Privacy Policy
This policy explains what personal information The Social Web collects, why we collect it, who can see it, how long we keep it, and the choices and rights you have. It covers the website at https://thesocialweb.site, our apps, and email we send. We wrote it to be complete and specific, because a vague privacy policy is a warning sign.
1. The short version
- No advertising, no analytics, no tracking, ever. There are no ad networks, pixels, analytics scripts, social widgets or fingerprinting on The Social Web.
- We never sell your personal information or share it for advertising. Not now, not later.
- We keep what the service needs to work, for as long as it needs it, on a published schedule that is enforced automatically.
- Nothing is visible to the public internet. Profiles, posts and photos are visible only to signed-in members, and you choose which members.
- Messages are not end-to-end encrypted. We are telling you up front so you can decide what to send.
- You can download your data and delete your account yourself, any time, from Settings → Account.
2. Who we are
The Social Web is operated by BOT-HOLDINGS, LLC, doing business as codedatda.casa, a Nevada limited liability company based in Las Vegas, Nevada, USA. We are responsible for the personal information described in this policy. You can reach us at [email protected] or through Support. We do not publish a postal address; contact us by email if you need a mailing address.
3. What we collect
Information you give us
- Account details: your username, your email address (which we confirm), and your password, which we never store; we keep only a scrypt hash of it. We also record that you confirmed you are at least 18 and that you accepted the terms, with the date and terms version.
- Profile details you choose to add: display name, bio, pronouns, location (free text you type, never detected), website, status line, profile song (a link with its title and artist, and when you confirmed you have the right to share it), profile picture, cover image, top friends and your theme and layout choices, including wallpaper photos you upload. A wallpaper is shown to visitors of your profile only when your profile theme says so ("Same as mine" or a profile wallpaper); other members never see your wallpaper gallery. All of these are optional.
- What you post and do: posts, comments, votes (which way you voted on which post or comment), reactions, reposts and quotes, bookmarks, hashtags and mentions, wall posts, and the media you upload (we keep the file's original name and a fingerprint of the upload alongside it). When you add a GIF by pasting a link, our server fetches that file once from the address you pasted and keeps a copy like an upload; the other site sees our server's address, never yours.
- Your connections: friends, friend requests, follows and blocks, the groups and pages you join or follow (and your role in them), and the unguessable token behind your personal QR friend code (you can regenerate or turn it off at any time).
- Age check: at sign-up we ask for your date of birth once to confirm you are an adult. The date is compared and discarded; we store only that the check passed and how (date of birth or attestation). A failed check sets a short-lived cookie so the form cannot be retried at once.
- Ideas and bug reports: what you write on the Ideas & bugs board; a bug report also records the page address you were on, your browser's user-agent string and the site version, so staff can reproduce it. Bug reports are visible only to you and staff; ideas are visible to members.
- Messages: direct and group messages and the photos in them, plus read markers and per-conversation mute settings.
- Invites: the invite codes you create, any note you attach to them, and which member used each code.
- Reports, appeals and support tickets: what you report and why, appeals you file, and your conversations with our support team, including privacy requests.
- Security settings: if you turn on two-factor authentication, your authenticator secret (encrypted at rest) and your recovery codes (stored only as hashes). API tokens you create are also stored only as hashes.
- Preferences: your theme, privacy, notification and wellbeing settings, including muted words.
Information collected automatically
- Sessions: when you sign in, we record the session's IP address, your browser's user agent string, and when it was created and last used, so you can review and end your sessions in Settings → Security.
- Security events: sign-ins, failed sign-in attempts, password resets, two-factor changes, invite creation and similar account events, with the IP address involved. We use these to protect accounts and to investigate abuse.
- Sign-up signals: the IP address and browser user agent used to create your account (see section 4).
- Activity timestamps: when you last signed in and were last active. These keep sessions alive and may be used to show whether you are online right now. They are not used to profile you.
- Server logs: our web server writes a short line for each request (IP address, method, path, status and timing) to its operational log so we can keep the service running and fight abuse.
Information from others
- Other members may mention you, post on your wall, send you messages, add you to a group chat, or report your content.
- The member whose invite code you used is recorded as your inviter.
- Cloudflare tells us the result of a bot check when you sign in or sign up, and passes along your IP address with each request.
4. Invite lineage and bot detection
The Social Web is invite-only so that it stays a place for real people. The weak point of any invite system is that one code handed to a bot operator can turn into thousands of fake accounts very quickly. To catch that, we keep the following with every account:
- which member's invite code created it ("invite lineage"), which forms a tree from every member down to everyone they invited, everyone those people invited, and so on;
- the IP address and browser user agent used at sign-up;
- whether invites are paused on the account.
Moderators and administrators can view the tree of accounts that grew from any member. The service computes simple, transparent signals for each tree, such as how many accounts signed up from the same IP address (currently 3 or more is flagged) and how many joined in the last 24 hours (currently 5 or more is flagged), along with how many accounts in it never confirmed an email address or made a friend. A flag is only a prompt for a human to look. No automated decision is made about you from these signals. If staff confirm a bot network, they can lock, suspend or pause the invites of an entire tree at once, and every such action is recorded in our moderation log.
If you invite someone, you can see which of your codes have been used and the username of the member who used each one. Other members cannot see your sign-up IP address or user agent.
5. What we never collect
We do not ask for or collect your real name (unless you choose to use it), your phone number, your address book or contacts, your precise or approximate location from your device, your browsing activity on other websites, family or relationship details, or payment card details. We do not build advertising profiles or make inferences about you for marketing. We do not use your content to train artificial intelligence models.
Photos are re-encoded when you upload them, which removes camera metadata such as GPS coordinates and device details, and videos are transcoded with their metadata removed. Animated GIFs are re-encoded frame by frame as well, which drops any comment or XMP blocks they carried.
6. How we use information
We use personal information only to:
- provide the service: create and run your account, show your posts and messages to the people you chose, deliver notifications, and process your media;
- keep accounts and the service secure: authenticate you, send sign-in alerts and password-reset emails, rate-limit abuse, run bot checks, and detect and contain spam, fraud and bot networks;
- enforce our Terms and Community Guidelines: review reports, take moderation action and handle appeals;
- answer you when you contact support, including privacy requests;
- send you service email you need, such as account confirmation, security alerts, moderation notices, replies to your tickets, and notice of material changes to our terms or this policy;
- comply with the law, respond to valid legal process, and protect the rights, safety and property of our members, the public and us.
We do not send marketing email. Feeds are chronological and are not personalized from your behavior.
7. Who can see what
- The public internet: nothing about you. Logged-out visitors see only the home page, the About page and these legal pages. Search engines are told not to index anything else, and media files are served only to signed-in members.
- Other members: your username, display name, profile picture and the profile details you added. Each post can be shared with all members, with friends only, or with no one but you. Your privacy settings control things like who can see your friends list, who can message you and who can post on your wall.
- People you block: nothing. Blocked members cannot see your profile, posts or messages, and you will not see theirs.
- Moderators and administrators: a small number of trusted staff can see account details, reported content, moderation and support records, invite lineage, sign-up signals and security events when they need to for moderation, support, security or legal compliance. Every moderation action is logged. Staff accounts are required to use two-factor authentication.
8. Private messages
Direct and group messages are visible only to their participants in the app. However, they are not end-to-end encrypted: they are stored on our server as plain text that the operator of the service can technically read. Our staff do not browse private messages. A message or conversation may be reviewed when a participant reports it, when we are investigating abuse such as spam or a bot network, or when we are legally required to disclose it. When you delete a message, it is removed from the conversation, and the deleted copy is purged from our database after 30 days unless it is under a legal hold.
9. Who we share information with
We do not sell personal information, we do not "share" it for cross-context behavioral advertising, and no third party collects information about your activity on The Social Web for its own purposes, apart from the site behind a profile song you choose to play (see Profile songs below). We rely on only these service providers, each of which receives only what it needs to do its job for us:
| Provider | What it does | What it receives |
|---|---|---|
| Cloudflare, Inc. (United States, global network) | DNS, TLS encryption, the secure tunnel to our server, firewall and attack protection, and the Turnstile bot check on the sign-in, sign-up and password-reset forms | Your IP address and request details (such as the address, headers and timing of each request) as traffic passes through its network; the Turnstile check also runs in your browser on those forms |
| Forward Email (United States) | Sends our email from [email protected] | Your email address and the contents of the email we send you (confirmations, alerts, moderation notices, support replies) |
| PayPal (only if you donate) | Processes donations on its own website | Whatever you give PayPal; we never see your payment details, and PayPal's own privacy policy applies |
Profile songs
If a member adds a profile song, nothing loads until you press play; when you do, your browser fetches the audio from the address the member provided and that host sees your IP address and browser details. Track pages on music platforms are plain links that open that platform. The request also tells the host that it came from The Social Web (our address only, never the page you were on), and what the host does with it is governed by its own privacy policy, not this one. We never fetch, copy or host the audio ourselves.
We may also disclose information:
- when the law requires it, in response to valid legal process, as described in our law enforcement guidelines;
- to the National Center for Missing & Exploited Children, when we find apparent child sexual abuse material, as federal law (18 U.S.C. § 2258A) requires;
- in an emergency, when we believe in good faith that disclosure is needed to prevent death or serious physical injury;
- if the service changes hands. If the service is ever transferred to another operator, your information would move with it. We would tell you beforehand, the new operator would be bound by the promises in this policy, and you would be able to delete your account before the transfer.
10. Where your information lives
The service runs on hardware we operate in Las Vegas, Nevada, USA, and your data is stored there. Traffic passes through Cloudflare's global network on its way to us. Our team also administers the service from Hong Kong, and working copies of some production data may be kept on our administrators' workstations there, protected by the same access controls. By using the service you understand that your information is processed in the United States and may be accessed from Hong Kong.
11. How long we keep it
A housekeeping job runs every day and enforces this schedule automatically. Content under a legal hold is the only exception: it is preserved for at least 365 days after the hold is placed (and longer if the law or a court requires) regardless of the schedule.
| Information | How long |
|---|---|
| Your account, profile, posts, comments, messages and media | Until you delete them or your account |
| Posts, comments, messages and media you delete | Removed from the service immediately and purged from the database after 30 days |
| A deleted account and everything it owns | Hidden immediately, permanently erased after a 30-day grace period (signing in during that period cancels the deletion) |
| Sign-in sessions (IP address, user agent) | Expire after 30 days without use, or when you sign out or end them |
| Security and account event logs, including IP addresses | 90 days |
| Sign-up IP address and user agent | 180 days after sign-up (cleared automatically; kept longer only under a legal hold) |
| Invite lineage (who invited whom) | For as long as the account exists |
| Notifications | 90 days |
| Resolved reports | 730 days after they are resolved |
| Moderation log | 730 days |
| Closed support tickets | 730 days after they are closed |
| Unused invite codes | Expire after 90 days and are deleted 30 days later |
| Email confirmation and password-reset links | Deleted about a day after they expire or are used |
| Backups | Rotated on a similar schedule, so deleted data ages out of backups as well |
When a reported account or its content is under review, the related records are kept until the review and any appeal are finished, and moderation records about an account can outlive the account itself for the period above, so that banned people cannot simply delete and return.
12. Your choices and rights
- See and download your data: export a machine-readable (JSON) copy of your account data any time from Settings → Account.
- Correct it: edit your profile, email address and settings yourself. For anything you cannot change yourself, ask us.
- Delete it: delete individual posts, comments and messages, or delete your whole account from Settings → Account.
- Control who sees it: choose visibility per post, and use the privacy settings and blocking.
- Control email: turn sign-in alerts and other notifications on or off in Settings. Security and legal notices are always sent.
- Make a privacy request: open a ticket in the "privacy request" category at Support, or email [email protected], to ask for access, correction, deletion or a portable copy of your information, or to ask any question about this policy. We answer within 45 days. If the law allows us more time and we need it, we will tell you why within that window. To protect you, we verify requests by asking you to make them while signed in or from the email address on your account.
- Global Privacy Control and "Do Not Sell": we honor Global Privacy Control signals and "do not sell or share" requests. Because we never sell or share personal information and use no trackers, there is nothing to switch off, and you are already opted out.
We will never treat you differently, charge you more or give you a worse service for exercising any of these rights.
13. U.S. state privacy rights
Residents of California (CCPA as amended by the CPRA), Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and other states with comprehensive privacy laws have rights to know what personal information we collect, to access it, to correct it, to delete it, to receive a portable copy, and to opt out of its sale, of sharing for targeted advertising, and of profiling. You can exercise all of them as described in section 12. You may use an authorized agent; we will ask the agent for proof of your authorization and may ask you to confirm the request from your account. If we decline a request, we will explain why, and you may appeal by replying to our answer; we will respond to an appeal within the time the law allows and tell you how to contact your state attorney general if you disagree.
For the record, in the past twelve months we collected these categories of personal information, all from you, your devices or other members, for the purposes in section 6:
- Identifiers: username, email address, IP address, account and session identifiers.
- Customer records: the account details described in section 3.
- Internet or other electronic network activity on our service: sessions, security events and server logs. Not your activity anywhere else.
- Audio, electronic or visual information: photos and videos you upload.
- User content and communications: posts, comments and messages.
- Sensitive personal information: your account login (username with a hashed password) and the contents of messages you send through the service. We use it only to provide the service and keep it secure, as the law permits, and never to infer characteristics about you.
We disclosed identifiers and network activity to Cloudflare, and identifiers and email content to Forward Email, only to operate the service. We have not sold or shared personal information, and we have no actual knowledge of selling or sharing information about anyone under 16. We do not engage in profiling that produces legal or similarly significant effects.
14. Notice for Nevada residents
This notice is provided under Nevada Revised Statutes Chapter 603A.
- Categories of covered information we collect: username, email address, any name you choose to display, an identifier that allows you to be contacted online (your account), and the other information described in section 3.
- Third parties that may receive it: the service providers listed in section 9, and authorities when the law requires.
- Reviewing and changing your information: review and correct it in Settings, download it from Settings → Account, or ask us as described in section 12.
- Tracking across websites: no third party may collect covered information about your online activities over time and across different websites when you use The Social Web, and we do not do it either. The one exception is a member's profile song that you choose to play: your browser then loads it from the site that hosts it, under that site's own policy (see section 9).
- Sale of covered information: we do not sell covered information as defined in NRS 603A.333. You may still submit a verified request directing us not to sell it by emailing [email protected]; we will confirm it within 60 days.
- Changes to this notice: announced by a notice on the site and an updated effective date at the top of this page, plus an email for material changes, as described in section 17.
- Effective date: October 8, 2026.
15. Children
The Social Web is only for adults. Every member must confirm at sign-up that they are at least 18. We do not knowingly collect personal information from anyone under 18, and we never knowingly collect it from children under 13. If we learn that an account belongs to someone under 18, we close it and delete its information, except anything we are legally required to preserve. If you believe a minor is using the service, tell us at [email protected].
16. Security and breach notification
We protect your information with strong password hashing, encrypted connections, two-factor authentication, encrypted two-factor secrets, strict browser security policies, members-only media and limited staff access. Our Security page describes these measures in detail. Apart from two-factor secrets and hashed credentials, the database is not encrypted field by field; it is protected by access control on hardware we operate. No system is perfectly secure.
If a security breach exposes your personal information, we will notify affected members by email without unreasonable delay, as required by NRS 603A and other applicable laws, and tell you what happened, what information was involved and what you can do.
17. Changes to this policy
When we change this policy, we update the effective date at the top of the page and post a notice on the site. When a change is material, we also email the address on your account before it takes effect. We will never apply a change that weakens the promises in section 1 to information we collected before the change without your consent.
18. Contact
Questions, requests or complaints about privacy: email [email protected] or open a ticket at Support. BOT-HOLDINGS, LLC, doing business as codedatda.casa, Las Vegas, Nevada, USA; contact us by email for a mailing address.