OffChest
HomeTrending18+
OffChest — A safe, anonymous space.
Privacy PolicyTerms of ServiceGitHubMy Account

Privacy Policy

Last updated: February 20, 2026

TL;DR: ConfessIt is built around anonymity. Your confessions are never publicly linked to your identity. We collect minimal data, we don't sell it, and you can delete your account at any time.

1. Who We Are

ConfessIt ("we", "us", or "our") is an anonymous online confession platform where registered users can share thoughts, feelings, and secrets without their identity being revealed to the public. This Privacy Policy explains how we collect, use, store, and protect information when you use our website (confessit.app).

By using ConfessIt, you agree to the practices described in this policy. If you do not agree, please discontinue use of our platform.

2. Information We Collect

2.1 Information You Provide

  • Email address — required for account creation and email verification. Your email is never displayed publicly.
  • Username — a unique handle you choose. This is stored internally but is never shown on any public confession.
  • Password — stored as a secure cryptographic hash via Supabase Auth. We never store your plain-text password.
  • Confession content — text you submit (max 1,000 characters). All confessions are displayed publicly under the label "Anonymous".

2.2 Automatically Collected Information

  • IP address — logged by our hosting provider (Vercel) for security, rate-limiting, and abuse prevention. Not stored permanently by us.
  • Browser / device type — collected in server logs for debugging and compatibility.
  • Usage data — pages visited, timestamps of actions (e.g., post creation, likes). Used for moderation and platform health.

2.3 Cookies

We use minimal, essential cookies only:

  • Authentication session cookie — set by Supabase Auth to keep you logged in. This is a strictly necessary cookie and cannot be opted out of while using the platform.

We do not use advertising cookies, cross-site tracking, or analytics cookies from third parties (e.g., Google Analytics).

3. How We Use Your Information

  • To create and manage your account.
  • To send a one-time email verification link upon signup.
  • To send a password reset link if you request one.
  • To enforce our rate limits (max 5 confessions per day) and detect abuse.
  • To allow administrators and super administrators to review reported content and take moderation actions (e.g., account suspension, post deletion).
  • To detect dangerous or self-harm-related content and display mental health helpline information automatically.
  • To maintain our activity log for admin accountability.

We do not use your data for targeted advertising, profiling, or sale to third parties.

4. Anonymity & How It Works

Every confession posted on ConfessIt is displayed publicly as "Anonymous". Your username and email are never shown on the public feed or confession detail pages.

However, your account is internally linked to your confessions in our database for the following legitimate purposes:

  • Allowing you to view and delete your own confessions.
  • Enforcing per-user rate limits.
  • Allowing Super Administrators to investigate serious violations (e.g., threats, illegal content) when strictly necessary.

Important: While we take privacy seriously, ConfessIt is not designed to be used for illegal activities. In the event of a credible legal obligation (e.g., a court order), we may be required to disclose account information to law enforcement.

5. Data Storage & Security

All data is stored securely using Supabase (PostgreSQL database hosted on AWS infrastructure). We implement the following security measures:

  • Row Level Security (RLS) policies on all database tables.
  • All communication is encrypted via HTTPS / TLS (enforced by Vercel).
  • Passwords are hashed using Supabase Auth's built-in bcrypt implementation.
  • Admin and Super Admin routes are protected by server-side middleware.

While we take reasonable precautions, no system is 100% secure. We cannot guarantee absolute security of your data.

6. Data Retention

  • Your account data (email, username, password hash) is retained as long as your account is active.
  • Confessions are retained indefinitely unless deleted by you, an Admin, or a Super Admin.
  • Reports and admin action logs are retained for accountability purposes even after the underlying content is deleted.
  • On account deletion: your personal information (email, username) is permanently purged. Your confessions may be anonymized or deleted depending on our moderation needs.

7. Third-Party Services

We rely on the following trusted third-party services:

Supabase

Database, Authentication, and backend infrastructure. Supabase's privacy policy applies to their data handling: supabase.com/privacy

Vercel

Hosting and content delivery. Vercel's privacy policy: vercel.com/legal/privacy-policy

We do not integrate any social media logins, ad networks, or data brokers.

8. Your Rights

Depending on your location, you may have the following rights:

  • Access: Request a copy of the data we hold about you.
  • Correction: Update your username or email through your account settings.
  • Deletion: Delete your account at any time via the "Delete Account" option in your settings. This triggers a permanent data purge.
  • Objection: Object to certain types of processing (where applicable under law).

To exercise any of these rights, contact us at the email below.

9. Children's Privacy

ConfessIt is not intended for use by anyone under the age of 13 (or 16 in the EU under GDPR). We do not knowingly collect personal information from minors. If you believe a minor has created an account, please contact us immediately and we will delete the account.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of ConfessIt after changes are posted constitutes your acceptance of the updated policy.

11. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us:

Email: privacy@confessit.app

Platform: confessit.app

Terms of Service →← Back to Home