Privacy Policy
Effective date: July 27, 2026 ยท Last updated: July 27, 2026
1. Information we collect
Information you provide
- Account email address โ required at signup; used for login and password reset. Not shown publicly.
- Username and display name โ required at signup; shown publicly on everything you post.
- Password โ never stored in plain text. We store an Argon2id hash of it, a one-way transformation that cannot be reversed to recover your actual password.
- Avatar image (optional) โ if uploaded, it's re-encoded before storage (this strips embedded metadata such as EXIF data) and shown publicly.
- Bio (optional) โ shown publicly on your profile.
- Posts and comments โ public by design; see Section 2.
- "Same Here" reactions โ which posts you've reacted to is tracked to prevent duplicate reactions; the resulting reaction count on a post is public, but we do not display a public list of who reacted to what.
- Reports you submit โ the reported content, your account, and your stated reason are stored and visible only to administrators.
- Support and legal requests you send us โ whatever information you choose to include when contacting us (see Contact and Legal Requests).
Information collected automatically
- Authentication/session data โ when you log in, we create a session record tied to your account, used to keep you signed in and to let you (or us, in response to a password reset) revoke it. Sessions expire automatically.
- IP addresses โ AnnoyanceHub's own database does not store IP addresses. IP addresses are used briefly, in memory only, to slow down abusive request patterns such as repeated login attempts, and are not written to our database. Our hosting and content-delivery providers may capture IP addresses in standard infrastructure request logs as an ordinary part of operating a web service; retention of those logs is governed by those providers, not by AnnoyanceHub.
- Error and diagnostic data โ see Section 4. Only genuine application errors are reported, never routine "bad input" responses; request bodies, cookies, and authorization headers are stripped before an error report is sent, and query strings (which could contain a password-reset token) are stripped from any URL captured.
- Local browser storage โ AnnoyanceHub stores a few small values in your browser's local storage (not cookies โ see below) to keep you signed in between visits, remember which posts you've reacted to or hidden locally, and remember whether you've dismissed a one-time welcome message. This data stays on your device.
What we don't collect
AnnoyanceHub does not use cookies of any kind โ authentication is handled with a token stored in your browser's local storage, not a session cookie. AnnoyanceHub does not currently use any analytics or advertising tracking (no Google Analytics, no ad pixels, no cross-site tracking scripts) โ the only outbound telemetry this product sends today is the error monitoring described in Section 4, which is errors-only and does not track your browsing behavior.
2. What's public vs. private
Public
- Username
- Display name
- Avatar
- Posts and comments
- "Same Here" reaction counts (aggregate counts, not who reacted)
- Public profile statistics (e.g. your recent posts)
- Bio, if you set one
- The month and year you joined (not the exact date)
Private
- Email address
- Password (stored only as an irreversible hash)
- Password-reset tokens
- Session/authentication data
- Reports you've filed, or that have been filed against your content, and any related moderator notes
- Any IP-related infrastructure logs described in Section 1
3. How we use information
We use the information above to:
- Operate the service โ render the feed, posts, comments, and your profile.
- Manage your account โ login, logout, profile editing, avatar display.
- Authenticate you and keep your session secure.
- Process password resets (see how reset emails are sent in Section 4).
- Moderate content โ review reports, remove content that violates our Community Guidelines.
- Maintain security โ rate limiting, abuse prevention, fraud and spam prevention.
- Debug and monitor the application โ error tracking, uptime monitoring.
- Back up the database and avatar files so data isn't lost to a hardware failure or operator mistake.
- Comply with legal obligations, and respond to lawful requests (see Contact and Legal Requests).
- Send you service-related communications (currently limited to password-reset emails โ AnnoyanceHub does not send marketing email today).
AnnoyanceHub does not currently sell your personal information. We do not currently share your personal information for targeted advertising, and we do not currently display targeted advertisements or use third-party behavioral analytics. Service providers who help us operate AnnoyanceHub may process information only to provide infrastructure, email, monitoring, security, and storage services, as described in the next section.
4. Vendors and service providers
We use a small number of infrastructure providers to run AnnoyanceHub. None of them are permitted to use your data for their own independent purposes โ they process it only to provide their service to us.
- Railway โ hosts the backend application and its database and file storage.
- Cloudflare โ manages DNS for annoyancehub.com and stores off-site database and avatar backups.
- Resend โ delivers password-reset emails. If no email provider is configured, a reset link is logged privately on our servers instead of being emailed โ never exposed to any API response.
- Sentry โ receives error reports (backend and frontend, separately) when the application throws an unhandled exception. Request bodies, cookies, and authorization headers are excluded, and only genuine failures are reported on the backend side.
- UptimeRobot โ periodically checks whether the site and its health endpoint are reachable. It only ever calls a public, unauthenticated status URL โ it does not receive any user data.
5. Data retention and backups
Your account, posts, and comments are retained for as long as your account exists and the content isn't deleted. When you delete your own post or comment, or a moderator removes content, it's removed from the live app right away โ but it may still exist in a backup or snapshot for a period after that, described below.
AnnoyanceHub's hosting provider maintains automatic volume snapshots. AnnoyanceHub also maintains tools for creating database and avatar backups, including copies stored in private off-site storage. These application-level backups are performed manually and are not guaranteed to occur on a fixed schedule.
We do not claim that deleted content is erased everywhere instantly: it is removed from the live app right away, but may remain in a backup or snapshot until that backup is deleted or the snapshot is rotated out.
Accounts are not currently deleted solely because of inactivity.
6. Account deletion
AnnoyanceHub does not provide self-service account deletion. You may submit an account-deletion request by emailing [email protected]. Requests are reviewed individually. AnnoyanceHub does not guarantee a specific completion time, and some information may be retained when reasonably necessary for security, fraud prevention, legal compliance, dispute resolution, backups, or enforcement records.
Public content that other users have already copied, quoted, or shared may remain outside AnnoyanceHub's control even after your account is deleted.
7. Security practices
We take reasonable, concrete steps to protect your information, including: hashing passwords with Argon2id, never storing them in plain text; encrypting traffic to the site over HTTPS; stripping metadata from uploaded avatar images and re-encoding them rather than storing the raw upload; parameterized database queries throughout the backend to prevent SQL injection; rate limiting on sensitive actions like login and password reset; and a set of standard security response headers on every request. No system is perfectly secure, and we don't claim otherwise โ if you believe you've found a security issue, please report it via Contact and Legal Requests.
8. Children's privacy
AnnoyanceHub is a general-audience service. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, contact us via Contact and Legal Requests and we will investigate and remove the account if confirmed.
9. Your rights and requests
Depending on where you live, you may have rights to access, correct, or delete your personal information under applicable law. AnnoyanceHub does not currently have a self-service data-export or "download my data" feature โ requests of that kind are handled individually. To make a request, email [email protected].
10. International users
AnnoyanceHub is operated from the United States. If you access AnnoyanceHub from outside the United States, you are responsible for complying with local laws that may apply to you. AnnoyanceHub does not represent that the service is appropriate or legally available in every jurisdiction. Information may be processed and stored in the United States.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected here with an updated "Last updated" date, and may also be communicated through the service or other appropriate channels.
12. Contact
Questions or requests about this policy? See Contact and Legal Requests.