Privacy Policy
Effective 26 July 2026
The Story of the Internet, at ofstory.net, is operated by TWAMD LLC. There are no accounts, and we collect as little as possible.
1. What we collect
- Anonymous browser keys. Your browser may generate random keys stored on your device. Where the Service needs to prevent abuse or accept a report, the server stores only purpose-limited, salted hashes rather than the original keys.
- Daily Edition device storage. This browser keeps separate purpose-bound random keys for voting and reporting. It stores vote candidate identifiers, not word text; your current streak, lifetime counts, bounded tie-break markers, and a bounded set of private per-order placement claims. It also keeps a bounded, per-ballot presentation seed so the same browser sees a stable randomized order. That seed does not choose a word, alter a vote, or create a profile. Clearing browser data, using private browsing, or changing devices permanently loses this local record. There is no account and the Service cannot recover it.
- Owner-only daily totals. We store only the date, event kind, and count for play, return, and share totals. These metric rows contain no vote pick, participation history, page URL, IP address, or user agent.
- Safety reports. New safety reports include the reported word or title, the reason you select, and anonymous reporter hashes. They contain no free-text note. Historical reports may include an optional note accepted before this change. Reports are private and do not create comments or profiles.
- Abuse-prevention signals. We process technical data such as an IP address and Cloudflare Turnstile results to limit bots and misuse.
- Launch-alert emails. If you join the launch list, we store your email to send a confirmation link and the promised launch announcement. Unconfirmed addresses are deleted after 30 days, and the confirmed list is deleted after that announcement is sent.
- Messages you send us. The contact form sends us what you write and any contact detail you choose to provide.
- Direct word-placement orders.If you pay to place a word, we store the word, its named ballot, the price and currency, safety-review evidence, payment and placement status, opaque Stripe identifiers, and a hash of a random browser-local claim. We do not store a buyer profile or copy Stripe’s payment email into the Service. We never receive or store card numbers.
2. What we do not do
We do not require accounts or names, sell personal data, run advertising trackers, build profiles of readers or voters, or offer a public or browsable history of who participated or which word they chose.
3. How we use data
We use data only to operate the launch list, story reader, voting and direct word placement, receive private safety reports and messages, prevent abuse, reconcile payments, maintain the Service, and meet legal obligations.
4. Cookies and local storage
We use only essential browser storage, including the private rebuilding gate, bot-protection state, the purpose-bound Daily Edition records described above, and random per-order claims that let the same browser reconcile placed words. These records are not an account or stored-value wallet. We do not use advertising or cross-site tracking cookies.
5. Service providers
We use Supabase for data storage, Vercel for hosting, Cloudflarefor delivery and bot protection, and Resend for launch and contact emails, and OpenAI for optional candidate generation and limited safety review. When that provider is enabled, portions of the public story, proposed words, and reported story content may be sent to it. We do not send browser keys or a voter’s choice. API data is not used to train models by default; abuse-monitoring logs may be retained for up to 30 days. Stripe hosts Checkout, processes card authorizations, captures, cancellations, refunds, disputes, and receipts, and may collect a payment email under its own relationship. The Service does not copy that email into its order records.
6. How long we keep data
We keep data only as long as needed for the purposes above. Resolved safety reports, historical optional notes, and anonymous reporter hashes are deleted after 90 days. Unresolved reports remain available while their reported content still needs review. Contact messages are kept as long as needed to respond and maintain records. After launch, completed payment and placement history is retained as an append-only business and safety record. Expired or abandoned order data and abuse-prevention signals are retained only as long as needed for reconciliation, security, disputes, and legal obligations. Stripe applies its own retention policy to provider records.
7. Your choices and rights
Depending on where you live, you may have rights to access or delete personal data. Because the Service is anonymous, we often cannot connect stored data to a particular person. You can still contact us with a request, and you may reply to a launch email to be removed sooner.
8. Children and security
The Service is not intended for children under 13. We take reasonable measures to protect data, including keeping secrets on the server and using hashes where practical, but no method is perfectly secure.
9. Changes and contact
We may update this policy. The effective date shows the latest version. Reach us through the contact form. The Service is operated by TWAMD LLC in the United States.