Privacy Policy
Last updated 2026-05-21
This policy explains what data CTFO collects, why we collect it, and what we do with it. UK GDPR applies. The data controller is CTFO, ctfo.uk. Reach us via the contact form.
What we collect
- Account data: email, username, first name, last name, password hash (bcrypt, never the password itself), bio
- Content: posts, replies, follows, flags, pins, moderation actions
- Direct messages: stored encrypted at rest (AES-256-GCM, per-conversation key wrapped by a server-held master key). Metadata stored in the clear: who sent, who received, when. See the DM section below for when, and only when, a moderator can decrypt.
- Session and audit logs: IP address, user agent, action timestamps. Used to detect coordinated abuse and prevent spam. Kept for 90 days then deleted
- Cookies: one HttpOnly session cookie for keeping you logged in. No analytics or advertising cookies
Direct messages
DMs sit encrypted at rest. We do not scan them, read them for ad targeting, or train models on them. There are three situations in which a moderator can decrypt your messages, and each one is logged:
- You or the other participant reports a message. The plaintext of the reported message comes from the reporter's device.
- A valid UK legal request names your account (court order, warrant or statutory request).
- A credible imminent threat to life.
When a moderator unseals surrounding messages on a report, they have to type a written justification and the access is recorded with their name, the conversation id, the count of messages unsealed, and the reason. Aggregate counts will appear in the transparency report once we have enough activity to report meaningfully.
You control who can DM you in Settings. Blocking somebody hard-blocks DMs both ways. See Trust & Transparency for the full crypto and policy detail.
Why we collect it
- To run the platform (display posts, let people follow you, etc)
- To enforce the Rules (audit logs help spot brigading and bot networks)
- To comply with UK law where we have to
We don't profile you, we don't run targeted advertising and we don't sell data to anyone.
Who we share it with
- Other users: your posts, replies, profile and pin record are public by design
- UK law enforcement: only in response to a valid legal request (court order, warrant or equivalent). We push back on overbroad requests
- CSAM and credible threats to life: reported immediately to UK authorities
We never sell user data and we never share it with advertisers, brokers or "analytics partners".
Sub-processors
We use the following third parties to run the service. Each one only sees the data it needs for its specific job and processes it under its own privacy terms.
- Railway (UK and EU regions), hosts the application and database. Sees everything we store.
- Cloudflare Turnstile, bot-prevention widget on the signup form. When you submit signup, Cloudflare receives your IP address and a set of browser signals (headers, JavaScript environment, interaction timing) so it can score whether the request looks human. It does not receive your email, password or any other form field. Processed globally by Cloudflare, Inc. (US) under their privacy policy.
- Cloudflare R2, object storage for user-uploaded images, when image uploads are enabled. Stores the image bytes and the storage key. Does not see your account details.
- Brevo, transactional email provider for verification, password reset and email-change confirmation messages. Receives your email address and the contents of those system emails. We do not send marketing email.
If we change sub-processors we'll update this list and bump the “last updated” date.
How long we keep it
- Account data and content: while your account exists. Delete your account in Settings and we remove everything. Pin records remain public for transparency and stay tied to your @username, your real name can be kept private at any time via the "Keep my real name private" toggle in Settings
- DMs: kept until either you or the other participant deletes the message or leaves the conversation. Reported message ciphertext is retained for the legal retention period even if both parties delete, so we can comply with audit requirements.
- Audit logs: 90 days, then deleted automatically
- Backups: 30 days rolling, then overwritten
Your rights (UK GDPR)
You have the right to:
- Ask what data we have about you
- Correct it if it's wrong
- Delete it (account deletion in Settings handles this)
- Export it in a portable format
- Restrict how we use it
- Complain to the Information Commissioner's Office (ICO) at ico.org.uk
Use the contact form with the Privacy / data category for data access, export or deletion requests outside the in-app flow.
Cookies
We use one HttpOnly cookie (ctfo_session) to keep you logged in. No advertising cookies, no third-party trackers, no analytics tags. The cookie expires after 30 days. Logging out deletes it.
The signup page loads the Cloudflare Turnstile bot-prevention widget, which sets short-lived first-party cookies (e.g. cf_chl_*) and inspects browser signals to tell humans from bots. This only runs on the signup page and only for the duration of the challenge. We do not use it to profile or track you across the site.
Children
CTFO isn't for under-16s. We don't knowingly collect data from anyone under 16. If we find out we have, the account and its data are deleted.
Changes
We'll update this policy when our practices change. Material changes get an in-app notice. Last updated date at the top.