Privacy and content policy.

Who can enter and what is allowed

This service is intended for adults aged 18 or older. Admission currently uses a self-declaration and an educational rules quiz; it does not verify age or prove that identities belong to different people. Adult topics and fictitious stories are permitted. Threats, self-harm encouragement, sexual content involving minors, targeted harassment, hate, identifying private details, and doxxing are prohibited.

Storage and access

The database is on the operator’s server. Selected hosting provider: Render. Provider connection logs, lawful requests, and operational access must be assessed before public launch. The application does not store network addresses in its database and sends no private text to external analytics.

Matched participants see their room. Senior moderators can review history and restricted evidence; juniors can review cases permitted by their role. Access and actions are attributed in an append-only audit log. A username is a pseudonym, and repeated prompts or identifying text can connect activity. Per-room aliases hide the ordinary username from other participants, not from authorized moderators.

Consent and withdrawal

Every submission records the choice between one encounter and archival reuse. Only explicitly reusable Gossip prompts enter future rooms. Withdrawal stops future matching and closes active rooms; existing participant history retains text. Senior suppression replaces the prompt and all messages in affected rooms with a removal notice while retaining restricted evidence. A download is a separate private copy that cannot be recalled.

Retention and account controls

Ordinary guest-only conversations expire after 30 days. Registered conversation history is kept for up to 365 days; flagged guest evidence is kept for 180 days. Cleared original text and suppressed quotations expire 180 days after their latest relevant case decision; unresolved cases and recorded legal holds extend retention. Physical storage and encrypted backup copies can persist until their separate rotation. Unreferenced old confessions expire after the configured account-history window. Private registered-account karma ledgers and reserved usernames and audit records remain so deletion does not enable impersonation or erase action history.

Deleting from history removes your access and prevents future prompt reuse; it does not erase another participant’s copies or moderation evidence. Account deletion ends login access and reserves the name. Change a password or sign out all sessions in account settings. Existing older passwords continue to work and their hashes upgrade after successful sign-in; new passwords require at least 12 characters and common-password checks.

Suggestions and problems

Authenticated visitors, including guests, may submit feedback through the booth’s footer. Feedback is a separate moderator inbox, independent of conduct reports and enforcement. It includes the submitting account or guest username and is kept for up to 180 days after submission. No conversation is attached automatically. Do not include passwords or other people’s identifying details.

Moderation and private observations

Static patterns mask or suppress matching text; they cannot recognize every harmful statement or evasive spelling. Reports are reviewed individually or through an explicitly selected, reasoned batch. Resolving a case does not reverse enforcement. Temporary suspension can expire or be manually restored; permanent suspension cannot be restored.

Private karma records are an experimental moderator-only record of conversation length, balance, early exit, and timely reports. They have no effect on access, matching, punishment, privileges, report weight, or participant-visible status.

Contact

Safety and privacy contact: mailto:ConfessionBoothAdmin@protonmail.com. Public launch also requires an identified operator, staffed coverage, jurisdiction and age-assurance review, and a tested severe-case response.

Return to Confession Booth