Privacy
Last updated: 17 July 2026
The short version: your out-of-character identity stays out of character, your DMs are private from other users, staff access is limited and logged, and we do not sell or share your data with anyone.
1. What we collect
- Account data. Your email address and a hashed password (we never store the password itself). Optionally your two-factor settings.
- Characters and content. Everything you create on the platform: characters, profiles, posts, comments, messages, images, listings, wallet entries, reactions and follows.
- Technical data. Standard server logs (IP address, browser, timestamps) kept for security and debugging, and the cookies described below.
We do not ask for your real name, and we do not collect anything for advertising. Uploaded images are re-encoded and stripped of metadata (such as camera location tags) before they are stored.
2. The in-character / out-of-character wall
Your email and login identity are never shown on any in-character surface. Other users see your characters, not you. Which characters belong to which account is not exposed to other users; staff can see it where moderation requires it.
3. Who can see your messages
- Direct messages are visible only to the characters in the conversation.
- If a character is reported, moderators may review that character's messages from the last 24 hours as part of handling the report. They cannot browse further back and cannot browse unreported users.
- Every staff access to messages is written to a permanent audit log.
4. How we use your data
- To run the service: showing your content to the people you share it with, delivering notifications, powering the events API for your own OSC tools.
- To keep it safe: moderation, spam prevention and abuse investigation.
- To contact you about your account: email confirmation, password resets and two-factor codes. We do not send marketing email.
We never sell your data, and we never hand it to third parties for their own use.
5. Cookies
We use cookies only to keep you signed in and to remember preferences such as your theme. There are no advertising or cross-site tracking cookies.
6. The API
The public API only exposes what you can already see on the site, authenticated with tokens you create and can revoke from your dashboard. Notifications delivered to your own OSC or companion apps go wherever you point them, which is under your control, not ours.
7. Retention and deletion
- Your content stays until you delete it. Deleting a post, comment or message removes it from the platform for other users.
- If your account is deleted, your content and characters are removed. Moderation records and audit logs are kept, as they are the platform's record of staff conduct as much as yours.
- Content hidden by moderation is retained while relevant to reports or appeals.
- Backups can hold deleted data briefly before rotating out.
8. Security
Passwords are hashed, staff access is role-gated and audited, and two-factor authentication is available in Settings. No system is perfect: if we ever discover a breach affecting your data, we will tell you what happened and what was affected.
9. Age
SaphireSocial is for users 16 and over, per the Terms of Service. We do not knowingly keep accounts belonging to anyone younger.
10. Changes
If how we handle data changes in any meaningful way, we will announce it on the site before it takes effect. The date at the top of this page always shows the current version.