Privacy policy

haneoka

Privacy policy

This Privacy Policy describes how the maintainers of haneoka (the “Operator”, “we”, “us”, or “our”) collect, use, disclose, retain, and protect information when haneoka provides its public archive, community, account, and related services (collectively, the “Service”). Please read it before creating an account or submitting information.

Effective and last updated: September 27, 2026

Operator, scope, and public access

The haneoka project maintainers operate the Service and act as the controller or responsible organization to the extent required by applicable law. This Policy applies to the haneoka website, account system, community, uploads, moderation, and support interactions. It does not govern third-party websites, applications, or services linked from the Service. The homepage and public archive can be viewed without an account. Authentication is required only for account features, community participation, uploads, or saved server-side preferences. Merely viewing public pages may still produce ordinary network and security records described below.

Information you provide

We process the email address used for registration, sign-in, verification, password recovery, and security notices; profile information such as display name, handle, biography, and avatar; and community material such as posts, comments, attachments, tags, reactions, bookmarks, follows, blocks, mutes, recommendation feedback, reports, and appeals. We also process information included in support, rights, or abuse requests. Passwords are transmitted only for account operations and are stored as one-way salted password hashes, not as plaintext passwords. Community edits and deletions create new revisions or state records rather than overwriting all prior records. Do not submit confidential information that is unnecessary for the relevant feature.

Email-only registration and third-party sign-in

Email registration creates a pending account and sends a time-limited link through which the mailbox holder chooses the final password. The email address is verified and a public numeric UID is assigned only after setup succeeds. Reissuing a setup email invalidates an earlier setup link after the new delivery request is accepted. If you choose Google, GitHub, X, or Discord sign-in, we receive the identifiers and basic account information needed to authenticate you, which may include a verified email address and account name. OAuth tokens are encrypted by the application before database storage. Google user data is used only for sign-in, account security, and user-facing account functionality; it is not sold, used for advertising, or transferred to data brokers. You may revoke provider access through the relevant provider’s account settings, including Google’s connected-app controls at https://myaccount.google.com/connections.

Network, IP-region, and device information

For security, abuse prevention, moderation, and audit purposes, we record the original IP address supplied by Cloudflare and the full User-Agent associated with relevant account and community actions, together with timestamps, request identifiers, session and rate-limit data, and action metadata. The original IP address is stored in plaintext in the application database and is not application-level encrypted. It is available only through authorized administrative interfaces, subject to access controls. Public content may show only the country or territory and first-level administrative region derived from Cloudflare request metadata, plus generalized browser and operating-system icons derived from the User-Agent. The Service does not use GPS to determine precise location. IP-based location can be inaccurate, particularly when a proxy, VPN, mobile network, or corporate gateway is used. Cloudflare also processes operational logs and sampled request traces to diagnose errors, analyse performance and address security issues. The relevant service configuration determines their contents and retention.

Cookies and local device storage

The service uses cookies for sign-in, session security and OAuth, plus a language-preference cookie with a one-year lifetime. Browser local storage also keeps settings such as theme, release server, layout, player and workspace state, and local post drafts. These remain on your device and can be cleared through your browser. A service worker caches public pages, static files and images for subsequent visits. The service uses cookies for authentication and preferences; third-party sign-in and Cloudflare Turnstile process cookies and device information under their own policies. The Service does not currently operate third-party advertising, cross-site behavioral advertising, or advertising-profile trackers. Google, GitHub, X, Discord, Cloudflare Turnstile, or other third-party services may use their own cookies or device information when you actively interact with them, under their own policies.

What is public and what administrators can access

Your approved profile, public UID, posts, comments, attachments, tags, reaction counts, follow information exposed by the feature, creation and last-edit times, generalized IP-region label, and generalized browser or operating-system icon may be visible to other users or the public. Search engines or third parties may copy publicly available information, and we cannot guarantee deletion of copies outside our control. Authorized moderators or administrators may access pending, blocked, edited, or deleted content; all stored revisions and state events; reports and appeals; the original IP address; full User-Agent; moderation signals and decisions; account restrictions; and other records reasonably necessary to operate, secure, audit, and enforce the Service. Such access is not intended for unrelated personal use.

Purposes and legal grounds

We use information to provide and authenticate the Service; deliver requested features; display and organize public content; operate recommendations and notifications; detect spam, fraud, abuse, security incidents, and prohibited conduct; moderate content and decide appeals; enforce the Terms of Use; maintain audit trails; troubleshoot and improve reliability; respond to users and rights holders; and comply with lawful obligations. Where applicable law requires a legal basis, processing may be necessary to perform our agreement with you, based on your consent, required to comply with law, or based on legitimate interests in operating and protecting a community service. We balance those interests against affected rights. You may withdraw consent where consent is the applicable basis, without affecting earlier lawful processing.

Moderation and recommendations

Posts, comments, profile names, and attachments may be evaluated by automated rules or moderation services and may be placed in pending, allowed, or blocked states. For automated classification, Cloudflare Workers AI may process submitted text, post tags, uploaded images or text files, original file names and, when reviewing a comment, limited excerpts from the related post, parent comment, and recent discussion. Model identifiers, classifications, reasons, and review events may be stored with the moderation record. Editing content triggers a new review for the new revision. Human administrators may review the content, technical records, prior revisions, reports, and appeals and may confirm or change a result. These processes are intended for content safety and do not make decisions that produce legal or similarly significant effects. The recommended feed uses an internally implemented score based on factors such as recency, engagement, followed authors or tags, muted or blocked preferences, prior feedback, and randomized tie-breaking. Previous exposure lowers weight but does not automatically exclude a post. We do not use third-party advertising profiles for this ranking.

Service providers and disclosures

Cloudflare provides network delivery, request metadata, bot verification, application execution, databases, object storage and AI inference for automated moderation. An email service delivers account messages. When you choose third-party sign-in, the selected identity provider handles authentication. Avatars can use approved uploaded images; when an image is unavailable, the interface displays an initial generated locally. Reference data and media are served through Haneoka and configured resource hosts. When your browser connects to a resource host, that host receives ordinary network information such as the request IP, User-Agent, time and URL, and processes it under its own policies. We may disclose information when reasonably necessary to comply with valid legal process; protect users, rights holders, the public, or the Service; investigate fraud, security incidents, or abuse; obtain professional advice; or complete a reorganization, transfer, or succession of the project subject to appropriate safeguards. We do not sell personal information, disclose it to data brokers, or share it for cross-context behavioral advertising.

International processing

The Service and its providers may process or store information in countries or regions other than the one in which you live. Those locations may have different data-protection laws. Where legally required, we rely on an adequacy decision, contractual safeguards, consent, or another permitted transfer mechanism. By using globally delivered network and authentication services, your requests may be routed through infrastructure in multiple jurisdictions.

Retention, deletion, and account closure

Account and profile information is kept while an account is active and as needed to provide the service. Account-setup and password-reset links normally last one hour; sessions normally last up to seven days, subject to renewal or revocation. Scheduled jobs clean up expired sessions, verification records and rate-limit records. Email-delivery protection records are retained for security and repeated-request control. Uploads not attached to a post receive a 24-hour expiry. Rejected or pending-review attachments become eligible for cleanup after 30 days; scheduled jobs perform deletion. Post and comment revisions, deletion states, moderation cases, appeals, reports, original IP addresses, User-Agent values and related audit events retain their history and may remain throughout service operation, including after content or account deletion. Account deletion disables the public profile and access, and revokes durable sessions. Further handling of identity and historical records follows security, rights-protection, dispute-resolution and applicable legal requirements.

Security and incident handling

We use measures intended to protect information, including HTTPS in normal production use, salted password hashing, encrypted OAuth tokens, restricted administrative routes, session controls, rate limits, input validation, and audit records. As expressly stated above, original IP addresses and full User-Agents are stored as readable database fields for authorized administration and are not separately encrypted by the application. No system or transmission is completely secure. You are responsible for protecting your mailbox, password, devices, and active sessions. If we become aware of a qualifying personal-data breach, we will investigate and provide notices to affected persons or authorities when and as required by applicable law.

Your rights and choices

Depending on applicable law, you may have rights to request access, correction, deletion, restriction, objection, portability, or information about processing; withdraw consent; or complain to a competent data-protection authority. These rights may be limited where retention is necessary for freedom of expression, security, fraud prevention, legal obligations, establishment or defense of claims, or protection of others. We may verify identity and request enough information to locate the relevant account before acting. You can edit profile information, manage social and tag preferences, edit or delete current community content, revoke OAuth access, sign out sessions, and request account deletion through available controls. For a formal request, contact the maintainers using the link below without posting passwords, tokens, raw IP addresses, identity documents, or other sensitive data publicly; ask for a private channel if verification is required.

Children

The Service is not directed to children under 13 or under the minimum age at which they may consent to online data processing in their jurisdiction. We do not knowingly request accounts from children who cannot lawfully consent. A parent or guardian who believes a child provided personal information without valid authorization should contact us so that we can review and take appropriate action. Public archive access remains available without signing in.

Changes to this Policy

We may revise this Policy to reflect changes in the Service, data practices, providers, law, or security requirements. The effective date above will be updated. Where a change materially expands the use of previously collected information, we will provide a prominent notice or request renewed consent when required before applying the new use. Continued use after a non-material update takes effect is subject to the revised Policy.

Contact

The haneoka project maintainers are the contact point for privacy questions, rights requests, and complaints. Use the project contact link below. Because the linked issue tracker is public, submit only a request for contact and no personal or confidential details; the maintainers may arrange a private verification channel. Nothing in this Policy limits any non-waivable right to contact a competent supervisory or consumer-protection authority.