Privacy

What we collect, why, who else sees it, and what you can ask. Plain language, and it matches what the site actually does. Last updated 5 September 2026.

1. Who is responsible

Mapheim AS, a Norwegian limited company, organisasjonsnummer 929 542 681, Høgskoleringen 4, 7034 Trondheim, Norway, is the controller of the personal data described on this page. Questions, requests and complaints go through the form at internetwall.art/contact or to tra.llawtenretni@olleh. One person reads both.

2. When you look at the wall

A cookie called iw_viewer. The room sets it the first time your browser asks about referral credit, which happens when the room loads, or when you first answer “Was there” on a card. It holds a random identifier and nothing else, lasts one year, and does three jobs: it is what lets the wall show you which pieces are yours on another device, it is what referral credit is paid to, and it is what your “Was there” answers are kept against, so each card counts you once. It is not used for advertising and is not shared with anyone.

Your address, hashed. We keep a salted hash of your IP address beside that identifier, on the record of each open tab for one hour, and on a counter for one day, and a hash of your network beside each “Was there” answer for as long as the answer is kept. Those are what stop one address opening dozens of checkouts, holding the whole frame, or counting itself as a crowd, and what stops somebody referring themselves. A hash is not an address, but it is not anonymous either: someone with our code and a list of addresses could match them. We never store the address itself.

The bot check. When you answer “Was there”, Vercel’s bot check (BotID) runs in your browser to tell a person from a script, and sends what it reads about the browser to Vercel. It runs on that one request and no other.

How the room is used. PostHog records what happens on the page: which pages open, what is tapped, the steps between arriving and paying, your browser, device and country, and a replay of the screen as you used it. Anything you type is blanked before it is recorded, and so is the picture you upload; the 3D room itself is never recorded, only the screens in front of it. It keeps a random identifier in your browser’s session storage, which is discarded when you close the tab, and sets no cookie. We strip the referral code and the payment reference from every address before it is sent. Vercel Web Analytics counts page views alongside it, with the same addresses stripped and no cookie.

In your browser only. The site keeps a few things in your browser’s own storage that never leave it: the pieces you have bought, your last guest frame purchase, your referral code, and a per-tab id for the “watching” count. Clearing site data removes them.

3. When you buy

Your card is handled entirely by Stripe. We never see the number. Stripe gives us back an email address, which you type into their form, and identifiers for the session and the payment. We keep the email with the purchase so we can send you the confirmation the terms promise, and so we can reach you if your piece is removed.

Your picture is stored in two sizes: the 512-pixel version that is screened and shown on the wall, and the file as you uploaded it. Both are on a public file host with an unguessable-looking but not secret address, because the wall itself is public. The name, country and link you give are printed on the wall beside it. All of that is public by design; section 9 of the terms is the permission you give us to use it.

The check. Shortly after your picture goes up, it and the name and link you signed it with are sent to an automated image classifier run by Anthropic, a company in the United States, which answers with a set of yes-or-no findings and a one-sentence description. We keep the findings, the description and what the check cost, and a hash of the picture that identifies it if it is sent again and cannot be turned back into it. A picture the check removes is taken off the public file host and kept for 30 days in our database (Neon, listed below), not at any address, so a person can look at it if you appeal (terms §7); it is then deleted.

The record. Every purchase is a row: what you bought, what it cost, what credit was applied, the Stripe identifiers, your email, whether the confirmation was sent. Norwegian bookkeeping law requires us to keep sales records for five years, so a purchase record outlives the picture.

4. When you write to us

The form on /contact stores what you wrote, the address you gave for the answer, a hash of your IP address for the rate limit, and the iw_viewer identifier if your browser already had one. We keep messages, because a report about something on the wall is a record we may need to show. The suggestion box in the room stores the text and the identifier if there is one, and nothing else.

5. Who else sees it

Anthropic, Vercel and Neon are in the United States, and the pictures and the database are stored there. Each of them offers the safeguards EU and Norwegian law asks for on a transfer outside the EEA, in their standard data processing terms, and we rely on those. PostHog keeps its records inside the EU. We do not sell anything about you and we do not give any of this to anyone else, except where the law requires it.

6. How long

7. What you can ask

You can ask what we hold about you, ask for it to be corrected or deleted, object to our using it, and ask for a copy. Write to us at the address in section 1 and say which purchase, message or browser you mean; the iw_viewer identifier is the only way we can tell one visitor from another, so for anything that is not a purchase we will need it, and your browser’s developer tools can show it to you.

Two limits, said plainly. A purchase record cannot be deleted inside the five years the bookkeeping rules require, though the email on it can be. And a picture that has been on the wall may already be inside exports, clips and copies that other people made; section 9 of the terms describes what removal reaches and what it does not.

If you think we have handled your data wrongly you can complain to Datatilsynet, the Norwegian data protection authority, or to the authority in your own country.

8. Children

Anyone can look at the wall. We do not knowingly collect anything from a person under 18 beyond what looking at it involves (section 2), and buying a piece of it is for adults.

9. Changes

This page changes when the site does, and the date at the top moves with it. The version published here is the one that applies.