Confessions Of

Privacy notice

Anonymity is the product. This notice explains, in plain English, what we hold about you, why, for how long, and what you can do about it. It is written to meet UK GDPR and the Data Protection Act 2018.

1. Who we are

The data controller is [data controller name — set in Admin → Settings] (“we”). You can reach us about anything in this notice at privacy@confesstheweb.com.

2. What we collect and why

DataWhyLawful basis
Account: email address, hashed password, optional two-factor secret (encrypted), the date you confirmed you are over 18.To run your account, sign you in, reset passwords, and tell you about moderation decisions on your content.Contract (providing the service you signed up for).
Anonymous profile: a generated handle, avatar colour, level, XP, badges, optional bio.To give you a persistent anonymous identity and reputation.Contract.
Content and activity: posts, comments, votes, reactions, saves, reports, blocks.To publish and rank content, run Truth or Myth results, and keep the community safe.Contract; legitimate interests (safety, integrity).
Verification: the domain of a work email and a one-way hash of the address, or a short note you send a moderator. We never store the work email address itself.To confirm you are a genuine insider without linking your identity to your handle.Legitimate interests (trust in the platform); the work email is processed only to send you a code.
Usage events: pages and content viewed, Web interactions, shares, searches, keyed to a random visitor id (cookie) and a keyed hash of your IP address.To understand what people explore, measure the product, and enforce rate limits against abuse.Legitimate interests (product improvement, security). No advertising or profiling.
Moderation and safety records: reports, automated risk flags, moderator decisions, notes, an audit log.To moderate content, handle complaints and appeals, and meet our duties under the Online Safety Act 2023.Legal obligation; legitimate interests (safety).
Server logs: IP address, requested URL, browser type, timestamp, held by our web server.Security, debugging and abuse investigation.Legitimate interests (security).

We do not collect your real name, workplace, or location, and we ask you not to include them in anything you post. Where our automated screening detects such details, the content is held for a human moderator.

3. Anonymity, and its limits

Your handle is generated and is never publicly linked to your email. Moderators can see which account posted which content; they are bound by our internal procedures and see verification evidence only where needed for a decision. We will disclose account information to third parties only where the law requires it (for example a court order or a lawful request from the police), or where we reasonably believe it necessary to prevent serious harm to a person, particularly a child.

4. Who else sees your data

  • Our hosting provider, whose servers in the United Kingdom / European Economic Area hold the site and database.
  • Anthropic, whose AI service we use to draft editorial content, tag and summarise. We send it only published content, never account data, verification data, or unpublished submissions. Anthropic processes data in the United States under standard contractual safeguards.
  • Google Fonts supplies the typefaces on the site; loading them sends your IP address to Google.
  • Email delivery is handled by our own mail server for verification codes and password resets.

We do not sell personal data, share it with advertisers, or use it to build advertising profiles. Any future trend or “Insider Index” reporting uses aggregated, anonymised data only.

5. Automated decisions

New posts and comments go through automated screening that looks for personal details, identifiable people or organisations, threats, and safeguarding-sensitive language. The screening decides only whether a human must review the item before it goes live; it never rejects content on its own. You can ask for any decision to be reviewed by a person by replying to the notification or emailing us.

6. How long we keep things

DataRetention
Account and profileWhile your account exists. On closure we delete your email, password and two-factor data immediately and turn your handle into an anonymous tombstone so published content keeps its attribution without identifying you.
Published contentEphemeral content leaves public view after 48–96 hours; persistent and Vault content stays published. Expired and removed content is retained privately for up to 12 months for moderation, appeals, abuse prevention and legal compliance, then deleted.
Verification dataDomain and hash: while your account is verified. Manual review notes: deleted within 30 days of the decision.
Raw usage events90 days, then only aggregated daily counts remain.
Moderation records, reports, audit logUp to 6 years, because they may be needed for legal claims and Online Safety Act record-keeping.
Server logsRotated after 30 days.

7. Your rights

Under UK GDPR you can ask us to: give you a copy of your data; correct it; delete it; restrict or object to how we use it; and, for data you gave us, provide it in a portable format. You can withdraw consent at any time where consent is the basis. Email privacy@confesstheweb.com from the address on your account, or use Settings → Close account. We will respond within one month.

If you are unhappy with how we handle your data you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would appreciate the chance to resolve it first.

8. Children

Confessions Of is for adults. You must be 18 or over to create an account, and we do not knowingly hold data about anyone younger. If you believe a child has an account, tell us at safety@confesstheweb.com and we will close it. Content that could identify or concern a child is prohibited and removed.

9. Cookies

We set three first-party cookies and no third-party or advertising cookies. Details are on the cookies page.

10. Security

Passwords are hashed with bcrypt. Two-factor secrets are encrypted. All traffic is HTTPS. Verification emails are never stored in full. The database and secrets sit outside the web root, and moderation access is limited to named staff accounts that must use two-factor authentication.

11. Changes

We will post changes here with a new version number and effective date, and tell signed-in users of anything material.