Privacy Policy
Last updated: August 2026
1. Introduction
Tchoff (“we,” “our,” or “the Service”) respects your privacy. This policy describes what data we collect, how we use it, and your rights. By using the Service, you agree to this policy and our Terms of Use.
2. Data We Collect
Account data: When you sign up, we collect email, a hashed password (we never store plaintext passwords), and username. We use this to create and secure your account.
Content: Images, audio, captions, and metadata you upload. We store and serve this to operate the Service.
Reports: When you report content, we store the report details, your user ID, and content identifiers for review.
Usage: We may log IP addresses, request metadata, and error logs for security, abuse prevention, and debugging. Data is retained only as necessary.
Region detection (privacy banner only): On first visit we may call a free geo-IP service (ipapi.co) solely to choose the correct consent model (EU opt-in vs US opt-out). This request is not used for advertising or profiling.
3. How We Use Data
We use your data to: provide and improve the Service; authenticate you; store and display your content; process reports; enforce our Terms; comply with legal obligations; and protect security. We do not sell your personal data.
4. Security
Passwords are hashed using PBKDF2-HMAC-SHA256 with industry-standard iterations. Authentication uses JWTs. We use HTTPS and secure hosting (Cloudflare). We implement access controls and follow security best practices appropriate to the Service.
5. Data Retention
We retain account and content data for as long as your account exists. Reports are retained for compliance and review. Logs are retained for a limited period. You may request deletion of your account and associated data.
Disabled accounts: When you disable your account, it becomes inactive 30 days after your request. Your content is hidden from all users, but we retain your data (account info, images, sounds) and do not delete it, consistent with our backup and compliance practices.
6. Your Rights
You may: access your account data; update your username; disable your account (takes effect after 30 days; data retained but content hidden); and request information about the data we hold. Residents of the EU/EEA and California may have additional rights under GDPR and CCPA. Contact us to exercise these rights.
We honor the Global Privacy Control (GPC) signal. When GPC is present we treat it as an opt-out of sale/share and non-essential tracking.
7. Cookies and Storage
We do not set third-party advertising or tracking cookies. We primarily use browser localStorage (not HTTP cookies) for essential and preference data. Details:
| Name / Key | Type | Purpose | Duration | Category |
|---|---|---|---|---|
tchoff_token |
localStorage | Stores the JWT session token so you stay signed in | Until you sign out or clear site data | Necessary |
privacy_prefs_v1 |
localStorage | Stores your privacy/consent choices (analytics, marketing, preferences, sale/share opt-out, region model, timestamp) | Persistent until you change or clear it | Necessary |
tchoff_themes |
localStorage | Saves custom theme definitions you create | Persistent until cleared | Preferences |
tchoff_active_theme |
localStorage | Stores the currently active theme colors | Persistent until cleared or changed | Preferences |
- Necessary storage is required for the Service to function (authentication, remembering consent).
- Preferences storage is used only for UI themes you choose.
- Analytics and marketing categories exist in the consent system but are currently not loaded with any third-party scripts; the hooks are present for future use and remain off unless you opt in (EU) or do not opt out (US).
- We may use Cloudflare’s standard security / edge features. Cloudflare may set its own strictly necessary cookies (e.g. for bot management or load balancing) that we do not control.
- You can clear all of the above at any time via your browser’s site-data / storage settings. Clearing
tchoff_tokensigns you out; clearingprivacy_prefs_v1will show the consent banner again on the next visit.
We do not use third-party advertising cookies, fingerprinting for ads, or cross-site tracking.
8. Third Parties
We use Cloudflare for hosting and D1 for database storage. They process data on our behalf. The privacy banner may contact ipapi.co once for country detection. We do not share your data with advertisers or other third parties for marketing.
9. Children
The Service is not intended for users under 13. We do not knowingly collect data from children under 13.
10. Changes
We may update this policy. Continued use after changes constitutes acceptance. Check the “Last updated” date for the current version.
11. Contact
For privacy questions or to exercise your rights, contact us via the contact information on the Service.