The ReceiptThe Receipt

Legal

Privacy policy

The short version

We collect almost nothing, we sell nothing, your contributions license us to display them, and the scores are editorial opinion grounded in documented fact.

This policy mirrors the plain-language version on the Safety page exactly. There is no separate, stricter, or looser legal version.

What we never collect

Real names. Phone numbers. Email addresses (an optional recovery key stands in instead). Precise location. Government ID of any kind.

What we strip automatically

EXIF and location metadata from every photo, the moment it's uploaded, before it's stored.

What we minimally hold, and for how long

Abuse-prevention data (rate-limit tokens, hashed, tied to no identity) is held for up to 14 days, then purged by an automated job. That's the full retention window for anything beyond a handle, passphrase hash, and recovery-key hash.

What happens if we're ordered to identify a contributor

We can produce only what exists. A handle and its submissions cannot be mapped to a person, because the mapping was never created.

What you should still do

Don't reuse a handle from another platform. Don't include faces or identifying details in photos. Consider a VPN if your connection itself could identify you. We do our part. These steps do yours.

Our commitment in writing

This page is the technical policy. Any change to it is logged publicly, because a safety policy that changes silently is worthless.