This Privacy Policy explains how the company operating Feed ("Feed," "we," "us," or "our") collects, uses, shares, and protects your information when you use our websites, mobile apps, and other services that link to this policy (together, the "Services"), and when you contact us through support or other channels. We may update this policy from time to time — when we do, we'll change the "Last updated" date above, and where the law requires it we'll give you additional notice of material changes through the Services. It's worth checking back occasionally.
What This Policy Covers
Feed is built around the idea that you should be able to share freely, gather safely, and keep hold of your own experience. That shapes how we handle data: we aim to collect only what we genuinely need to run the platform, give you meaningful control over what's visible about you, be plain about how your information is used, and build safety in from the start rather than bolting it on later.
This policy sets out:
- what information we collect;
- how we use it;
- when and why we might share it with others;
- the choices and rights you have over your data; and
- the extra rules that apply in certain regions, including the EU and parts of the United States.
Information We Collect
Broadly, the information we get falls into three buckets: what you give us directly, what's collected automatically when you use the platform, and what we occasionally receive from third parties.
What you give us directly
You provide some information when you create an account, when you talk to us, or when you sign up for updates. When you set up a Feed account, that includes:
- your display name and account handle;
- your email address; and
- your month and year of birth.
You may also optionally add a phone number. If you do, we store it in E.164 format and keep a salt-free SHA-256 hash of it so other users can find you through their own contacts by matching hashes — the same pattern Signal and WhatsApp have used for contact discovery. We never receive anyone else's raw contact list; a client only ever sends us hashes of numbers it already has.
What's collected automatically
When you use Feed, we may automatically collect certain information about how you access and interact with the platform, including:
- IP address;
- browser type and language settings;
- device type and operating system; and
- connection details used to reach the Services.
Your IP address can suggest an approximate location (country or city). We use that for things like language defaults and complying with regional legal requirements. If you choose to tag a post with your location, we may collect precise location data at the moment you create the tag — you control that through your device settings.
We use a small set of cookies and similar tools to keep you signed in, understand how people use Feed, improve performance and features, and analyse usage trends. The public website uses a single httpOnly, sameSite=lax authentication cookie for signed-in sessions; it does not load third-party analytics or advertising SDKs.
Content and media
When you upload photos, videos, or other media, your device may ask you to grant Feed access to your camera roll or storage. That permission is controlled entirely by your device settings and can be revoked at any time. We collect the content contained in what you post or upload, including:
- text;
- images or photographs;
- videos or livestreams; and
- other content shared through the Services.
From other sources
In some cases we receive information from third parties — for example:
- if you apply for account verification, we may use a third-party identity verification provider to confirm who you are;
- if you use a third-party authenticator app for multi-factor authentication, we may receive confirmation data from that service; and
- if you interact with Feed through another platform or service, we may receive limited information from that provider.
How We Use It
We use the information we collect to run, improve, and secure the Services. That includes using it to:
- create and manage your account;
- provide, maintain, and improve the platform;
- let you create, share, and interact with content;
- personalise your experience;
- send technical notices, security alerts, and support messages;
- send marketing communications (where you've opted in);
- analyse usage trends and platform performance;
- carry out research, testing, surveys, and troubleshooting;
- detect and prevent fraud, abuse, or illegal activity;
- enforce our Terms of Service, Privacy Policy, and Community Guidelines;
- comply with legal obligations; and
- produce aggregated or de-identified data that can't reasonably identify you.
Analytics
Feed provides first-party analytics to help creators understand how their posts are doing — views, engagement, audience trends. This is computed from platform activity, not sold to or shared with third-party analytics networks. We don't run third-party advertising or tracking SDKs on the public website.
Government & Legal Requests
We may disclose information when the law genuinely requires it — for example, in response to court orders, government legal orders, law enforcement investigations, or national security obligations. In every case we disclose only the minimum the law requires.
When we receive a request from a government or law enforcement agency for user information, Feed seeks to:
- require a valid legal basis before disclosing anything;
- review the request for legality and scope;
- disclose only the minimum the law requires; and
- challenge requests that appear unlawful or overly broad where appropriate.
Safety & Enforcement
Keeping the community safe sometimes means we have to share certain information to protect it. We may share information when necessary to:
- enforce our Terms of Service, Privacy Policy, or Community Guidelines;
- investigate abuse, spam, or malicious activity;
- protect the rights or safety of users or the public; or
- explain moderation or enforcement decisions.
We may also disclose information to trusted professional advisors — such as lawyers or business advisors — where it's necessary to do so.
Security
We work to protect your information with technical and organisational safeguards designed to keep personal data secure, including:
- encryption of data in transit (TLS) and, where appropriate, at rest;
- access controls that limit internal access to authorised personnel;
- monitoring systems designed to detect security incidents;
- security reviews and testing of platform infrastructure; and
- internal policies governing how employees handle personal data.
End-to-end encryption. Your private messages on Feed are end-to-end encrypted with the Signal Protocol (X3DH key agreement plus the Double Ratchet). Our servers only ever hold encrypted envelopes and public keys — we can't read your messages, and we don't want to. Private keys never leave your devices.
We implement reasonable safeguards, but no system can be guaranteed completely secure. You can help by choosing a strong password, keeping your login to yourself, and taking the usual care with your account.
Public Content
Feed is a platform for sharing. Once something is public, it can be hard to put back — even if you delete it from Feed, copies may exist elsewhere on the internet through search engines, web archives, or third-party services, and we can't control what those third parties do with it. Depending on your account settings, what you post may be visible to other users or to the public, and public content may be:
- viewed by other users of the platform;
- indexed by search engines;
- shared or reposted by other users; or
- copied, archived, or stored by third-party services outside of Feed.
Unauthorised access, collection, or use of data from the platform may result in enforcement action, including technical restrictions or account suspension. That includes monitoring for automated scraping or bulk collection of platform data, attempts to extract large volumes of user content or metadata, and activity designed to train automated systems or datasets without authorisation.
Data Retention
We keep personal information only for as long as we need it to provide the Services and fulfil the purposes described in this policy. Different kinds of information are kept for different periods depending on what they're for. In general:
- Account information is retained for as long as your account is active. When you delete your account, we begin removing your personal information from active systems.
- Content you've posted may take additional time to be removed from backup systems, and copies may continue to exist elsewhere on the internet through search engines, web archives, or third-party services — that's outside our control.
- Safety-related data may be kept for longer where the law requires it or where we need it to resolve disputes, enforce our policies, or prevent repeat violations.
We may also create and use aggregated, anonymised, or de-identified information that can't reasonably be used to identify an individual — for analysing platform usage, improving products, research, and statistical insights.
Your Choices
You have control over a lot of what's tied to your account.
Account information
You can access or update certain information in your account at any time through your account settings, and you can delete individual posts whenever you like. You can also control:
- whether your account is public or private;
- who can see your posts;
- what profile information is visible; and
- what content you share.
Account deletion
You can request deletion of your account by contacting privacy@postfeed.online. When we process a deletion request:
- your account is placed in a deletion queue;
- data directly associated with your account is removed from active systems; and
- you'll receive confirmation once deletion is complete.
Self-service account deletion from within the app is on our roadmap; until it ships, please email us and we'll handle it for you.
Cookies and tracking technologies
You can control or disable cookies through your browser settings. Disabling cookies may affect some functionality of the Services — for example, keeping you signed in.
Communications
You can opt out of marketing communications by following the unsubscribe instructions in the messages. Even after you opt out, we may still send non-promotional communications like security alerts or account-related notices.
Push notifications
With your permission, we may send push notifications to your mobile device. You can disable them through your device settings.
International Data Transfers
When we transfer personal data across borders, we take steps to make sure appropriate safeguards are in place, such as standard contractual clauses, contractual data protection commitments, or other legally recognised safeguards. You can request information about these safeguards by contacting us.
Your Rights in Europe
If you're in the European Economic Area or the United Kingdom, the following rights apply under the GDPR and the UK GDPR respectively.
Legal basis for processing
We process personal data only where we have a legal basis to do so, including:
- to perform our contract with you — providing the Services and enforcing the Terms of Service, Community Guidelines, and supplemental terms;
- for legitimate business reasons pursued by us or a third party, only where those reasons aren't overridden by your fundamental rights and freedoms — this covers things like detecting and preventing abuse or illegal activity, sending marketing communications, personalising your experience, improving the Services, and analytics;
- to comply with legal obligations, including tax, accounting, and reporting obligations and responding to government and legal requests; and
- with your consent, which you can withdraw at any time where processing is based on consent.
Minimum retention
We retain personal information only for the legally minimal amount of time needed to provide and maintain the Services, comply with legal obligations, resolve disputes and enforce agreements, and protect the safety and integrity of the platform.
Your data protection rights
Subject to applicable law, you may have the right to:
- access your personal data;
- request correction of inaccurate information;
- request deletion of your personal data;
- request restriction of certain processing;
- object to certain processing activities; and
- receive your personal data in a portable format.
Right to lodge a complaint
You have the right to lodge a complaint with the supervisory authority in the country where you live or work, or where the alleged violation occurred. A full list of EEA supervisory authorities is available from the European Data Protection Board. In the UK, you can contact the Information Commissioner's Office.
Age requirements
Users must be at least 16 years old to sign up. Feed does not knowingly collect or process personal data from anyone under 16. If we learn that we've collected personal data from someone under 16, we'll take steps to delete it as the law requires.
Data controller
The data controller responsible for personal data processed through the Services is the company operating Feed. For the formal legal name and registered address, see Contact Us below or email privacy@postfeed.online.
Data Protection Officer
Feed has appointed a Data Protection Officer (DPO) responsible for overseeing privacy and data protection compliance. You can reach the DPO at privacy@postfeed.online.
Your Rights in Certain U.S. States
We don't sell or trade personal information and we don't engage in targeted advertising as defined under applicable state privacy laws. Residents of certain U.S. states, including California, may have additional privacy rights. We collect and disclose certain categories of personal information, including:
- identifiers such as name or email address;
- internet activity information, such as IP address or device data;
- approximate geolocation information derived from IP address (such as country or city);
- audio or visual content such as photos or videos; and
- inferred information based on activity.
Depending on where you live, you may have the right to access your personal information, request correction of inaccurate information, request deletion of your personal information, or request information about disclosures to third parties. We won't discriminate against you for exercising your privacy rights.
You can contact our Data Protection Officer at privacy@postfeed.online for questions about this policy, exercising your privacy rights, concerns about data processing, or complaints related to data protection.
Children
Feed is intended for users 16 and older. People under 16 aren't permitted to create accounts or use the Services. If we learn that personal information from someone under 16 has been collected, we'll investigate and delete it unless the law requires us to keep it. Parents or guardians who believe a child has provided personal information should contact safety@postfeed.online.
Contact Us
If you have questions about this Privacy Policy or about how your information is handled, we'd like to hear from you.
Privacy & data protection
privacy@postfeed.online — Data Protection Officer, data subject requests, privacy concerns.
Safety & child protection
safety@postfeed.online — moderation appeals, child safety, urgent safety reports.
General support
support@postfeed.online — anything else.
This Privacy Policy is written in English and may be translated into other languages. If there's any difference between a translation and the English version, the English version controls.