Trust & legal

Turnfeed logo

Privacy policy

Turnfeed stores the feed, profile, account, safety, and support data needed to run the service. Turnfeed does not publish your private ChatGPT conversation. It never requests, stores, or reconstructs the full conversation. When you use Turnfeed through ChatGPT, ChatGPT may send Turnfeed-specific inputs needed for your request, such as text you ask to publish or the identifier of a post you ask to open. See what that means.

Last updated: July 22, 2026.

What Turnfeed stores

The product is designed to store the data needed to render the social surfaces and account controls you can already see in the app.

Turnfeed feed and thread data

Turnfeed stores public posts, replies, likes, follows, reports, and the metadata needed to show thread context, link previews, feed notifications, report snapshots, and current moderation state.

  • Posts, replies, likes, follows, reports, and timestamps
  • Quoted-post references, link previews, and media metadata
  • Report reasons and report history included in account export
Profile and trust data

If you add identity details, Turnfeed stores the profile and trust fields that make feed and profile decisions readable.

  • Display name, handle, bio, website, and avatar URL
  • Pinned profile lead post and profile counts
  • Notification preferences, hidden words, muted people, and blocked people
Inbox and account state

Notification and boundary features need event records to decide what reaches you and what stays quiet.

  • Notification, mute, block, hidden-word, and account-control state
  • Reply, like, and follow notifications
  • Viewer-specific account state kept separate from public profile data
Children and sensitive data

Turnfeed is not intended for children under 13 or the applicable age of digital consent. It is not meant for protected health information, payment card data, government ID numbers, passwords, or similarly sensitive data.

What is public versus private

Turnfeed tries to make visibility rules legible: public feed content is shared, profile details are user-controlled, and viewer-only trust controls stay attached to your account.

Public feed and profiles

The global feed is anonymously web-readable. Public profile details, public posts, replies, likes, lead posts, and visible relationship signals can be accessed by anyone with web access or a direct link and can appear in search and discovery surfaces.

If you post it publicly, treat it as something anyone could open, copy, or share.

Inbox and viewer-only settings

Notification preferences, hidden words, mute/block state, and similar trust settings are viewer-specific account data rather than public profile fields.

Blocking and muting propagate through feed, inbox, and discovery instead of only hiding one UI surface.

Private ChatGPT conversation

Turnfeed does not publish your private ChatGPT conversation. It also does not request, store, or reconstruct the full private conversation.

Relevant request context means the Turnfeed-specific inputs needed for the action—for example, the exact text you ask to publish, the post or reply identifier you ask to open, or the profile field you ask to change—not the full chat.

Categories of recipients

These are the groups that can receive or process Turnfeed data, depending on the action a user takes.

Other Turnfeed users

Public posts, replies, profile details, likes, visible relationship signals, and public media references can be accessed by anyone with web access or a direct link.

Hosting and storage providers

The hosting, database, and storage systems process Turnfeed data so the service can serve pages, MCP tools, feeds, moderation views, and account controls.

Link and media destinations

When link previews or user-provided media URLs are used, destination sites can receive the requested URL, request timing, and server or browser network information needed to fetch that resource.

Operator, support, and moderation reviewers

The operator and support/moderation reviewers may access reports, hidden or reported content, support details, abuse-control records, and current admin dashboard state when needed to run, secure, or moderate the app.

OpenAI and ChatGPT

When you use Turnfeed through ChatGPT, OpenAI and ChatGPT process your ChatGPT conversation and MCP tool interactions under their own account, product, and platform controls. For the Turnfeed action you request, ChatGPT may send Turnfeed relevant request context needed to respond or perform it. Turnfeed separately processes the account, network, and operational data described on this page.

Identity provider

When an account action requires sign-in, the configured identity provider authenticates you and issues scoped access tokens. It may process login identifiers under its own privacy notice. Turnfeed's app server verifies those tokens but does not receive your provider password.

Legal or safety recipients

Information may be shared when required to comply with law, enforce terms, investigate abuse, protect users, or respond to a valid legal or safety request.

Preview fetches, abuse prevention, and retention

These are the main places where Turnfeed processes supporting data beyond the core post and profile record.

Link previews

If a posted URL generates a link preview, the server may fetch that URL to read metadata like title, description, and image.

That reveals the URL to the destination site and uses this service's server IP address.

Abuse prevention

Public feed reading does not require an account. For private inbox data, publishing, profile changes, or account controls, Turnfeed verifies an access token from the configured identity provider and stores a keyed one-way hash of its issuer and pseudonymous subject with the Turnfeed activity needed to run the service.

That derived account key is pseudonymous personal data, not anonymous data. The app server does not store the raw access token or subject. The identity provider may separately process login details under its own privacy notice. Turnfeed may also process network and request signals for rate limits, spam prevention, service health, and abuse review.

Storage and retention

Data is stored in server-side application storage managed by the Turnfeed service.

  • Active beta storage keeps up to 500 posts, with up to 50 active posts per account. When an eligible limit is reached, a least-recently-active thread can become read-only and leave feeds while remaining available from its direct link and author profile.
  • The active service holds up to 4,000 replies across active threads, with up to 400 active replies per account and 400 replies per active thread. A new reply never archives its own target thread; if no other eligible thread can safely make room, publishing pauses without storing the reply.
  • The read-only archive is normally capped at 500 threads and 4,000 replies. When it fills, eligible least-recently-active whole threads roll out. A thread containing a live target of a retained report is not automatically evicted. If a legacy or recovered store is already above the normal cap and cannot be brought back within it without deleting protected evidence, Turnfeed preserves that evidence and pauses new content admissions for operator review until space can be made safely.
  • The active moderation queue accepts up to 2,000 new report records. Existing distinct moderation evidence is preserved even if legacy state is already above that limit. New reports pause when the queue is full; Turnfeed does not automatically replace a retained report, reporter receipt, or moderation-evidence record to make room. Contact Support if the queue cannot accept a report.
  • Profiles, follows, and settings remain in active storage until removed through applicable user controls, account reset/delete, or moderation. Recent like, follow, and group-invite notification event logs are each capacity-limited to 5,000 records. An event can outlast the feed item that generated it until its queue rolls over or applicable account, boundary, deletion, or moderation controls remove it.
  • Reports, moderation records, abuse-prevention records, and support messages are retained only as long as reasonably necessary for safety, legal, security, support, and service-operation needs. After account reset/delete, a private target-scoped keyed token may remain with a retained report solely to prevent the same account from repeatedly inflating that target's report count. It is not included in account or moderator exports and does not restore report history by itself. If the account explicitly reports that target again, Turnfeed creates a new current-account receipt without adding a second moderation record.
  • Security logs, rate-limit records, and other operational records are retained only as long as reasonably necessary for security, abuse prevention, troubleshooting, and applicable legal obligations; short-lived in-memory abuse-prevention identifiers can expire sooner.
  • Backup and recovery copies may remain after an active record changes or is removed until they are overwritten through the normal recovery cycle, unless a legal, safety, or security need requires longer retention.
  • Records may be kept longer when needed for legal duties, active disputes, safety investigations, security incidents, abuse prevention, or recovery from service failure.

These are product retention targets for Turnfeed product data; provider logs and OpenAI/ChatGPT account data are governed by those providers' own controls.

Session cookies and viewer tokens

The browser preview may use first-party session cookies or viewer tokens to keep Turnfeed account controls attached to the right account.

Turnfeed does not use third-party ad pixels or analytics cookies in this service.

No advertising sale

This service does not sell personal data, run third-party advertising, or use personal data for cross-context behavioral advertising.

If that changes, this policy will be updated before that processing starts.

Security model

Turnfeed protects transport with HTTPS/TLS and uses server-side access controls, signed viewer tokens, hashing, rate limits, and moderation controls where they fit the product.

Public posts and replies are not end-to-end encrypted because feed rendering, search, reports, and moderation need server-side processing. No online service can guarantee perfect security, but Turnfeed aims to apply controls proportionate to a public social product.

Norway and EEA privacy rights

Turnfeed is operated from Norway by THEODOR N. ENGØY · org. no. 934 120 337, a Norwegian sole proprietorship, so EEA privacy rights and Norwegian privacy oversight matter for how Turnfeed handles personal data.

Controller

THEODOR N. ENGØY · org. no. 934 120 337 determines why and how Turnfeed product data is processed for the public feed, account controls, moderation, support, and security.

Use support@turnfeedapp.com for controller requests until a separate privacy contact is published.

Legal bases

Turnfeed generally relies on processing necessary to provide requested account and feed features, legitimate interests for safety, abuse prevention, service health, and moderation, consent where a feature asks for it, and legal obligation when law requires a response.

Providing the data needed for account, feed, moderation, and support features is generally required to use those parts of the service. Public posting and replying remain user-controlled actions.

Your GDPR rights

Depending on context, you can ask to access, correct, export, delete, restrict, or object to processing of your personal data. Turnfeed exposes ChatGPT product paths for reset, delete, report, block, and profile controls, while export, mute, hidden-word, and broader privacy requests can be handled through support.

Privacy requests receive a response without undue delay and normally within one month.

Processors and transfers

Hosting, database, OpenAI/ChatGPT, link-preview destinations, and support or moderation systems may process data outside Norway or the EEA depending on how the product is used.

Turnfeed keeps processor and transfer documentation aligned with the real service stack and applicable transfer safeguards, and support can provide more information where required.

Automated decisions and consent

Turnfeed may use ranking, rate limits, filters, and moderation signals to run a public feed, but it does not make decisions about you that produce legal or similarly significant effects solely by automated means.

Where Turnfeed relies on consent for a feature, you can withdraw that consent through the relevant control or support route. Withdrawal does not affect processing that already happened.

Datatilsynet

If you believe your privacy rights have not been handled properly, you can contact the Norwegian Data Protection Authority, Datatilsynet.

The support route above is the fastest way to ask Turnfeed to fix something first.

Data minimization

Turnfeed is designed to collect what the feed, account controls, moderation, support, and security features need, and aims to avoid sensitive categories that do not belong in a public social product.

This is especially important for a small operator with a public social surface.

Your control paths

Turnfeed keeps removal, export, and support routes visible instead of burying them behind a generic email line.

Inside the app

Use Turnfeed in ChatGPT for reset, delete, block, report, profile, posting, and reply flows when you want product-level control first. Use support for export, mute, hidden-word, and broader privacy requests while chat tools expand.

This policy stays aligned with the live product and its stored fields as Turnfeed evolves.