Security and compliance
Compliance center
This page summarizes operational safeguards and user commitments. It complements the Privacy policy, Terms, and Legal notice.
Security controls
Firebase authentication, verified-email checks, short-lived identity tokens, Cloudflare Turnstile, IP and user rate limits, strict schemas, payload limits, CORS allowlists, security headers, Firestore deny-by-default rules, and backend ownership checks protect sensitive operations.
Uploads use controlled media identifiers, MIME and size validation, image compression, storage quotas, and server-authorized operations. Public errors are generic while technical details remain in restricted logs.
Deletion and evidence
Timeline deletion uses a 24-hour reversible trash. Deleted messages are tombstoned and their prior versions are kept in a server-only history for up to 365 days.
Account export and deletion controls are available. Some restricted evidence may remain temporarily where required for security, backups, disputes, moderation, or law.
Analytics and consent
Analytics consent is separate from accepting the user contract. Optional Google measurement remains denied until the configured consent platform records a valid choice.
React route changes emit one page_view event through the existing Google tag path. The implementation intentionally avoids installing a second History Change tracker that would double-count views.
Reports and review
Use Contact + suggestions to report unlawful content, rights infringement, abuse, privacy issues, or vulnerabilities. Do not exploit a vulnerability or access third-party data.
Infrastructure settings, provider contracts, backups, alerts, and these documents require periodic review. This page is operational information, not a certification or a substitute for qualified legal advice.