Disclose
Privacy Policy
Last updated: 20 July 2026
1. Who We Are
This Privacy Policy explains how Disclose collects, uses, stores, shares, and protects personal information when you use https://discloseapp.com and related Disclose services.
Disclose is currently an unincorporated service operated by its individual developer. There is no company, charity, partnership, or other organisation behind Disclose at this time. In this policy, "Disclose", "we", "us", and "our" mean that individual operator acting for the Disclose service.
For privacy law purposes, the controller of personal information is the individual operator of Disclose. We have not appointed a data protection officer. Privacy requests can be sent to the contact details below.
2. Contact
For privacy questions, access or deletion requests, complaints, law-enforcement requests, or legal notices, contact us here:
Privacy email: privacy@discloseapp.com
Legal email: legal@discloseapp.com
Support form: discloseapp.com/support
Because Disclose is operated by an individual, a private postal address is not published here. If a postal address or legal name is required for a valid legal, privacy, or regulatory request, email us and explain the request.
3. Information We Collect
We collect the following information depending on how you use Disclose.
Account information
- User ID, username, display name, avatar URL, biography, verification status, donator status, account role, and account creation date.
- Email address, if you sign up with email or Google provides a verified email address.
- Password hash, if you use password login. We do not store your plain-text password.
- Google account ID, Google profile name, and verified Google email address if you use Google login.
- Roblox account ID, Roblox username, and Roblox display name if you use or link Roblox login.
Authentication and security information
- Session IDs, linked user IDs, account-vault IDs for stored account switching, and session expiry dates.
- Temporary OAuth state and code-verifier cookies for Google or Roblox login.
- Temporary encrypted signup-verification cookies containing pending signup details, a password hash, verification-code hash, expiry time, and attempt count.
- Network information, including IP addresses and a Vercel-provided TLS client fingerprint (JA4), used for rate limiting, abuse prevention, signup limits, and security logs. Rate-limit identifiers are converted into keyed hashes before they are stored.
- Hashed IP-related signup-security events, such as code requests and account creations.
- Cloudflare Turnstile verification results if a signup security check is required.
Content, media, and social activity
- Posts, comments, replies, repost notes, poll options, poll votes, spoiler flags, anonymous-post flags, pinned-post flags, and timestamps.
- Images, videos, audio files, media URLs, avatars, community icons, and community banners.
- Follows, followers, blocks, likes, comment likes, bookmarks, notifications, notification read status, community memberships, community roles, last-viewed community timestamps, and a recent activity timestamp used for online status.
- Direct messages, conversation participants, message content, message timestamps, message request status and sender, request chat message counts, and message read-state records.
Moderation, reports, and safety records
- Reports submitted by users, report categories, report details, reported content snapshots, attachment URLs, reporter labels, reported-user labels, review notes, and report status.
- Moderation actions, including warnings, suspensions, bans, terminations, reasons, internal notes, offensive-item references, durations, active status, start dates, expiry dates, moderator IDs where applicable, and whether AI was involved.
- Appeals, appeal statements, appeal review notes, appeal outcomes, acknowledgement status, and appeal bundle snapshots.
- Staff role, staff supervision, staff disciplinary, trial-staff approval, and administrator audit-log records where relevant to staff accounts.
Support and contact requests
- Support request category, subject, message, optional contact name, reply email, public ticket number, submission time, status, email-delivery records, messages exchanged with support, basic email-routing metadata such as sender, recipient, message IDs and receipt time, and linked account ID if you are signed in when you submit the request.
- Any information you choose to include in a support message, including account, privacy, safety, billing, bug, or other details needed to respond.
Purchase, donation, and payment information
Disc purchases and optional donations are processed by Stripe. We do not store full card numbers or card security codes. Stripe may receive payment details directly from you. We may send Stripe your email address, Disclose user ID, selected Disc pack or donation amount, currency, checkout session details, and payment metadata needed to process and fulfil the transaction.
Technical information
We and our service providers may process IP address, browser type, device type, operating system, referring page, pages requested, request times, server logs, diagnostics, and similar technical information needed to run, secure, debug, and improve Disclose. We do not ask your browser for GPS or precise device location.
4. Sources of Information
We collect information from:
- You, when you create an account, post, comment, upload media, send direct messages, report content, appeal moderation, donate, or contact us.
- Other users, when they interact with you, mention you, message you, report your content, or create moderation-relevant records.
- Google or Roblox, if you choose to use those login methods.
- Service providers that run Disclose, including hosting, database, media, email, payment, security, and AI providers.
- Technical logs generated when you use the service.
We do not buy contact lists from data brokers, collect marketing profiles from public databases, or use third-party advertising partners to build behavioural advertising profiles.
5. Sensitive Information
We do not require you to provide special-category or sensitive personal information, such as racial or ethnic origin, political opinions, religion, health information, sexual orientation, or similar information. However, Disclose is a social platform, so you may voluntarily include sensitive information in posts, comments, direct messages, reports, appeals, profiles, or media.
If you choose to include sensitive information in public content, that information may be visible to others and processed by Disclose to provide, moderate, secure, and enforce the service. Do not post sensitive information unless you understand that it may be processed and, for public areas, seen by other people.
6. How We Use Information
We use personal information to:
- Create, authenticate, secure, and manage accounts and stored account switching.
- Send signup verification emails, security notices, service notices, and policy notices.
- Receive, review, and respond to support, privacy, safety, billing, bug, and account requests.
- Display profiles, posts, comments, media, communities, notifications, direct messages, search results, and social interactions.
- Process Disc purchases and optional donations through Stripe, credit Disc balances, and prevent duplicate or fraudulent fulfilment.
- Run uploads, media storage, community features, polls, bookmarks, blocks, follows, likes, reposts, messages, and notifications.
- Prevent spam, account abuse, fraud, ban evasion, security threats, and misuse of Disclose.
- Review reports, enforce our Terms of Service, moderate content, handle appeals, and keep users safe.
- Generate optional AI comments or replies when those features are enabled or when you interact with the Disclose AI account.
- Use AI to triage reports and, in limited high-confidence cases, take moderation action on reported posts or comments.
- Debug, maintain, protect, and improve the service.
- Comply with laws, respond to lawful requests, resolve disputes, and protect legal rights.
7. Legal Bases
Where laws such as the EU GDPR or UK GDPR apply, we rely on the following legal bases:
- Contract: to provide accounts, login, content, media, communities, direct messages, purchases, donations, and core Disclose features you request.
- Legitimate interests: to secure Disclose, prevent abuse, moderate content, protect users, debug problems, maintain service reliability, understand feature use, and improve the product.
- Consent: where you choose optional settings, optional login methods, optional AI reply features, or where applicable law requires consent. You can withdraw consent where processing is based on consent.
- Legal obligations: to comply with applicable law, tax/accounting duties, lawful requests, regulatory duties, and dispute-handling obligations.
- Vital interests and safety: where processing is necessary to protect someone from serious harm.
If you make sensitive information public through Disclose, we may process it because you made it public, because it is necessary to provide or moderate the service, or on another basis allowed by applicable law.
8. Public Information, Limited-Audience Posts, and Anonymous Posts
Disclose is a social platform. Usernames, display names, avatars, bios, public posts, comments, replies, reposts, communities, community membership, follower/following relationships, badges, visible interactions, and public media may be visible to other users or the public depending on the feature.
Personal posts can be shared publicly or with accepted friends only. Friends-only posts are not shown in public search, trends, or reposts, and access can change when a friendship ends.
Public personal posts and their comments may be viewed through a direct link by people who are not signed in. Public profile and community information may also be viewed without an account. Community posts remain limited to community members.
Bookmarks are intended to be private unless Disclose clearly says otherwise.
Follower and following lists are visible by default. You can make both lists visible only to you in Privacy settings; their totals remain visible.
Direct messages are not public posts, but they are not end-to-end encrypted. They are stored by Disclose and may be accessed where necessary to provide messaging, investigate abuse, comply with law, or protect users and the service.
People who are not friends may be able to send a message request. You can limit new requests to anyone, followers and people you follow, or nobody in your privacy settings. Blocks always prevent new requests. Accepted request chats are limited until both people become friends.
Disclose stores message read-state records to provide unread counts. If read receipts are enabled in your privacy settings, other participants may also see how far you have read in a direct message or group conversation. You can disable that visibility without disabling unread counts for your own account.
Anonymous posts hide your account identity from other users where the feature says they are anonymous. They are not anonymous to Disclose. We store the account ID connected to anonymous posts for safety, moderation, security, abuse-prevention, and legal reasons.
9. Cookies and Similar Technologies
We use essential cookies, local storage, and similar technologies for login, authentication, account switching, signup verification, OAuth security, security checks, preferences, and core website functionality.
- The main session cookie and account-vault cookie are used to keep you signed in and support stored account switching. They are set for up to 30 days and may be refreshed when your session is refreshed.
- Temporary Google and Roblox OAuth cookies are used to protect login and linking flows and expire after about 10 minutes.
- The temporary signup-verification cookie expires after about 10 minutes.
- The temporary add-account cookie expires after about 15 minutes.
We do not currently use third-party analytics cookies or advertising cookies. If you block essential cookies, Disclose may not work correctly.
10. AI and Automated Systems
Disclose uses automated systems for search, ranking, notifications, spam prevention, signup-abuse controls, rate limiting, security checks, and moderation workflows.
Disclose may use OpenAI to support optional AI comments, replies, Wisp direct messages, and report triage. When these features run, relevant post text, comment text, Wisp conversation context, the coarse device-local weekday and hour supplied for Wisp direct messages, report text, attachment URLs, images, and audio attachments or transcripts may be sent to OpenAI for processing. Disclose does not send a location or timezone for this feature and does not store this local-time context. We configure supported OpenAI response-generation requests not to store inputs for model training or later use where the API supports that setting.
AI moderation is used to help review reports. AI suggestions may be advisory for administrators. In limited cases, if a report about a post or comment is high-confidence and supported by valid evidence, the system may automatically remove the content and create a moderation action such as a warning, suspension, ban, or termination. Where a decision significantly affects your account, you may use the available appeal flow or contact us to request human review.
11. Service Providers
We use third-party providers to operate Disclose. They process information only as needed to provide services to us, comply with law, and protect their services.
- Vercel: application hosting, deployment, serverless infrastructure, and related logs.
- PostgreSQL database provider: database hosting for account, content, community, session, notification, moderation, and platform data.
- UploadThing: media uploads and storage for images, videos, audio, avatars, community icons, and banners.
- Stripe: Disc purchase and optional donation checkout and payment processing.
- Resend: signup verification and transactional email delivery and receipt, including support confirmations and two-way support replies.
- Google: optional Google login.
- Roblox: optional Roblox login and account linking.
- Cloudflare Turnstile: signup security checks when needed.
- OpenAI: optional AI replies, Wisp direct messages, AI report triage, image review, and audio transcription for AI-enabled features.
We may change providers as Disclose develops. If a provider change materially changes how personal information is processed, we will update this policy.
12. How We Share Information
We may share personal information:
- With other users or the public when you use public or social features.
- With service providers listed above, as needed to operate Disclose.
- With authorised moderators and administrators where needed to enforce rules, investigate abuse, manage communities, review appeals, or protect the service.
- With payment, email, login, media, security, AI, hosting, and database providers as described in this policy, including database hosting for direct messages.
- With law enforcement, regulators, courts, or other parties where we believe disclosure is legally required or necessary to protect users, the public, Disclose, or legal rights.
- If Disclose is transferred to a company or another operator in the future, as part of that transfer, subject to this policy or a replacement policy notified to users.
We do not sell personal information. We do not share personal information for cross-context behavioural advertising or targeted advertising. We do not use third-party ad networks.
13. International Transfers
Disclose is intended for global use. Your information may be processed in New Zealand, the United States, the European Economic Area, the United Kingdom, or other countries where we or our providers operate.
Where required by law, we rely on appropriate safeguards such as provider data-processing terms, standard contractual clauses, adequacy decisions, transfer-risk assessments, or other lawful transfer mechanisms.
14. Retention
We keep personal information only for as long as reasonably needed for the purposes in this policy, unless a longer period is required or permitted by law.
- Account information is generally kept while your account exists.
- Session records are kept until they expire or are removed. Sessions usually expire after up to 30 days unless refreshed.
- Signup-security events based on hashed IP-related information are kept for about 30 days.
- Rate-limit buckets contain keyed hashes rather than the raw identifier. They expire at the end of their quota window and are removed by the daily cleanup job.
- Temporary signup and OAuth cookies expire in minutes as described above.
- Posts, comments, media, direct messages, social interactions, communities, and related records are generally kept while the account, content, conversation, or community exists. Routine activity notifications are generally kept for up to 90 days, and posting-streak loss notifications for up to 30 days. Pending friend-request and anonymous-message notifications are kept until the related request or message is resolved or deleted. You can also delete eligible notifications yourself.
- Account-safety, report-outcome, and copyright notices, as well as reports, moderation actions, appeals, staff disciplinary records, and administrator audit logs, may be kept longer for safety, abuse-prevention, legal, audit, and enforcement reasons.
- Purchase, donation, Disc fulfilment, and payment metadata may be kept as needed for accounting, tax, fraud-prevention, dispute, and legal reasons.
- Support requests may be kept while needed to respond, maintain a support history, investigate safety or account issues, comply with law, and protect Disclose or users.
- Backups may retain deleted information for a limited period before they are overwritten or deleted.
15. Deletion, Correction, and Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal information. You may also have rights to withdraw consent, appeal a refused request, object to certain profiling, or request human review of certain automated decisions.
New Zealand users may request access to and correction of personal information. UK, EEA, and Swiss users may have GDPR-style rights. Australian, Canadian, Californian, and other US state residents may have additional rights where those laws apply. Even where a particular law does not strictly apply to Disclose, you can still contact us and we will try to respond reasonably.
To make a request, email privacy@discloseapp.com or use the support form. We may need to verify your identity or authority before responding. Some requests may be refused or limited where information is needed for safety, security, fraud prevention, legal compliance, evidence, disputes, another person's rights, or the integrity of Disclose.
You can update some profile or account information in Disclose, manage blocked users in Privacy settings, and delete your account in Account settings. Account deletion signs the account out and hides its profile and posts from the active service. Its username remains unavailable, and some records may be retained where needed for account recovery, safety, security, moderation, legal compliance, disputes, support history, backups, or another person's rights. You may separately request erasure by contacting us.
16. Children and Teen Users
Disclose is not intended for users below the minimum age required by the laws where they live or by our Terms of Service. We do not currently ask every user for their date of birth, so we may not always know a user's age.
If we learn that a user is not old enough to use Disclose, we may restrict, suspend, or delete the account and related information, subject to safety, legal, moderation, and backup-retention needs. Parents or guardians can contact us at privacy@discloseapp.com.
17. Security
We use reasonable technical and organisational measures to protect personal information, including password hashing, HTTP-only cookies, session expiry, access controls, rate limits, signup abuse controls, secure hosting, database controls, and moderation and security monitoring.
No internet service can be guaranteed to be perfectly secure. You are responsible for keeping your account credentials secure and for contacting us if you believe your account or information has been compromised.
If we become aware of a data breach that requires notification, we will notify affected users or regulators as required by applicable law.
18. Do Not Track, Ads, and Sale of Data
Some browsers send Do Not Track signals. There is no single accepted standard for responding to these signals, and Disclose does not currently respond to them in a specific way.
We do not use targeted advertising, third-party advertising cookies, or third-party analytics cookies. We do not sell personal information or share it for cross-context behavioural advertising. Because of that, Global Privacy Control signals do not currently change how Disclose behaves.
19. Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the "Last updated" date above. If changes are material, we may provide additional notice through Disclose, email, or another reasonable method.
20. Complaints
Please contact us first so we can try to resolve your concern. If you are not satisfied, you may be able to complain to your local privacy regulator, such as the New Zealand Office of the Privacy Commissioner, the UK Information Commissioner's Office, an EU supervisory authority, the Australian Information Commissioner, a Canadian privacy commissioner, a US state attorney general, or another authority that applies where you live.
Privacy email: privacy@discloseapp.com
Legal email: legal@discloseapp.com
Support form: discloseapp.com/support