Skip to content
confession.baby

Privacy Policy

Version 2026-10-11

Draft for legal review. Highlighted items must be completed by the operator before public launch. This document does not claim compliance with any specific law.

Summary

  • You can post without an account, name or email.
  • We do not store your IP address in readable form, do not fingerprint devices, and do not use advertising. We use Google Analytics to count visits to public pages (see Analytics).
  • Some technical data is still processed to keep the service working and to stop abuse. This page lists all of it.
  • Anonymity has limits. Do not post anything that would harm you if it were linked to you.

confession.baby is operated by [operator legal name and address to be completed before launch], the controller of the data described here.

What is processed

When you post a confession or comment

  • What you write, the category and community you choose, and timestamps.
  • A one-way hash of your receipt or comment key. We never store the receipt itself.
  • A record that you accepted the Terms and Guidelines, which versions, and that you confirmed you are 18 or older. This record contains no identity information.
  • Automated safety flags produced while screening the text (see Moderation processing).
  • Your Instagram username, only if you choose to add it. It is shown publicly on your post, which means that post is no longer anonymous. It is never allowed on school pages and is erased if you delete the post.

When you react, comment or report

  • A random visitor identifier in a cookie (see Cookies). We store only a keyed hash of it, to remember your reaction and stop duplicates.
  • For reports: the reason, any details you add, and a hash that changes every day, used only to stop the same person reporting the same item twice. The report-abuse form also stores contact details if you choose to give them.

Technical data on every request

  • Your IP address and browser user agent are received by our hosting provider and our code. For rate limiting and view de-duplication we keep only a keyed hash of them, bound to a short time window, and delete it when the window ends (at most 24 hours, purged daily).
  • Our hosting provider keeps short-term operational logs (request path, status, timing, errors) to run and secure the service. We do not log submission text, receipts or cookies.

Accounts (claimants and moderators only)

  • Email address, a salted password hash, your role, and session records (a hash of the session token, a shortened user agent, and timestamps).
  • For handle claims: the institution email you provide and the evidence you write. Rejected claim evidence is erased after 90 days.

Limits of anonymity

We designed confession.baby so that we do not know who wrote a post: there are no author accounts, and posts are not linked to your IP address or cookie. Even so:

  • What you write can identify you. Details, writing style and timing can let people who know you recognise you.
  • Your network provider, your school or workplace network, and your device can see that you visited the site.
  • Short-lived hashed data and hosting logs exist for a limited time, as described above.
  • Anyone holding your receipt or comment key can manage that submission.

We never promise absolute anonymity, and community moderators never receive any information about authors.

Cookies and local storage

NamePurposeDuration
cb_vRandom visitor identifier. Set only when you react, comment, report or post. Lets you change or remove your reaction and helps limit abuse.180 days
cb_sessionKeeps claimants and moderators signed in.12 hours
_ga, _ga_*Google Analytics: tells visits apart to count readers. Not set for visitors in the EEA, UK or Switzerland, and never on admin, account, receipt or claim pages.Up to 2 years
TurnstileCloudflare’s anti-abuse check, shown on forms. Cloudflare may process device and browser signals to tell people from bots.Session

Your browser also keeps two items in local storage that never leave your device: an unsent draft (cb:draft:v1, removed after you submit) and the keys for comments you wrote (cb:comment-keys:v1). Clearing site data removes them; you then cannot edit those comments.

The confession.baby cookies are strictly necessary for the features you use. The Google Analytics cookies are not; you can block them in your browser or with a tracker blocker and the site keeps working. We do not use advertising cookies.

View counting

A confession’s view count is the number of qualified views: a real browser kept the page open for a few seconds. Each visitor is counted at most once per confession in any 24 hours, using a keyed hash of the visitor cookie (or, if there is none, of the IP address and browser type). Known bots and link-preview crawlers are not counted. The hash expires after 24 hours. Daily totals per confession are kept without any visitor data.

Analytics

We use Google Analytics 4 to understand how many people visit public pages and which pages they read. Google receives the page address, referrer, approximate location, device and browser type. It runs only on https://confession.baby public pages. It is not loaded on the admin, account, receipt or claim pages, and never receives what you write or your receipt. For visitors in the EEA, UK and Switzerland it runs without cookies. Google Signals and advertising features are turned off. Google's processing is described in its privacy policy. [operator to set GA data retention (we recommend 2 months) and confirm the Google data processing terms]

Moderation processing

Every submission is screened automatically before it reaches a human moderator. Screening checks for contact details, explicit content, threats and spam with our own rules, and sends the text to a safety classifier (Llama Guard, run on Cloudflare Workers AI) that labels categories of risk. The text is not used to train models by us. A human moderator then decides. Moderators see the submission, its flags and reports, never who wrote it.

How long we keep data

  • Published content: until you delete it, a moderator removes it, or the service closes. Removed content is kept for review and appeals; deleted content is erased immediately.
  • Rejected confessions and comments: the text is erased 30 days after rejection; the status stays for audit.
  • Rate-limit and view de-duplication hashes: until their time window ends, at most 24 hours.
  • Reactions: while the reaction exists.
  • Sessions: until they expire or you sign out, then purged within 30 days.
  • Moderation history and audit logs: [retention period to be set by the operator].
  • Backups: Cloudflare D1 keeps point-in-time recovery data for up to 30 days, so erased data can persist in backups for that period.

Service providers

Cloudflare, Inc. hosts the site and database and provides Turnstile and Workers AI. Data may be processed in the countries where Cloudflare operates. Google LLC provides Google Analytics (see Analytics). Fonts are served from our own domain. No other third parties receive your data. [operator to confirm data processing agreement and transfer mechanism]

Search engines and AI crawlers

Published confessions, comments and community pages are public. Search engines, AI answer engines and AI companies may read them, quote them, and use them to train models. School community posts are not offered to search engines. Pending, rejected and deleted content is never public.

When we disclose data

We do not sell data. We may disclose the limited data we hold if the law requires it, or where there is a credible threat to someone’s life or safety or a child safety concern, following the escalation process for moderators. Because we do not store readable IP addresses or author identities, there is usually little to disclose.

Security

Connections are encrypted. Receipts, keys, sessions and passwords are stored only as hashes. Administrative access requires an account with a moderator role, and every moderation action is logged. No system is perfectly secure; if we learn of a breach affecting you we will act as the law requires.

Your choices and rights

  • Delete a confession or comment at any time with its receipt or key on Check a submission.
  • Delete cookies in your browser at any time.
  • If you have an account, you can ask for access, correction or deletion through the contact details below.
  • Depending on where you live, you may have further rights (for example to object or to complain to a data protection authority). [operator to list applicable rights and authority]

Because we cannot link anonymous posts to a person, we cannot find “all posts by you” without your receipts.

Children

The service is for adults. We do not knowingly collect submissions from anyone under 18. If you believe a child has posted, or a post exposes a child, use Report abuse and we will review it with priority.

Contact

Privacy contact: [privacy contact email to be completed before launch]. For content problems, use Report abuse.

Changes

We will publish any changes here with a new version date. Accepting the Terms when posting is not consent to unrelated processing.