The Receipt

What we know about you: almost nothing. On purpose.

The strongest privacy policy is not a promise to protect your data. It’s not having it.

What we never collect

Real names · phone numbers · email addresses (optional recovery key instead) · precise location · government ID of any kind.

What we strip automatically

EXIF and location metadata from every photo, the moment it’s uploaded, before it’s stored.

What we minimally hold, and for how long

Abuse-prevention data: short-lived hashed rate-limiting tokens only, no IPs in application logs, retention capped at 14 days, then purged by an automated job.

What happens if we’re ordered to identify a contributor

We can produce only what exists. A handle and its submissions cannot be mapped to a person, because the mapping was never created.

Why The Floor has no private messages

There is no direct-message feature anywhere on the platform, and there never will be. A private channel between two pseudonymous handles is a harassment vector and a way to pressure a contributor off the record. Every post on The Floor is public, that’s the safety design, not a missing feature.

What you should still do

Don’t reuse handles from other platforms. Don’t include faces or identifying details in photos. Consider a VPN. We do our part; these steps do yours.

Our commitment in writing

The full technical policy and its change log publish alongside participation features. A safety policy that changes silently is worthless.