Policies

Privacy

What the platform holds about you, who can see it, and what you can do about it.

Last edited 7 October 2026

What is collected

The platform holds only what it needs to run an account and a feed.

  • Account: your email address, your handle, your account type and status, and a salted hash of your password. The password itself is never stored and cannot be read back.
  • Age: the date of birth you declare at registration, so the minimum-age rule can be applied. It is held server-side, it is never returned by any endpoint, and it is never shown on a profile.
  • Profile: what you choose to publish there, such as a display name, a biography, links, languages and the visibility of the profile.
  • Content: the posts, comments, stories and messages you create, and the media you upload.
  • Relationships and preferences: who you follow, who you block, who you mute, which notifications you have switched off, and what you have saved.
  • Security records: sessions with their expiry, and failed sign-in attempts by identifier and address so that brute force can be slowed down.

What is public

A public profile is readable by anyone, including people who are not signed in. What a profile shows is the projection the platform allows: a handle, a display name, an avatar, a biography and the visibility you chose. Your email address is never published.

A post is readable according to its own visibility. A followers-only post is readable by accounts that follow you, and by nobody else. A message is readable only by the participants of the conversation it belongs to.

Reading a private thing is not possible through the API, not merely hidden in the interface: every read is scoped to the signed-in account before the query runs.

What is never exposed

Credentials are outward-facing nowhere: no response carries a password hash, a refresh token, or a session secret.

Moderation material stays in the moderation queue. A person who is the subject of a report is not shown who reported them, and a report is readable only by its reporter, its subject where the contract allows it, and the moderators who decide it.

Who else is involved

Three outside services are used, and only for the job named here.

  • Media storage, for the images and files you upload. A file is uploaded directly to the storage provider with a signed authorization issued by the platform.
  • Email delivery, for the messages that verify an address or reset a password.
  • Payment processing, where a section of the platform takes money. Card details are entered with the payment provider and never reach the platform.

Your choices

You can change your profile and your profile visibility, switch off notification events you do not want recorded, block or mute an account, and delete what you published.

Self-service data export and self-service account deletion are not built yet. Until they are, ask through the phone number on the platform, +234 803 668 2403 and we will tell you what can be handed over or removed.

Changes

When this page changes, the date at the top changes with it.