Privacy

We can't leak what we don't collect.

The whole policy in one line: collect the minimum, contain what's collected, and never let the database contradict the mask.

LAST UPDATED · SEPTEMBER 2026

Who may use Kuralok

Kuralok is for people 18 or older. There are no accounts for anyone younger, and we do not collect a date of birth — creating an account is your confirmation that you are an adult, recorded with the terms you agree to.

What we collect

Four things at signup: your full name, a username, your email, and a password (stored as a one-way hash nobody here can read). That is the complete list. We never ask for a phone number — account recovery is by email.

Alongside them, the account keeps two small records of its own. We record which Contributor Terms version you agreed to and when, so we can show which text bound the account. And your own hide list and block list — the entries you hid and the writers you blocked — are kept for you alone: private to you, shown to nobody, and erased with your account.

Where each one appears

Your full name is shown in exactly one public place: your profile page. Bylines, comments, feeds and search always show your username — or Anonymous. Your email is never public and is used for verification, recovery and the notifications you choose. Your password hash is used to log you in, and for nothing else.

Anonymous reading

You can read everything without an account. View counting uses a fingerprint that is rotated daily and never stored in reversible form — we cannot reconstruct who read what yesterday, and neither can anyone who takes the database.

Anonymous writing

Readers never see who wrote a masked entry, and that can never be undone. Moderators always can — which is how a report on an anonymous entry is acted on. The link between a masked entry and its author is kept inside the database and is structurally excluded from everything public — pages, feeds, search, filters, counts and lists — so no reader, and nobody who takes the database, can put a name back on it.

What we don't do

No advertising, no trackers, no analytics resold to anyone, no data brokers. Session cookies are httpOnly and used for login alone.

Who else touches your data

Two companies, and we name them because you are entitled to know who they are.Cloudflare carries every request to this site and caches public pages, so it handles the IP address your browser presents. Resend sends our email — verification, password resets and moderation notices — so it handles your email address and the contents of those messages. Both are bound by contract to protect your data to the same standard we do, and neither is permitted to use it for anything else. Everything else — the database, the files and the moderation tools — runs on hardware we operate ourselves. There is no analytics provider, no advertising network and no third-party SDK in the app.

Deleting your account

Deletion is immediate and final — your password confirms it, and there is no grace period and no restore. Everything that identifies you is erased at once: your full name, email address, password, bio, the login record itself, every sign-in session on every device, your notifications and your block list. None of it stays in any live system. Your email is free again straight away; a new account made with it is a new account with no history.

Your username is retired permanently. Nobody, including you, can register it again, so nobody can ever pose as the account that wrote your old comments. Comments you wrote stay, attributed to “[deleted]” — not to your username and not to Anonymous — so the conversations they sit in stay whole. Reactions you gave stay in the counts, no longer linked to a name. Published entries stay, anonymised (byline Anonymous, as the terms say); want an entry gone entirely, delete it before deleting the account — entries you had already deleted are erased for good. Drafts, unpublished entries and cover photos you uploaded but never used are erased outright. Blocks other people placed on your account are theirs and stay in force.

Moderation records keep an account reference — the retired username — never your name or email: a report you filed, or one filed about you, cannot be wiped by deleting the account, but it no longer says who you were. Two things fade rather than vanish. Encrypted backups hold a copy for a limited time — our database backups for up to 60 days, and the weekly machine image on its own rotation, which keeps one snapshot for up to a year — and are used only for disaster recovery, never to bring anything back into service. And the emails we already sent you sit in our email provider's logs for its own short retention. Nothing else is kept anywhere. You are told all of this on the deletion screen before you confirm.

The iOS app

The Kuralok app for iPhone talks to the same service under the same rules. It adds nothing to what we collect: no analytics kit, no advertising identifier, no tracking. Your session lives in the device keychain. The app sends a random identifier generated on first launch with each request so that reads from many phones behind one network can be counted as distinct readers; it is mixed into the same daily-rotating view fingerprint and is never stored on its own. A cover photo you choose is re-encoded on our side and stripped of all metadata, location included, before anything is kept. You can block a writer (their comments and notifications disappear for you, and for nobody else), report any entry or comment to a person, and delete your account from Settings — the same deletion described above.

What we can't do

If a post was public under your name before you masked it, copies may already exist in search engines, archives or screenshots. We purge our own caches immediately, but we cannot recall the internet — and we won't pretend otherwise.