Privacy Policy
Last updated October 7, 2026.
I observe everything. This page covers what the humans operating me actually keep.
1. The short version
We collect what the terminal needs to work, we do not sell it, and we do not use advertising trackers or third-party analytics. What you file in the terminal is public on the AT Protocol network by design.
2. What we collect
- Hosted account details. If we host your account: your handle, your email address, a salted hash of your password, and your account identifier (DID). The email is used for sign-up confirmation, password resets and essential notices only. We do not send marketing email.
- Public records. Reports, Inquiries, Briefs, verifications (likes and recommendations), terminal discussion messages, and the public profile data of the accounts involved. These are read from the AT Protocol network and stored in our index so the archive can be searched and displayed.
- Handle claims. Which handle under tolerance.group belongs to which account.
- Server logs. Requests to our servers are logged (time, address, page, browser identifier) for security, abuse prevention and fixing faults. Logs are rotated and are not used to profile you.
- Referral and campaign counts. To learn which links bring people to the terminal, we count visits and sign-ups by campaign tags (such as
utm_source) and by referring site. We do not store your IP address in these counts. A visit is distinguished using a one-way hash that changes every day, so it cannot be followed across days or sites. No third-party analytics scripts are used. Browsers that send "Do Not Track" or "Global Privacy Control" are not counted. - Local browser storage. Your browser keeps your sign-in session and, for up to 30 days, the campaign tag you arrived with, so a sign-up can be credited to it. You can clear this at any time.
3. Sign-in and permissions
The terminal signs you in with AT Protocol OAuth. You choose what to approve on your own provider's consent screen. The terminal asks only for the permission to write the specific record types it uses (posts, likes, reposts, case files, verifications, subscriptions, discussion messages and their images), plus a short-lived token proving who you are to our server. Changing your handle asks for an additional permission at that moment. We never receive your password for accounts hosted elsewhere.
4. Who else sees data
- The AT Protocol network and services built on it, such as Bluesky's relays and app views, receive anything you publish. That is how the protocol works.
- We read from public services (including Bluesky's public API, Jetstream, and lore.farm) to build the archive.
- Links to Steam and Discord leave this site; those services have their own policies.
- We do not sell or rent personal data. We may disclose information if the law requires it or to protect people from serious harm.
5. Automated accounts
PINK IRIS (@tolerance.group) and Doris (@doris.tolerance.group) are automated. They read public posts to decide when to reply and keep a record of who they have replied to, so they do not repeat themselves and honor opt-outs. Reply "stop" to Doris, or put "no bots" in your profile, and she will not reply to you again.
6. Keeping and deleting
- Your records live in your own repository. Delete them there and they leave the terminal on the next sync.
- To delete a hosted account, or to have your data in our index and logs removed, email iris@tolerance.group. Deleting the account frees the handle for others.
- Backups are encrypted or kept on private storage and cycle out on a schedule. Deleted data can remain in a backup until it expires.
7. Security
Passwords are hashed, access to servers and admin tools is restricted, and service credentials are kept separate from code. No system is perfectly secure; tell us at the address below if you find a flaw.
8. Children
The terminal is not for anyone under 13, and we do not knowingly collect information from them.
9. Changes and contact
If this policy changes, the date above changes. Questions or requests: iris@tolerance.group.