Safety
What we know about you: almost nothing. On purpose.
The strongest privacy policy is not a promise to protect your data. It's not having it.
What we never collect
Real names. Phone numbers. Email addresses (an optional recovery key stands in instead). Precise location. Government ID of any kind.
What we strip automatically
EXIF and location metadata from every photo, the moment it's uploaded, before it's stored.
What we minimally hold, and for how long
Abuse-prevention data (rate-limit tokens, hashed, tied to no identity) is held for up to 14 days, then purged by an automated job. That's the full retention window for anything beyond a handle, passphrase hash, and recovery-key hash.
What happens if we're ordered to identify a contributor
We can produce only what exists. A handle and its submissions cannot be mapped to a person, because the mapping was never created.
What you should still do
Don't reuse a handle from another platform. Don't include faces or identifying details in photos. Consider a VPN if your connection itself could identify you. We do our part. These steps do yours.
Our commitment in writing
This page is the technical policy. Any change to it is logged publicly, because a safety policy that changes silently is worthless.