PRIVACY NOTICE
COLLECT LESS. EXPOSE LESS.
Reporter anonymity depends on collecting only what the platform needs.
What we do not ask for
No reporter name, email, phone number, student ID, campus login, or public account.
Campus verification
Your browser shares a one-time location after permission. It is checked against the selected campus and discarded. The database retains only a short-lived token record without coordinates.
What becomes public
The reported position, institution, allegation account, categories, approximate incident period, status, replies, flags, corrections, and outcomes are public. The reported name and official source remain hidden until three qualifying reports from distinct anonymous origins exist, then publish automatically. Reporter identity is never intentionally displayed.
Private information
Recovery-code hashes, private evidence, respondent contact details, and grievance contact details are restricted. Uploaded evidence is not public.
Limits
Absolute anonymity cannot be guaranteed against a compromised device, infrastructure records held by service providers, information you include in your own text, or valid legal requirements.
Retention
Campus tokens expire after one hour and expired token records are deleted during subsequent verification checks. Public reports remain until the reporter withdraws or permanently deletes them, or a confirmed safety or legal requirement removes them. Private evidence remains only while its report remains active. Private reply-verification and grievance contact details are erased when the identity check or grievance is resolved.
Your controls
Use the recovery code to add a correction, withdraw the public account, or permanently delete the report and its private evidence. Use the grievance form for privacy concerns.