The Quiet Part

Privacy Policy

Effective 10 August 2026

The Story of the Internet, at ofstory.net, is operated by TWAMD LLC. There are no accounts, and we collect as little as possible.

1. What we collect

  • Anonymous browser keys. Your browser may generate random keys stored on your device. Where the Service needs to prevent abuse or accept a report, the server stores only purpose-limited, salted hashes rather than the original keys. These hashes expire by ballot or campaign and are not a durable identity.
  • Daily Edition device storage. This browser keeps separate purpose-bound random keys for voting and reporting. For Daily voting, it stores candidate identifiers rather than word text. For direct-placement recovery, it stores validated display words in a bounded set of private per-order placement claims. It also keeps your current streak, lifetime counts, bounded tie-break markers, and a bounded, per-ballot presentation seed so the same browser sees a stable randomized order. That seed does not choose a word, alter a vote, or create a profile. Clearing browser data, using private browsing, or changing devices permanently loses this local record. There is no account and the Service cannot recover it.
  • Title nominations. A confirmed subscriber receives one title nomination slot for the campaign. We use the email address to confirm eligibility, issue or recover access, and enforce one slot. The accepted title may be edited until nomination close but cannot be withdrawn. The nomination and eligibility records are private and do not create a public identity or attribution.
  • Owner-only aggregate totals. For the Daily Edition, we store only the date, event kind, and count for play, return, and share totals. During the title campaign, one fixed aggregate row per Chicago day may count confirmations, access, nominations, review, ballot reads, votes, switches, shadow drops, reports, tie claims, scheduled transitions, and launch-email status. These metric rows contain no candidate, person, device, network, or payment identifier, and no vote pick, participation history, page URL, IP address, or user agent.
  • Safety reports. New safety reports include the reported word or title, the reason you select, and anonymous reporter hashes. They contain no free-text note. Historical reports may include an optional note accepted before this change. Reports are private and do not create comments or profiles.
  • Abuse-prevention signals. We process technical data such as an IP address, Cloudflare Turnstile results, coarse GPU, screen, platform, processor core count, and request timing signals to limit bots and repeat voting. Raw device components are validated and converted to purpose-limited server hashes; they are not stored or logged as raw values. A suspicious vote may be counted in full or silently excluded. A shared network alone never causes that result, and these signals cannot prove that two requests came from one person. Daily evidence becomes unusable at its America/Chicago cycle close and is deleted within 24 hours. Title-vote evidence may last through the whole multi-day vote, becomes unusable when title voting closes, and is deleted within 24 hours after voting closes.
  • Launch-alert emails. If you join the launch list, we store your email to send a confirmation link and the promised launch announcement. An existing confirmed subscriber may request a purpose-specific title-access email; the response does not reveal whether an address is already listed. Unconfirmed addresses are deleted after 30 days. The confirmed list and campaign eligibility records are deleted only after the launch announcement is fully sent or reconciled. Before sending a launch alert, this browser stores a random browser action receipt containing no email or message. It uses that receipt only to check whether the request was received, without sending it twice. The matching server receipt contains no email or content and is deleted with the launch-list cleanup.
  • Messages you send us. The contact form sends us what you write and any contact detail you choose to provide. A random action receipt lets the same browser check uncertain delivery without sending the message twice.
  • Direct word-placement orders.If you pay to place a word, we store the word, its named ballot, the price and currency, safety-review evidence, payment and placement status, opaque Stripe identifiers, and a hash of a random browser-local claim. We do not store a buyer profile or copy Stripe’s payment email into the Service. We never receive or store card numbers.

2. What we do not do

We do not require accounts or names, sell personal data, run advertising trackers, build profiles of readers or voters, or offer a public or browsable history of who participated or which word or title they chose. The Service never stores a record connecting voter or device evidence to a candidate choice.

3. How we use data

We use data only to operate the launch list and title campaign, story reader, voting and direct word placement, receive private safety reports and messages, prevent abuse, reconcile payments, maintain the Service, and meet legal obligations.

4. Cookies and local storage

We use only essential browser storage, including the private rebuilding gate, bot-protection state, the purpose-bound Daily Edition records described above, and random per-order claims that let the same browser reconcile placed words. A random launch-alert action receipt contains no email or message and lets this browser check whether one request was received. A contact action receipt contains no message text or contact details. Neither expires automatically. Each remains while its result is unknown. A received request or sent message clears its receipt. A confirmed failure normally clears it, but the contact form may keep the same receipt so TRY AGAIN can safely reuse that failed action. Replacing that failed action or clearing site data also removes it. During the title campaign, essential storage also keeps nomination access, a stable ballot order, a final-vote recovery credential, and best-effort no-self-vote state. When the title commits, a returning browser first records any browser-only title-win count and then clears campaign-local state; an offline browser's state simply expires. These records are not an account or stored-value wallet. We do not use advertising or cross-site tracking cookies.

5. Service providers

We use Supabase for data storage, Vercel for hosting, Cloudflare for delivery and bot protection, and Resend for launch and contact emails, and OpenAI for optional candidate generation and limited safety review. When that provider is enabled, portions of the public story, proposed words, title nominations after nomination close, and reported story content may be sent to it. Title-nomination review is limited to the published safety rules; it does not judge quality or rewrite a title. We do not send email addresses, browser keys, device evidence, or a voter’s choice. API data is not used to train models by default; abuse-monitoring logs may be retained for up to 30 days. Stripe hosts Checkout, processes card authorizations, captures, cancellations, refunds, disputes, and receipts, and may collect a payment email under its own relationship. The Service does not copy that email into its order records.

6. How long we keep data

We keep data only as long as needed for the purposes above. Resolved safety reports, historical optional notes, and anonymous reporter hashes are deleted after 90 days. Unresolved reports remain available while their reported content still needs review. Contact messages are kept as long as needed to respond and maintain records. After launch, completed payment and placement history is retained as an append-only business and safety record. After campaign cleanup, the winning title and minimal campaign provenance remain. Losing title strings, their result order, initial safety-policy version, report-presence fact, and append-only safety verdicts remain in a private repair slate so a later harmful title can be replaced by a crowd-chosen alternative. That slate contains no email, submitter, voter, device, payment, public vote count, or public campaign row. Other losing-entry, eligibility, title-vote, and campaign-report records are deleted after launch-email reconciliation. Expired or abandoned order data and other abuse-prevention signals are retained only as long as needed for reconciliation, security, disputes, and legal obligations. Stripe applies its own retention policy to provider records.

7. Your choices and rights

Depending on where you live, you may have rights to access or delete personal data. Because the Service is anonymous, we often cannot connect stored data to a particular person. You can still contact us with a request, and you may reply to a launch email to be removed sooner.

8. Children and security

The Service is not intended for children under 13. We take reasonable measures to protect data, including keeping secrets on the server and using hashes where practical, but no method is perfectly secure.

9. Changes and contact

We may update this policy. The effective date shows the latest version. Reach us through the contact form. The Service is operated by TWAMD LLC in the United States.