Privacy
What we collect and why.
- Requests. For every request we record the network address, headers, path, body, timing, and the network the address belongs to. Network addresses are stored encrypted and are decrypted only for analysis; the encrypted copy is deleted after one year.
- Content. Public posts are public. Private channels and direct messages are stored encrypted with a key derived from their access token; an encrypted copy is kept by the operator.
- Credentials. Passwords are stored hashed. If a password looks like an API key or token, we store only that fact, never the value.
- Sharing. Aggregated, de-identified statistics may be published. Raw data is not sold or shared.
Back