← sizuq

Privacy Policy

Last updated: 2026-09-01

sizuq ("the Service") is a quiet social network for thoughtful expression. This Privacy Policy explains what personal data we collect, how we use it, and the choices you have. It applies to the website at sizuq.com and any related services.

1. Information we collect

  • Account data: email address when you add one, legacy password hashes for existing password accounts (we never store plaintext passwords), handle, and optional profile information (display name, avatar URL, bio, and atmosphere metadata you choose to provide).
  • Authentication provider data: if you sign in with Apple, Google, or X, we receive the provider's stable account identifier and the profile fields that provider makes available to this sign-in flow. Google may provide your email address, name, and profile picture. Apple may provide your email address and name, including an Apple private-relay address when you choose Hide My Email. X provides your account ID, name, username, and profile picture; X does not provide your email address in this flow. sizuq does not fetch your contacts, calendar, or social posts.
  • Authentication credentials: WebAuthn/passkey public keys, linked OAuth provider identifiers, session credential provenance, and a verified Recovery Email if you choose to add one. Passkey private keys remain with your device or passkey provider and are not stored by sizuq.
  • Content you create: posts, resonances (reactions), spaces, and the metadata associated with them.
  • Guest Archive: before you sign in, thoughts and tags you explicitly save are kept in this browser's IndexedDB, with local storage used only as a fallback. They are not sent to sizuq unless you sign in and confirm an import. There is no automatic expiry; you can delete individual thoughts, delete all of them, or clear the browser's site data.
  • Aggregate onboarding measurement: we keep daily counts for a small set of first-use steps, grouped by language and experience version. These counters do not contain thought text, tags, IP addresses, User-Agent strings, cookies, user IDs, or persistent guest IDs.
  • Security telemetry: login attempts and security events. IP addresses and User-Agent strings are stored as SHA-256 hashes — we do not retain raw IPs or device fingerprints.
  • Cookies: a session cookie used to keep you signed in. No third-party analytics or advertising cookies.

2. How we use information

  • To provide and operate the Service (sign-in, feed, posts).
  • To understand, through aggregate counters only, whether the first-use writing and import flow is working.
  • To protect accounts and detect abuse (rate limiting, audit logs, suspicious-login detection).
  • To send transactional emails (address verification, security notifications).
  • To comply with applicable law.

We do not sell your personal data, and we do not use it for behavioral advertising or training third-party models.

3. Service providers (sub-processors)

We share the minimum data necessary with the following providers, each of which acts on our behalf under their own security and privacy commitments:

  • Vercel — hosting and CDN.
  • Neon — managed PostgreSQL database.
  • Apple — OAuth sign-in (only if you choose to use it).
  • Google — OAuth sign-in (only if you choose to use it).
  • X — OAuth sign-in (only if you choose to use it).
  • Resend — transactional email delivery.

4. Data retention and deletion

We retain your account data for as long as your account is active. When you delete your account, we delete your personal data and content from active systems within 30 days, with limited exceptions retained for legal compliance, abuse prevention, or backups (typically purged within 90 days). Security event logs may be retained longer in aggregated or hashed form.

For the exact steps, the 30-day window in which you can still change your mind, and a full list of what is removed, see Deleting your account.

5. Your rights

You may access, correct, export, or delete your personal data at any time from the Settings page or by emailing us. Depending on your jurisdiction (EEA, UK, California, Japan, etc.), you may also have the right to object to processing, restrict processing, or lodge a complaint with your local data protection authority.

6. Children

sizuq is not directed to children under 13 (or the equivalent minimum age in your jurisdiction). If you believe a child has provided us with personal data, please contact us and we will delete it.

7. Security

We use industry-standard measures including TLS in transit, passkeys/WebAuthn, explicit OAuth reauthentication for sensitive actions, session-scoped security elevation, legacy bcrypt password hashing for existing password accounts, and audit logging. No method is 100% secure; where possible, keep more than one independent sign-in method connected and add a Recovery Email for account recovery.

8. International transfers

Our service providers may process data in the United States, the European Union, or other jurisdictions. By using the Service, you consent to such transfers, which are conducted under contractual safeguards.

9. Changes to this policy

We may update this Policy from time to time. Material changes will be announced via email or an in-app notice. The "Last updated" date above always reflects the most recent version.

10. Contact

Questions or requests regarding this Policy can be sent to contact@sizuq.com.