Privacy Policy
Last updated 30 August 2026
TEA is built so that the story is public and the storyteller is not. This page describes exactly what we hold, why, and who else touches it. It is written to be read, not to be survived.
We do not ask who you are
There is no signup. The first time you open TEA we create an anonymous session that lives in your browser's local storage. It is not linked to a phone number, a social account, or a real name, and we have no way to work out who you are from it. Clearing your browser storage ends that identity permanently — including access to anything posted under it.
What we store
- What you write. Posts (up to 2000 characters) and comments, as text. TEA does not accept photos, video, or audio at all.
- Your verdicts. Which of the three options you picked on a post, so we can show a total and stop the same session voting twice.
- Reports you file. Kept so moderators can act on them. The author of the reported content is never shown who reported it.
- An optional email. Only if you choose to claim a handle. See below.
Handles and email
By default everything you post is anonymous. If you want a handle, you give us an email address and confirm a one-time code. That email is used for exactly two things: proving the address works, and letting you get back into the same account on another device. It is never shown on your posts, never sold, and never used for marketing. Choosing a handle does not retroactively attach your name to anything you already posted anonymously — attribution is decided per post, at the moment you post it.
The de-identification check
Before a post goes live, its text is sent to Groq, an AI inference provider, which flags fragments that could identify a real person — names, employers, handles, locations — and suggests neutral replacements. This is the one place your draft leaves our infrastructure. We send only the text of that draft, with no account identifier attached, and we do not use your content to train any model. If the check is unavailable, we let the post through rather than block you, and we record that it was unchecked.
Technical data
Our servers see your IP address on each request, as any web server does. We use it only to rate-limit posting and to run Cloudflare Turnstile, which distinguishes people from bots. We do not store IP addresses alongside your posts.
Analytics and errors
We use PostHog to count a small, fixed set of product events — a post was created, a verdict was cast, a report was filed — so we can tell whether the product works. Those events carry the anonymous session identifier and never the content of what you wrote. We use Sentry to receive crash reports. Neither is used to build an advertising profile, and TEA carries no ads and no third-party ad trackers.
Who can see what
Posts, comments and vote totals are public to anyone with the link. Your email, your session identifier and the reports you file are visible only to you and, where necessary for moderation, to our moderators. Database access rules enforce this at the row level rather than relying on the app to remember.
How long we keep it
Content that is reported and hidden is not deleted — it stays in our database so a moderator can review the decision and so we retain a record if the complaint escalates. Content removed after review is retained in the same way rather than erased. Everything else is kept for as long as TEA runs. Because this is a beta, we may reset non-essential data between test phases; we will say so in the app before we do.
Deleting your data
Write to our grievance officer from the email attached to your handle, or include enough detail to identify the post, and we will delete it. Where we are required to retain something — an active complaint, a moderation record — we will tell you what and why rather than quietly keeping it.
Children
TEA is not for anyone under 18. We do not knowingly hold data belonging to a child. If you believe we do, contact the grievance officer and we will remove it.
Changes
If we change what we collect or who processes it, we will update the date at the top of this page and surface a notice in the app. We will not start collecting something materially new and leave you to find out from a diff.