Twittesia

Privacy Policy

Effective September 24, 2026

Twittesia never asks who you are. There is no sign-up, no email address, no password and no social login. This policy explains the little we do collect, why, who helps us process it and how long we keep it.

1. What we collect

  • An identity we invent. When you start, we generate a handle and a display name for you. Your picture is drawn in your browser from that handle, so it is never stored and never fetched from anyone. You gave us nothing to make any of it from.
  • Your content. The posts and comments you create, and the images, video and audio you attach to them. They are deleted 24 hours after you write them, whether or not you are still here.
  • Your chats, but not what you say in them. When you start a chat we keep which two identities are in it, when it began and when it ends, and the handles of anyone waiting to be let in. Nothing said in a chat is stored, by us or by anyone we use: messages pass between the two browsers and are kept nowhere. The key they are encrypted with lives in the part of the invite link after #, which your browser never sends us.
  • Your camera and microphone. Only while the camera or recorder window is open, and only once your browser has asked you. What they capture stays on your device until you attach it and send it; closing the window turns them off.
  • What is inside your files. JPEG, PNG and WebP images are drawn again in your browser before they upload, which leaves behind hidden details such as where a photo was taken and on what device. Video, audio, GIF and AVIF files upload exactly as they are, so any such details inside them go with them.
  • Your session. A random token in a cookie keeps your identity signed in. We store only a one-way fingerprint of it, never the token itself, and forget it when your identity ends. We don't record which browser or device you use.
  • Your IP address. Only to count how many requests come from one network in a short while, so that nobody can flood Twittesia. It is kept with that count, never with your identity or your content.
  • Usage and performance. Page views and loading performance, measured with Vercel Analytics and Speed Insights, which do not use cookies.

We do not ask for, and cannot receive, your name, email address, phone number or any other contact detail. If you put such a detail in a post, it is content like any other, visible to whoever can see that post, and deleted with it.

2. How we use it

  • To run Twittesia and show your content to the people you share it with.
  • To keep you signed in for the life of your identity, and to limit abuse.
  • To flag the text of posts and comments that falls in a harmful category, so readers can choose to have it hidden. A flag only blurs content for readers; it removes nothing.
  • To find and fix problems, and make Twittesia faster.

We send no email, because we have no address to send it to.

3. How long we keep it

  • Content. Posts and comments are deleted for good 24 hours after they are created.
  • Attached files. Deleted with the post or comment they belong to. Copies kept by the network's caches, or by a browser that already opened them, can outlast it by up to a day. A file whose post or comment was never sent is deleted within a day.
  • Your identity. It stops working 24 hours after it was created, and is deleted then, or as soon as you leave. There is no way to recover it and no way for us to restore it.
  • Sessions. Until they expire or you leave.
  • Request counts. Your IP address and how many requests came from it, for a day at most.

4. Who processes it

We do not sell, rent or trade information about you. These services process it on our behalf, only to provide Twittesia:

  • Vercel hosts Twittesia and provides Analytics and Speed Insights.
  • Upstash stores your identity, your session, and your posts and comments, each until it expires, and the files you attach until they are deleted with them. Your browser sends files to it directly, and loads them from it when you view them.
  • TypeSafe checks the text of each post and comment when it is written, to flag harmful content. It receives only that text, and does not train its models on it. Chats are never sent to it: they are encrypted, and we cannot read them either.
  • jsDelivr delivers the list of emoji the reaction picker shows. Your browser loads it from them directly when you open the picker, so jsDelivr sees your IP address. Nothing else about you is sent.

We may also disclose information when the law requires it.

5. Cookies and local storage

We use a cookie only to keep your identity signed in. Your light or dark theme choice, and what content you choose to have hidden, are saved in your browser's local storage. We do not use advertising or tracking cookies.

6. Security

We protect data with encryption in transit. The strongest protection here is that there is so little to protect: no password to steal, no address to leak, and nothing that outlives a day. No system is perfectly secure, so we cannot guarantee absolute security.

7. Your rights

You can delete any post or comment you wrote, and leaving ends your identity immediately. Everything else deletes itself within a day, and afterwards we hold nothing that would let us find your information again, or connect it to you if you asked us to. Questions go to davidaragundy@outlook.com.

8. Changes to this policy

We may update this policy. When we do, we will publish the new version here and update the effective date. For significant changes, we will also post a notice on Twittesia, since we have no way to write to you.

9. Contact

Questions about your privacy? Write to davidaragundy@outlook.com.