Privacy
Ctrl+Shift+3 is a text community platform (website and iOS app). This page explains how this installation handles privacy. It is also the privacy policy linked from App Store Connect for the iOS app.
We do not sell your personal data. We do not track you across other companies’ apps or websites for advertising. We do not use your data for targeted ads.
Who we are
This installation is operated by the site operator (platform owner). Questions: contact the operator via the site’s Contact page when signed in, or the support email listed on the App Store product page.
What we collect
- Account information you provide: username, email, and password (stored as an Argon2id hash—we cannot read your password).
- User content you write: posts, comments, art, bios, Click names/descriptions, poll text, moderation/report reasons (plain text).
- App / functional data needed to run the service: session cookies (website), API auth tokens (iOS app, stored in the device Keychain), rate-limit records, push device tokens if you enable notifications, theme preference, and moderation log entries (actions and reasons, not deleted content).
- Site operator settings such as SMTP credentials (password stored encrypted in the database; encryption key kept in server config, not in MySQL).
How we use data
- To create and secure your account, and to show your content to people who are allowed to see it.
- To send optional email (for example password reset, or a daily ping digest if you turn that on).
- To send optional push notifications on iOS if you enable them (ping-related).
- To enforce rules, rate limits, blocks, reports, and moderation.
- To operate optional Fediverse sharing only if you opt in under Settings (off by default).
We use this data for app functionality only—not for advertising, not for data brokerage, and not to profile you for sale.
What we do not do
- No advertising networks or ad SDKs.
- No analytics or tracking pixels.
- No fingerprinting.
- No sale or rental of personal data.
- No “tracking” as Apple defines it (we do not link your data with other companies’ apps or websites for ads, and we do not share data with data brokers).
- No third-party JavaScript on the website; no external fonts loaded from CDNs.
Sharing
We do not share your personal data with third parties for their marketing. Limited technical sharing may occur only as needed to run the service you chose (for example your email provider receiving a password-reset message we send via SMTP, or Apple delivering a push notification you opted into). Optional Fediverse sharing (if you turn it on) publishes selected main-feed posts to other servers you interact with; see below.
Cookies and local storage
The website uses only functional cookies (session and security). There are no marketing cookies. The iOS app stores your login token in the device Keychain and may store simple preferences (such as appearance) in app storage.
Push notifications (iOS)
Push is optional. If you enable ping notifications, we store a device token so we can send those notifications through Apple Push Notification service. You can revoke permission in iOS Settings. Logging out unregisters the token from this installation when possible.
Blocks, reports, and safety
You can block another user so you do not see their posts or comments; blocking also stops them from writing on your profile, inviting you to Clicks, or viewing your profile in the usual way. You can report accounts for moderator review. Account deletion is available in Settings (website and iOS app).
Access, correction, and deletion
- On the website, you can edit your bio, change your password, manage Fediverse sharing, and export your data from Settings while signed in.
- In the iOS app, you can edit your bio, change appearance theme, enable optional push notifications, log out, and delete your account from Settings (You → Settings).
- You can delete your account in Settings (website or iOS). When you delete, your username becomes
abandoned(or a numbered variant), and the original text of your posts and comments is permanently replaced with placeholders. We do not keep the deleted text.
Retention
We keep account and content data while your account is active, and for as long as needed for security, abuse prevention, and legal obligations after that. Soft-deleted account rows may remain with placeholder content so historical threads stay coherent without your original words.
Children
Ctrl+Shift+3 is not directed at children under 13. Do not create an account if you are under 13.
Fediverse (optional)
Main-feed posts (and your comments on main-feed posts) can be shared into the Fediverse—for example so someone using Mastodon can look up
[email protected] and read that public writing.
This only happens if you opt in under Settings (“Send posts to main feed out into the Fediverse”). The option is off by default.
Click posts, profile posts, and contact posts are not shared this way.
If you delete a post or comment here, or turn Fediverse sharing off, this site stops offering that content to new Fediverse requests (and may mark it removed for servers that check again). Servers that already downloaded a copy (such as a Mastodon instance) may keep it; this site cannot reliably force those remote copies to disappear.
Changes
If this policy changes in a material way, we will update this page. Continued use of the website or iOS app after an update means you accept the revised policy. The version line below helps you notice updates.
Contact
Privacy questions about this installation should go to the site operator (the platform owner who installed it), via Contact when available, or the support channel listed with the iOS app on the App Store.
v0.4.36 · (c) billy wilcosky