Last updated July 2, 2026. This policy explains how the hosted Currents service collects, uses, and shares information.
1. Scope
This policy applies to the hosted Currents web app, mobile apps (including Android), browser extension, APIs, appview, and related search and inference infrastructure that we operate. It does not cover self-hosted forks or third-party services such as your PDS, Bluesky, Eurosky, or sites you visit through links saved in Currents.
2. Information we collect
We collect or process the following categories of information:
- Account and profile data such as your DID, handle, display name, avatar, description, pronouns, website, and related public AT Protocol profile fields.
- Public content you create or interact with through Currents, including collections, saves, image blob references, captions, notes, source URLs, and optional attribution metadata.
- Derived metadata used to operate discovery features, including image embeddings, dominant-color palettes, image dimensions, save clustering signals, and collection embeddings.
- Authentication data needed to keep you signed in, including a signed
currents-sessioncookie in the browser, an equivalent session token kept in your device's secure storage in the mobile apps, and server-side OAuth session records. - Search and interaction data you submit to the service, such as text queries for semantic search and standard request metadata needed to deliver, secure, and debug the service.
- Local browser state. The web app currently stores your last-used collection URI in local storage to make saving faster.
- If you use the browser extension, it may access the current page URL, page title, selected image URL or bytes, and Currents session cookie so it can create a save only when you invoke the extension.
- In the mobile apps, the images you choose to save: pictures you pick from your photo library or capture with your camera. Camera and photo access are used only when you actively select or take an image to save, never in the background.
- Content shared to the mobile app from other apps (an image or link you send to Currents through the system share sheet), used only to pre-fill a save you choose to create.
- Subscription and billing data if you become a Supporter. Checkout and billing are handled by Polar, our merchant of record, which collects your billing email, payment method, and country, and may set its own cookies inside the checkout window. Currents itself stores only your subscription status, plan, and Polar customer and subscription identifiers linked to your account — we never see your full payment card details.
- Aggregate usage statistics collected with Umami, a privacy-focused, cookieless analytics tool. It records anonymous page views and a small set of interaction events without account identifiers, cookies, device fingerprinting, or cross-site tracking. Searches, profile identifiers, collection identifiers, and save identifiers are removed before analytics data is sent.
3. How we use information
We use information to:
- Authenticate you and maintain your session.
- Fetch, index, display, and synchronize public AT Protocol content.
- Provide search, related saves, discovery feeds, and personalization features.
- Generate technical derivatives like embeddings and image metadata.
- Detect abuse, secure the service, debug failures, and maintain reliability.
- Comply with legal obligations and enforce our Terms.
4. What is public
Currents is designed around public AT Protocol records. If you publish content through Currents, that content and related metadata may be visible in Currents, on your PDS, and through other clients or protocol consumers.
Your search queries, session data, and the local browser state described above are not intended to be public user content.
5. How we share information
We may share information in the following ways:
- With the AT Protocol ecosystem and your chosen identity or hosting providers when necessary to authenticate you, fetch records, upload data, or serve public content.
- With infrastructure and service providers that help us host the database, appview, image proxy, and inference systems on our behalf.
- With Polar, our payments provider and merchant of record, when you purchase or manage a Supporter subscription. Polar processes your billing details under its own privacy policy.
- With other users and the public when the information is part of public AT Protocol content.
- If required by law, to protect users or the service, or as part of a reorganization, asset transfer, or similar transaction.
We do not currently run third-party advertising trackers on the web app, sell personal information, or use Currents data to serve ads.
6. Retention
Public records and their derived search metadata may remain in our indexes for as long as needed to operate the hosted service, plus reasonable backup and recovery windows. Deleting content from your PDS or through Currents may take time to propagate through indexes and caches.
Hosted OAuth sessions are kept only as long as needed to keep you signed in. At the time of writing, Currents expires sessions after roughly 90 days and may clear them earlier after extended inactivity.
Browser local storage remains on your device until you clear it or the app overwrites it.
Subscription records (status, plan, and Polar identifiers) are kept for as long as you have a subscription and afterwards for as long as needed for accounting, tax, and dispute-handling purposes.
7. Your choices
- Review or change your public profile and records through your AT Protocol account.
- Log out to clear the active Currents session: the cookie on the web, or the stored session token on mobile.
- Clear local browser storage in your browser settings.
- Avoid posting private, sensitive, or confidential material to Currents.
- Only use the browser extension when you want to clip a page or image; it is not meant to monitor browsing in the background.
8. Children's privacy
Currents is not intended for children under 13 or the higher minimum age required by local law. If you believe a child has provided personal information in violation of this policy, contact us using the method below.
9. Changes to this policy
We may update this policy from time to time. When we do, we will post the revised version here and update the date at the top of the page. Your continued use of the hosted service after the update takes effect means the revised policy applies.
10. Contact
For privacy questions or requests related to the hosted Currents service, including data deletion requests, email privacy@currents.is or open an issue at github.com/matteomarjanovic/currents/issues .