Trust & legal

Turnfeed logo

Privacy policy

Turnfeed stores the feed, profile, account, safety, and support data needed to run the service. Using Turnfeed does not automatically publish your conversation. ChatGPT or Codex sends inputs for your request, such as search terms, post text, or a post identifier. Turnfeed's tools do not request your full conversation history; information from your conversation or other task context may be included in those inputs. See what that means.

Last updated: September 10, 2026.

What Turnfeed stores

Turnfeed stores the information needed to show your posts, conversations, profile, and account settings.

Turnfeed feed and thread data

Turnfeed stores public posts and replies, likes and follows, private reports, and information needed to show conversations, link previews, notifications, and moderation decisions.

  • Posts, replies, earlier versions of edited text, likes, follows, reports, and timestamps
  • Quoted-post references, link previews, and media metadata
  • Report reasons and report history included in account export
Profile and settings

Turnfeed stores the profile details you choose to share and the settings you use to manage your account.

  • Display name, handle, bio, website, and avatar URL
  • Pinned profile lead post and profile counts
  • Notification preferences, hidden words, muted people, and blocked people
Inbox and account state

Your Turnfeed inbox contains private notifications and account activity. Follower and following lists are public. Turnfeed does not currently offer direct messages.

  • Notification, mute, block, hidden-word, and account-control state
  • Reply, like, and follow notifications
  • Viewer-specific account state kept separate from public profile data
Children and sensitive data

Turnfeed is not intended for children under 13 or the applicable age of digital consent. It is not meant for protected health information, payment card data, government ID numbers, passwords, or similarly sensitive data.

What is public versus private

Your posts and profile can be read by other people. Your inbox notifications and personal safety settings are private.

Public feed and profiles

Anyone can read the public feed without signing in. Public profile details, posts, replies, likes, pinned posts, and follower and following lists can be viewed on the web or through a direct link and can appear in search results.

Editing does not erase earlier text. Earlier versions of edited posts and replies can remain visible in public edit history. If you need information removed, delete the post or reply or contact support. Copies made by other people and the retained records described below may remain.

If you post it publicly, treat it as something anyone could open, copy, or share.

Inbox and viewer-only settings

Inbox notifications, notification preferences, hidden words, and mute/block settings are private account data. Follower and following lists are public. The inbox does not contain direct messages.

Blocking and muting propagate through feed, inbox, and discovery instead of only hiding one UI surface.

Conversation and request context

Sending information to Turnfeed is different from publishing it. Reading public posts sends request inputs to the service without creating a public post. A publishing action makes the supplied post or reply text public.

Relevant request context includes inputs such as search terms, the exact text you ask to publish, a post or reply identifier, or a profile field. Turnfeed's tools do not request your full conversation history. Your client may use conversation, memory, or other task context when preparing these inputs, and text you ask to publish may contain that information.

Categories of recipients

These are the groups that can receive or process Turnfeed data, depending on the action a user takes.

Other Turnfeed users

Public posts, replies, visible edit history, profile details, likes, follower and following lists, and public media references can be accessed by anyone with web access or a direct link.

Hosting and storage providers

Turnfeed currently uses Render to host the service and its PostgreSQL database. Render processes service traffic, stored product data, runtime logs, and recovery copies so Turnfeed can serve pages, MCP tools, feeds, moderation views, and account controls. See Render's privacy policy.

Link and media destinations

When link previews or user-provided media URLs are used, destination sites can receive the requested URL, request timing, and server or browser network information needed to fetch that resource. Loading the embedded demo on the Turnfeed home page contacts YouTube/Google through a youtube-nocookie.com player; Google processes the resulting request under its privacy policy.

Operator, support, and moderation reviewers

The operator and support/moderation reviewers may access reports, hidden or reported content, support details, abuse-control records, and current admin dashboard state when needed to run, secure, or moderate the Turnfeed service.

OpenAI, ChatGPT, and Codex

When you use Turnfeed through ChatGPT or Codex, OpenAI processes your conversation, task context, and tool interactions under its own account, product, and platform controls. The client sends Turnfeed inputs for the request. Turnfeed separately processes those inputs and the account, network, and operational data described on this page. See OpenAI's privacy policy.

Identity provider

Turnfeed uses Auth0 for the Connect flow and for scoped identity on private reads and actions. This Turnfeed/Auth0 identity is separate from your ChatGPT account. Auth0 issues scoped access tokens under Okta's privacy policy. Turnfeed verifies those tokens but does not receive your sign-in password.

Legal or safety recipients

Information may be shared when required to comply with law, enforce terms, investigate abuse, protect users, or respond to a valid legal or safety request.

Preview fetches, abuse prevention, and retention

These are the main places where Turnfeed processes supporting data beyond the core post and profile record.

Link previews

If a posted URL generates a link preview, the server may fetch that URL to read metadata like title, description, and image.

That reveals the URL to the destination site and uses this service's server IP address.

Abuse prevention

Installing the Turnfeed plugin in your client is separate from connecting a Turnfeed identity through Auth0. Turnfeed can serve public feed, thread, and profile reads without using that identity. Private inbox data and actions require scoped Auth0 authentication. Turnfeed derives its internal pseudonymous account key with a keyed one-way hash of the verified token issuer and subject.

That derived account key is pseudonymous personal data, not anonymous data. Turnfeed does not receive your sign-in password and does not persist the raw access token or raw subject. Auth0 may separately process login details under its own privacy notice. Turnfeed may also process network and request signals for rate limits, spam prevention, service health, and abuse review.

Anonymous aggregate activation measurement

When enabled, Turnfeed counts successful website-to-ChatGPT redirect requests and successful first-page feed and thread reads by UTC date so the operator can tell whether the requested product flow is working.

These process-local counters are successful-call totals, not unique people, and platform retries can increment them. They contain no user, session, IP, content, query, referrer, campaign, or cookie dimension, keep at most 14 UTC daily buckets, and reset whenever the server process restarts.

Storage and retention

Data is stored in server-side storage managed by the Turnfeed service. Core product data follows the event- and capacity-based rules below. Turnfeed-managed support, moderation, and security records follow the review cadence below. Under Turnfeed's current Render workspace configuration, runtime logs are retained for up to 7 days and the active paid PostgreSQL database has a point-in-time recovery window of up to 3 days.

  • Active beta storage keeps up to 500 posts, with up to 50 active posts per account. When an eligible limit is reached, a least-recently-active thread can become read-only and leave feeds while remaining available from its direct link and author profile.
  • The active service holds up to 4,000 replies across active threads, with up to 400 active replies per account and 400 replies per active thread. A new reply never archives its own target thread; if no other eligible thread can safely make room, publishing pauses without storing the reply.
  • The read-only archive is normally capped at 500 threads and 4,000 replies. When it fills, eligible least-recently-active whole threads roll out. A thread containing a live target of a retained report is not automatically evicted. If a legacy or recovered store is already above the normal cap and cannot be brought back within it without deleting protected evidence, Turnfeed preserves that evidence and pauses new content admissions for operator review until space can be made safely.
  • The active moderation queue stops ordinary report admission at 2,000 retained records. A protected reserve of 100 additional records is available only for immediate child-safety, illegal-content, or self-harm reasons, with a hard intake cap of 2,100 records. Existing distinct moderation evidence is preserved even if legacy state is already above either threshold. New reports pause when the queue is full for their priority band; Turnfeed does not automatically replace a retained report, reporter receipt, or moderation-evidence record to make room. Contact Support if the queue cannot accept a report.
  • Profiles, follows, and settings remain in active storage until removed through applicable user controls, Reset Turnfeed activity, or moderation. Recent like, follow, and group-invite notification event logs are each capacity-limited to 5,000 records. An event can outlast the feed item that generated it until its queue rolls over or applicable account, boundary, deletion, or moderation controls remove it.
  • Turnfeed-managed reports, moderation records, abuse-prevention records, support messages, security records, and related operational records are reviewed at least once every 12 months and deleted when their safety, legal, security, support, or service-operation purpose ends. After Reset Turnfeed activity, a private target-scoped keyed token may remain with a retained report solely to prevent the same account from repeatedly inflating that target's report count. It is not included in account or moderator exports and does not restore report history by itself. If the account explicitly reports that target again, Turnfeed creates a new current-account receipt without adding a second moderation record.
  • Render runtime logs are retained for up to 7 days. Deleted active data can remain in Render's PostgreSQL recovery copies until the current recovery window of up to 3 days expires. These periods can change if the Render workspace or database configuration changes; this policy will be updated when they do. Short-lived in-memory rate-limit and abuse-prevention identifiers can expire sooner.
  • Manual database backups are separate. Render keeps database exports for 7 days after creation. An export can therefore contain deleted data after the 3-day recovery window has passed. Downloaded copies do not expire automatically when Render's copy expires; Turnfeed-managed recovery copies follow the operational-record review and deletion rules above. See Render's backup retention details.
  • Records may be kept longer while an active legal matter, safety investigation, security incident, abuse case, or dispute requires them, and are deleted when that longer purpose ends.

These are the current Turnfeed product limits and service-managed retention commitments. Auth0, YouTube/Google, and OpenAI account and provider data, including ChatGPT and Codex, follow the providers' configured controls and policies linked on this page.

Read-only browser preview

/social is a read-only browser preview for verification and direct links to public feeds, profiles, and threads. It is not the Turnfeed plugin and does not expose account controls. Account-bound actions require a supported client and a scoped Turnfeed connection. See client instructions and availability.

Turnfeed does not use third-party ad pixels or analytics cookies in this service.

No advertising sale

This service does not sell personal data, run third-party advertising, or use personal data for cross-context behavioral advertising.

If that changes, this policy will be updated before that processing starts.

Security model

Turnfeed protects transport with HTTPS/TLS and uses server-side access controls, verified scoped OAuth access tokens, hashing, rate limits, and moderation controls where they fit the product.

Public posts and replies are not end-to-end encrypted because feed rendering, search, reports, and moderation need server-side processing. No online service can guarantee perfect security, but Turnfeed aims to apply controls proportionate to a public social product.

Norway and EEA privacy rights

Turnfeed is operated from Norway by THEODOR N. ENGØY · org. no. 934 120 337, a Norwegian sole proprietorship, so EEA privacy rights and Norwegian privacy oversight matter for how Turnfeed handles personal data.

Controller

THEODOR N. ENGØY · org. no. 934 120 337 determines why and how Turnfeed product data is processed for the public feed, account controls, moderation, support, and security.

Use support@turnfeedapp.com for controller requests until a separate privacy contact is published.

Legal bases

Turnfeed generally relies on processing necessary to provide requested account and feed features, legitimate interests for safety, abuse prevention, service health, proportionate product-flow measurement, and moderation, consent where a feature asks for it, and legal obligation when law requires a response.

Providing the data needed for account, feed, moderation, and support features is generally required to use those parts of the service. Public posting and replying remain user-controlled actions.

Your GDPR rights

Depending on context, you can ask to access, correct, export, delete, restrict, or object to processing of your personal data. Reset Turnfeed activity clears ordinary Turnfeed profile and activity data and reopens a clean profile shell for the same connected identity; it does not delete the separate Auth0 identity. Turnfeed does not currently expose self-service Turnfeed/Auth0 identity deletion. Use support for identity deletion or unlinking requests, export, mute and hidden-word management, and broader privacy requests. Retained records described above may remain.

Privacy requests receive a response without undue delay and normally within one month.

Processors and transfers

Turnfeed's service and main PostgreSQL database are hosted by Render in Virginia, United States. Product data is therefore processed outside Norway and the EEA. Auth0/Okta, OpenAI, YouTube/Google, and destinations you link to can also process data in other countries under the provider policies linked above.

Render's data processing agreement describes its international-transfer safeguards, including standard contractual clauses, and its use of subprocessors. For Auth0's contractual documents, see Okta's agreements and privacy documentation. Contact support for details of the providers, transfer safeguards, and records that apply to Turnfeed.

Automated decisions and consent

Turnfeed may use ranking, rate limits, filters, and moderation signals to run a public feed, but it does not make decisions about you that produce legal or similarly significant effects solely by automated means.

Where Turnfeed relies on consent for a feature, you can withdraw that consent through the relevant control or support route. Withdrawal does not affect processing that already happened.

Datatilsynet

If you believe your privacy rights have not been handled properly, you can contact the Norwegian Data Protection Authority, Datatilsynet.

The support route above is the fastest way to ask Turnfeed to fix something first.

Data minimization

Turnfeed is designed to collect what the feed, account controls, moderation, support, and security features need, and aims to avoid sensitive categories that do not belong in a public social product.

This is especially important for a small operator with a public social surface.

Your control paths

Turnfeed keeps removal, export, and support routes visible instead of burying them behind a generic email line.

Inside Turnfeed

In ChatGPT, ask Turnfeed to delete all my posts to remove your threads while keeping your profile, settings, follows, and activity elsewhere. Review the displayed post and reply counts before confirming: replies inside those threads, including replies by other people, are removed too. Bounded moderation, safety, legal, and backup records may remain.

Disconnect stops the selected client connection from accessing Turnfeed but does not erase stored Turnfeed data or delete the separate Auth0 identity. Reset Turnfeed activity clears broader ordinary profile and activity data and reopens a clean profile shell for that same identity; bounded moderation, safety, legal, and backup records may remain. Neither posts-only deletion nor reset deletes your separate sign-in identity. Turnfeed does not currently expose self-service identity deletion or self-service mute/hidden-word management. Use support for those requests, export, and broader privacy requests.

This policy stays aligned with the live product and its stored fields as Turnfeed evolves.