Privacy Policy
What we do not collect
No email. No phone number. No real name. No profile. No address book. No contacts. No photos. No location. No social login tokens. No saved payment method. We do not integrate any SDK that collects device advertising identifiers (Android Advertising ID, iOS IDFA). Google AdSense, where enabled, sets its own advertising cookies through the browser — see "Advertising and cookies" below for how that works.
What we do collect, and why
A random session identifier (UUID) stored as an HttpOnly cookie. Purpose: so the server can distinguish one anonymous session from another — this is what remembers which stories you follow or liked, without any account. A random two-word handle (for example, "quiet-fern") generated per session. Purpose: a display name on your comments. You can reroll it any time. A hashed IP (one-way) with timestamp at the moment you confirm the 18+ gate, and a separately hashed IP used to enforce bans. Purpose: compliance evidence that the 18+ confirmation occurred, and abuse prevention. Neither hash is reversible into your real IP and neither is used for ad targeting. Aggregate telemetry: page views, error rates, and request timings. Purpose: keeping the site working. Stored on Cloudflare Analytics Engine with only the ephemeral session identifier attached; we cannot tie a row in that dataset back to an individual.
News: what you read, follow, and post
The news feed lets you like, follow, and comment on story threads without an account. When you like or follow a story, we store the story id against your anonymous session id so the app can show your likes and your followed stories back to you and keep per-story counts. When you post a comment, we store the comment text, your random handle, your session id, and a timestamp; comments are moderated (see "Third parties") and are publicly visible under the story. There is no reading history profile, no cross-site tracking, and no personalisation based on what you read — the feed is the same for everyone. You can stop following a story or unlike it at any time, which removes that association.
Confessions: what happens to a post
A confession is short anonymous text tied only to your session id (so you can delete your own) and a timestamp. There is no author identity beyond the ephemeral session. Confessions are moderated before they appear. You can delete your own confession at any time; deletion is immediate and permanent.
What we store and for how long
Session identifier: up to 30 days, rolling (extended every time you visit). News stories and updates: retained while live, and archived (hidden from the feed but kept for direct links / search-engine references) after a period of inactivity — never sold, never deleted purely to save space. News likes / follows / comments: kept while your session is active and the story is live; likes and follows are removed when you unlike/unfollow. Confession posts: up to 12 months by default, then automatically purged by a daily retention job; earlier if removed, auto-hidden for abuse signals, or deleted by the author. Reports: metadata (report ID, reason, reporting session ID, timestamp) plus any text evidence, retained for the time required to complete review, or longer if part of an ongoing safety or legal matter. Ban registry: session and IP hashes of banned sessions, retained indefinitely — the entire point of a ban is that it persists. Audit log: moderation actions, retained for operational review. Aggregate telemetry in Analytics Engine: 90-day retention (Cloudflare default). Cloudflare Workers operational logs: 7-day retention.
Where your data lives
Cloudflare Workers (compute), Cloudflare D1 (SQL — news stories, updates, likes, follows, comments; confessions; reports; audit log), Cloudflare KV (rate limits, bans, flags), Cloudflare R2 (report evidence — text only). Cloudflare edge locations are globally distributed; your request terminates at the nearest edge.
Your rights under GDPR, DPDP, CCPA, and equivalents
Right of access, erasure, rectification, portability, and objection apply where the relevant regulation applies to you. Because Agyata does not collect personal identifiers, most requests resolve as "we do not hold this data about you" — but we will confirm in writing. If you believe we hold data linkable to you, email privacy@agyata.com with enough context to identify the data (for example, a confession ID or a rough post time) and we will investigate and respond within 30 days.
Third parties
We use Cloudflare for compute, storage, and CDN. We use Workers AI for text moderation classification of confessions and news comments — prompts and outputs are not used to train models per Cloudflare terms. We use Sentry for error reporting. We use Google AdSense to serve ads (see "Advertising and cookies" below). Sponsored stories are supplied by the advertiser and labelled as sponsored; we do not hand advertisers any of your data — they simply pay to have a story shown to everyone. We do not sell data. We do not share data with advertisers beyond the standard AdSense-served placements.
Advertising and cookies
Agyata serves ads via Google AdSense and shows clearly-labelled sponsored stories in the news feed. AdSense and its partners may set cookies and similar identifiers on your device to personalise the ads you see, measure ad performance, and prevent repeated delivery of the same ad. These cookies are set by Google, not by Agyata, and are subject to Google's own privacy policy and ad-personalisation controls at https://adssettings.google.com. You can opt out of personalised ads at https://www.google.com/settings/ads. Where required by local law (EU, UK, California), AdSense surfaces its own consent prompt before setting non-essential cookies. Sponsored stories are not personalised — every reader sees the same sponsored content. Agyata itself sets no advertising cookies and does not share any identifier of yours with advertisers.
Children
Agyata is 18+ only. The 18+ gate is binding. If we learn a user is under 18, their session is terminated and any content they posted is removed. If you believe a user on Agyata is under 18, email safety@agyata.com immediately.
Changes
Material changes to this Privacy Policy will be announced in a site-wide banner for at least seven days before the change takes effect. The effective date and version number at the top of this page reflect the current revision. Historical versions are available on request by emailing privacy@agyata.com.
Contact
Privacy questions and data subject requests: privacy@agyata.com. General: ops@agyata.com.