Controller and contact
The data controller is Pedro Alexandre Vilas Boas Teixeira, trading through Trusted Free Fonts and Pedro Teixeira Foundry, Póvoa de Varzim, Portugal. For privacy requests, contact geral@trustedfreefonts.com. Last updated and effective: 28 August 2026.
Data collected
The site may receive account name, email, public author name, biography, location, official website, avatar, consent choice, submission and licence declarations, uploaded font packages and mockups, messages, forum posts, reports and moderation history. Security and delivery systems may process IP address, user agent, timestamps, request URLs, cookie identifiers and diagnostic logs.
Published author information, approved forum material and font metadata are public. Account email, quarantined files, private messages and reviewer notes are not intentionally published.
Purposes and legal bases
- Contract and requested service: create accounts, receive submissions, publish approved fonts, deliver downloads and provide messages or settings.
- Legitimate interests: secure the service, prevent abuse, keep provenance evidence, measure aggregate performance, correct records and defend legal claims.
- Legal obligation: respond to valid notices, preserve required records and cooperate with competent authorities.
- Consent: use non-essential analytics or advertising storage where consent is required. Consent can be withdrawn without affecting earlier lawful processing.
Google, analytics and advertising
Google services may include Site Kit, Search Console, Analytics and, after approval and configuration, AdSense. Third-party vendors, including Google, may use cookies to serve ads based on a visitor’s previous visits to this or other websites. Google’s advertising cookies enable Google and its partners to serve ads based on those visits.
Visitors can manage personalised advertising in Google Ads Settings and can learn about other participating vendors at YourAdChoices. Where required in the EEA, United Kingdom or Switzerland, advertising choices are requested through a Google-certified consent management platform before personalised advertising storage is enabled.
Service providers and recipients
Relevant data is shared only when necessary with providers supporting hosting, content delivery, email, security, backups, consent, analytics, advertising and controlled AI-assisted review. Current service categories may involve Hostinger for hosting infrastructure, Google for the services named above, WordPress components used to operate the site, and OpenAI only when an authorised AI-assisted review workflow is invoked. Each provider receives only the data needed for its task and acts under its own applicable terms or a data-processing arrangement.
Data may also be disclosed to professional advisers, rights holders or public authorities when reasonably necessary to investigate a claim, protect a person, enforce the Terms or comply with law.
International transfers
Some providers may process data outside Portugal or the European Economic Area. Where GDPR transfer rules apply, the controller relies on an adequacy decision, approved contractual safeguards or another lawful transfer mechanism provided by the relevant service.
Retention
Ordinary private messages are normally available for up to 180 days. Rejected submissions and their private files are scheduled for deletion after 30 days unless an unresolved safety, rights or legal issue requires a longer hold. Published font provenance, licence evidence and audit records are retained while the family is listed and afterwards where reasonably necessary for corrections, security or legal claims. Account data is retained until deletion is requested, subject to records that must be kept for those purposes. Backups and security logs expire on their own controlled schedules.
Your rights
Where the GDPR applies, a person may request access, correction, erasure, restriction, portability or object to processing based on legitimate interests. Consent may be withdrawn through the relevant settings. Identity may need to be verified before a request is completed. A complaint may be made to Portugal’s Comissão Nacional de Proteção de Dados (CNPD) or another competent supervisory authority.
Security and incidents
Measures include private upload quarantine, file-type and integrity checks, role-limited access, authentication controls, rate limits, audit records and protected backups. No online system is risk-free. A qualifying personal-data breach will be assessed and notified as required by law.
Children and changes
Contributor accounts and forum participation are intended for adults. The service does not knowingly create contributor accounts for children or use known children for personalised advertising. Material privacy changes will be dated here; where required, a new consent choice will be requested.