loomkeep (/legal/…) are loomkeep.app’s own, and say they only cover loomkeep.app. There is no setting yet to replace them with yours: write your own notice and privacy policy, publish them where your users can find them, and point them there. loomkeep.app’s privacy policy is a starting point to adapt; it is in French.

  • A domain with HTTPS: people will want the app on their phone, which needs it.
  • Email: without SMTP, nobody can reset a forgotten password, and dormant accounts are never cleaned up, since the warning before deletion can’t go out (see Scheduled jobs).
  • Backups, copied off the server, and restored once to be sure they work.
  • Two-factor authentication for every administrator. With the HTTPS override, the Admin area requires it.

In instance settings:

  • Registration open: anyone who finds the address can sign up. Add Turnstile against bots.
  • Registration closed: only an invitation, by email or by a link, lets someone in. The right choice for a family or a group of friends.

With social features on, people see each other’s activity, reviews and lists, within the privacy settings each one chooses. They can also report what others post: reports reach Admin › Reports, and administrators get a daily email while some are pending. Someone has to look at them: see Moderation.

  • Inactive accounts are warned by email after two years without use, and deleted after three.
  • API keys unused for a year are deleted.
  • The security log keeps a year of sign-ins and sensitive actions.

The full list is in Scheduled jobs. Each person can export or delete their own data at any time, without asking you.