Unsaid
Privacy
If you send a confession
- We store the text and which X handle it was sent to. You never need an account.
- We never store your IP address, account, device ID or browser fingerprint with a confession.
- To stop spam and let people block senders, we store keyed hashes that cannot be turned back into an IP address and cannot be matched across different recipients.
- There is no “who sent this” feature.
If you sign in with X
- X tells us your account id and handle. We read your public name, bio and photo from your X profile page.
- We cannot post, read DMs or see followers, and we throw X’s tokens away right after sign in.
- Your session is a random token in an HttpOnly cookie. We store only its hash.
Gifts and payments
- Gifts are paid through Stripe. Stripe (and we, as the platform) can see the payer’s payment details and email. The person who receives the gift never sees who paid.
- If you receive gifts, Stripe collects your identity, bank and tax details to pay you out. We never see your bank details.
- We keep a platform fee from each gift (shown before you set up payouts).
Moderation
- Our team can read confessions to handle reports and abuse. Every time staff view confessions it is recorded in an internal audit log.
- To stop abuse, each confession also stores a keyed hash of the sender’s IP address that lets staff ban a sender site-wide. It cannot be turned back into an IP address.
Storage
Confessions are encrypted (AES-256-GCM) before they are saved. Delete a confession and it is gone for good.