Privacy Policy
This policy describes the information pleasedtobe processes, how current privacy and visibility controls work, and where the pre-launch product still requires provider-specific and jurisdiction-specific legal disclosures.
Pre-launch legal notice
This policy reflects the current pleasedtobe product and safety design. pleasedtobe is still in pre-launch development. The final legal operator identity, legal contact information, jurisdictional provisions, and provider-specific disclosures must be reviewed and finalized by qualified counsel before public launch.
1. Scope
This Privacy Policy explains the information pleasedtobe currently collects, stores, uses, and exposes through the pre-launch service. It covers account registration, age verification, profiles, posts, social relationships, direct messages, reports, moderation records, policy acceptance, and profile media.
The production service provider list, legal operator identity, privacy contact, international-transfer terms, and jurisdiction-specific rights process must be finalized before public launch.
2. Account and identity information
- Email address, username, display name, biography, avatar URL, and account preferences.
- Password hashes. pleasedtobe stores a cryptographic password hash rather than the password itself.
- Account status, verification status, role, age-verification state, strike count, and moderation state.
- Session tokens used to keep you signed in. The current session cookie is HTTP-only, SameSite=Lax, and configured for secure transport in production.
3. Age-verification information
The current development build stores an age-verification provider name, provider reference ID, verification status, verified age threshold such as 18+, and relevant timestamps. The development environment currently uses a mock provider; a production age-verification provider is not yet configured.
Before production age verification is enabled, this policy must be updated to identify the provider and accurately disclose any identity-document, facial, biometric, or other information processed by that provider and whether pleasedtobe receives or retains any of it. pleasedtobe will not provide an internal moderator/admin path for manually overriding the provider's final age-eligibility result.
4. Content and social information
- Posts, replies, content labels, external media URLs, media type, and media alt text.
- Profile customization, profile modules, background settings, image and gallery assets, links, polls, poll votes, featured profiles, and profile music links.
- Follower relationships and block relationships.
- Direct-message conversations, message-request state, message content, unread counts, read timestamps, decline state, and message-retry settings.
- Notifications generated by follows, likes, replies, moderation events, or system activity.
5. Reports, moderation, and policy records
- Reports you submit, including target, category, description, priority, status, and timestamps.
- Moderation notes, strikes, restrictions, and related administrative records.
- Policy-acceptance records, including policy type, policy version, acceptance time, IP address when available through request headers, and user-agent string.
6. How information is used
- Create and authenticate accounts and enforce adults-only access.
- Operate feeds, profiles, search, discovery, follows, blocks, polls, notifications, and direct messaging.
- Apply privacy, sensitive-content, and message-request settings.
- Store and display user-generated content and profile media.
- Investigate reports, enforce platform rules, prevent abuse, and maintain security.
- Record policy consent and determine whether a user must accept an updated policy version.
- Diagnose, maintain, and improve service functionality.
7. Search, visibility, and profile controls
Users can control profile visibility, search/discovery visibility, follower availability, and who may start direct-message conversations. Search excludes accounts that opt out of discovery and accounts involved in a block relationship with the searching user.
Profile visibility controls access through the pleasedtobe application. It does not necessarily make every externally hosted or publicly readable media URL private.
8. Public-read profile media
Current profile background, Image-module, and Gallery-module uploads are stored through an S3-compatible object-storage system using a public-read bucket so browsers can render those assets. As a result, an object URL may be accessible to someone who obtains the URL even if the related profile later becomes followers-only or private.
Do not upload profile media that must remain confidential. A future private-media architecture would require product changes in addition to policy changes.
9. Direct messages
Direct-message content is stored so participants can view the conversation. Message state includes pending, active, and declined requests, unread counts, read timestamps, and retry/reopen controls.
Blocking prevents further messaging between the blocked accounts. Moderation access to message content is not currently exposed through a dedicated per-message reporting interface; that functionality is deferred and must be addressed separately if added.
10. Service providers and external services
pleasedtobe currently uses PostgreSQL through Neon-compatible infrastructure and an S3-compatible object-storage layer, with Neon Object Storage documented as the current profile-media backend. Infrastructure providers process data as needed to host and deliver the service.
When a profile embeds Spotify or SoundCloud content, or loads a direct external audio/media URL, the visitor's browser may connect directly to that third-party service. Those providers may receive technical information and apply their own cookies or tracking under their own policies.
11. Data retention
Account, content, messaging, moderation, report, and policy records are retained while needed to operate the service and for legitimate safety, security, moderation, legal, and operational purposes. Current code does not implement a single platform-wide automatic retention schedule.
Some content can be removed through existing product controls, and some associated object-storage files are deleted when a user replaces or removes supported profile assets. Backups, moderation records, legal holds, or third-party copies may persist for additional periods.
12. Security
pleasedtobe uses password hashing, HTTP-only session cookies, authenticated API routes, ownership checks, block checks, and upload validation in several service areas. No system can guarantee absolute security.
Do not share passwords or session credentials. If you believe your account has been compromised, stop using the exposed credentials and use the security/contact process that will be published before launch.
13. Your controls and legal rights
Available product controls currently include profile visibility, discovery opt-out, follower settings, message privacy, declined-message retry settings, content-blur preferences, blocking, and deletion of certain user-created content or profile assets.
Depending on where you live, you may also have legal rights to access, correct, delete, restrict, or object to certain processing. A production privacy-request mechanism and jurisdiction-specific disclosures must be finalized before public launch.
14. Changes to this Privacy Policy
We may update this policy when data practices, providers, features, or legal requirements change. Material policy updates may require acceptance of a new policy version before continued access to active community features.