privacy
Who is responsible
thewall.social is run by one person. For anything in this policy — access, deletion, correction, or a complaint — write to hello@thewall.social and you will get a human.
If you are in the UK or EU, that person is the "controller" for the purposes of the UK GDPR and the EU GDPR. There is no Data Protection Officer, because the scale does not require one.
Reading, without an account
You can read every room, every post and every reply without telling us anything. There is no sign-up wall.
No analytics. No advertising. No third-party trackers. No cookies are set for reading — the only cookie this site ever sets is the one that keeps you signed in, and it is only set after you make an account.
Our host records ordinary web server logs (IP address, time, page requested) as every web server does. Those are the host's, retained on their schedule, and we do not build anything on top of them.
What we hold if you make an account
Your name. Public — it appears on everything you post, and at thewall.social/~yourname.
Your email address. Never public, never shown to other users, never sold, never used for marketing. It is used to send you a sign-in link, because there are no passwords here — and one summary a day of replies waiting for you, which is on from the moment you have an account and off the moment you type notify off.
Whether you get that daily summary, and when the last one was sent. Not public, and held apart from the rest of your account so that neither the setting nor the unsubscribe link that goes with it is readable by anybody but the server. It is on from the moment you have an account and off the moment you type notify off. Nothing is sent to an address until somebody has followed a key that arrived in it, no summary is ever sent on a day when nobody answered you, and every one of them carries a link that stops it without signing in.
What you post and reply. Public, along with the time you posted it.
When you signed up, when you last read your mail, and when your current name was taken.
Names you have previously used. Not public: a name is shown as "previously somebody else's" only as a date, never attached to a person, so renaming to get away from a name actually works.
Which rooms you opened, if you make any. Not public — the site never shows who made a room, and the database does not let a browser read it either. It is held so the three-a-week limit can be counted, and so there is a record if a room needs looking at.
When you agreed to the terms, and which version of them. Not public. It is the record that you were asked and answered, and it is deleted with your account.
A one-way hash of the IP address you signed up from. Used to stop one person creating a hundred accounts. It is a SHA-256 digest, not an address, and it is not linked to your account — it is kept for one hour and deleted.
Why we are allowed to hold it
Your name and your posts: to perform the contract you entered into by making an account. Without them there is no service to provide.
Your email address: the same, plus our legitimate interest in being able to let you back in on a new device.
Which rooms you opened: our legitimate interest in enforcing a limit that keeps the place usable, and in being able to answer for a room if somebody complains about one.
Your agreement to the terms: our legal obligation to be able to show what was agreed, and our legitimate interest in not having to guess later.
The signup IP hash: our legitimate interest in not being overrun by automated accounts. It is the least identifying thing that answers the question, and it is short-lived.
We do not rely on consent for any of it, which means there is nothing to withdraw — if you want out, deletion is the lever, and it is below.
How long it is kept
Posts in commons are deleted after 24 hours, automatically and unconditionally. This is enforced by the database, not by a cleanup job that could be turned off.
Posts in every other room are kept until you ask for them to be removed.
Your account is kept until you ask for it to be deleted.
A room you opened outlives your account. When you are erased the link between you and it is removed, and the room stays — by then the conversations in it belong to everybody who turned up, and taking it down would delete their words to satisfy a request that was never about them.
Signup rate-limit hashes are kept for one hour.
Previously used names are kept for 90 days, then stop being consulted; they are deleted outright when you close your account.
Who else sees it
Supabase — the database and the sign-in system. Your name, email and posts live there. Supabase Inc., United States, under Standard Contractual Clauses.
Netlify — hosting. Sees requests and server logs, not the database. Netlify Inc., United States, under Standard Contractual Clauses.
Resend — the sign-in emails. Sees your email address and the link sent to it. Resend Inc., United States, under Standard Contractual Clauses.
That is the complete list. Nobody buys this data, because it is not for sale, and there is no advertising network to sell it to.
Your rights
Write to hello@thewall.social and we will act within 30 days.
Access — a copy of everything held about you.
Correction — anything wrong, fixed. Your name you can change yourself, whenever you like: type rename.
Deletion — your email address and your name are erased, permanently. What you posted stays up by default, attached to a handle that is nobody, because deleting it would also delete the replies other people wrote underneath it. If you want your posts taken down as well, say so and they will be.
Portability — your posts, as a file you can take elsewhere.
Objection and restriction — say what you object to and we will stop.
If you are unhappy with the answer, you can complain to the data protection authority where you live — the Information Commissioner's Office in the UK, or your national supervisory authority anywhere in the EU. That right is yours wherever this site is run from, and nothing in the terms changes it.
Children
This is not for people under 16. We do not knowingly hold anything about anyone younger, and if we learn we have, it is deleted.
Security, honestly stated
Traffic is encrypted in transit. There are no passwords to lose, because there are none. Access to the database is limited to the one person who runs it.
This is a small project run by one person, not an enterprise with a security team. Do not put anything here you would be harmed by seeing in public.
Changes
Last updated 5 August 2026. If this policy changes in a way that matters, the change will be announced in commons before it takes effect.