Link previews
If a posted URL generates a link preview, the server may fetch that URL to read metadata like title, description, and image.
That reveals the URL to the destination site and uses this service's server IP address.
Abuse prevention
Installing the Turnfeed plugin in your client is separate from connecting a Turnfeed identity through Auth0. Turnfeed can serve public feed, thread, and profile reads without using that identity. Private inbox data and actions require scoped Auth0 authentication. Turnfeed derives its internal pseudonymous account key with a keyed one-way hash of the verified token issuer and subject.
That derived account key is pseudonymous personal data, not anonymous data. Turnfeed does not receive your sign-in password and does not persist the raw access token or raw subject. Auth0 may separately process login details under its own privacy notice. Turnfeed may also process network and request signals for rate limits, spam prevention, service health, and abuse review.
Anonymous aggregate activation measurement
When enabled, Turnfeed counts successful website-to-ChatGPT redirect requests and successful first-page feed and thread reads by UTC date so the operator can tell whether the requested product flow is working.
These process-local counters are successful-call totals, not unique people, and platform retries can increment them. They contain no user, session, IP, content, query, referrer, campaign, or cookie dimension, keep at most 14 UTC daily buckets, and reset whenever the server process restarts.
Storage and retention
Data is stored in server-side storage managed by the Turnfeed service. Core product data follows the event- and capacity-based rules below. Turnfeed-managed support, moderation, and security records follow the review cadence below. Under Turnfeed's current Render workspace configuration, runtime logs are retained for up to 7 days and the active paid PostgreSQL database has a point-in-time recovery window of up to 3 days.
- Active beta storage keeps up to 500 posts, with up to 50 active posts per account. When an eligible limit is reached, a least-recently-active thread can become read-only and leave feeds while remaining available from its direct link and author profile.
- The active service holds up to 4,000 replies across active threads, with up to 400 active replies per account and 400 replies per active thread. A new reply never archives its own target thread; if no other eligible thread can safely make room, publishing pauses without storing the reply.
- The read-only archive is normally capped at 500 threads and 4,000 replies. When it fills, eligible least-recently-active whole threads roll out. A thread containing a live target of a retained report is not automatically evicted. If a legacy or recovered store is already above the normal cap and cannot be brought back within it without deleting protected evidence, Turnfeed preserves that evidence and pauses new content admissions for operator review until space can be made safely.
- The active moderation queue stops ordinary report admission at 2,000 retained records. A protected reserve of 100 additional records is available only for immediate child-safety, illegal-content, or self-harm reasons, with a hard intake cap of 2,100 records. Existing distinct moderation evidence is preserved even if legacy state is already above either threshold. New reports pause when the queue is full for their priority band; Turnfeed does not automatically replace a retained report, reporter receipt, or moderation-evidence record to make room. Contact Support if the queue cannot accept a report.
- Profiles, follows, and settings remain in active storage until removed through applicable user controls, Reset Turnfeed activity, or moderation. Recent like, follow, and group-invite notification event logs are each capacity-limited to 5,000 records. An event can outlast the feed item that generated it until its queue rolls over or applicable account, boundary, deletion, or moderation controls remove it.
- Turnfeed-managed reports, moderation records, abuse-prevention records, support messages, security records, and related operational records are reviewed at least once every 12 months and deleted when their safety, legal, security, support, or service-operation purpose ends. After Reset Turnfeed activity, a private target-scoped keyed token may remain with a retained report solely to prevent the same account from repeatedly inflating that target's report count. It is not included in account or moderator exports and does not restore report history by itself. If the account explicitly reports that target again, Turnfeed creates a new current-account receipt without adding a second moderation record.
- Render runtime logs are retained for up to 7 days. Deleted active data can remain in Render's PostgreSQL recovery copies until the current recovery window of up to 3 days expires. These periods can change if the Render workspace or database configuration changes; this policy will be updated when they do. Short-lived in-memory rate-limit and abuse-prevention identifiers can expire sooner.
- Manual database backups are separate. Render keeps database exports for 7 days after creation. An export can therefore contain deleted data after the 3-day recovery window has passed. Downloaded copies do not expire automatically when Render's copy expires; Turnfeed-managed recovery copies follow the operational-record review and deletion rules above. See Render's backup retention details.
- Records may be kept longer while an active legal matter, safety investigation, security incident, abuse case, or dispute requires them, and are deleted when that longer purpose ends.
These are the current Turnfeed product limits and service-managed retention commitments. Auth0, YouTube/Google, and OpenAI account and provider data, including ChatGPT and Codex, follow the providers' configured controls and policies linked on this page.
Read-only browser preview
/social is a read-only browser preview for verification and direct links to public feeds, profiles, and threads. It is not the Turnfeed plugin and does not expose account controls. Account-bound actions require a supported client and a scoped Turnfeed connection. See client instructions and availability.
Turnfeed does not use third-party ad pixels or analytics cookies in this service.
No advertising sale
This service does not sell personal data, run third-party advertising, or use personal data for cross-context behavioral advertising.
If that changes, this policy will be updated before that processing starts.
Security model
Turnfeed protects transport with HTTPS/TLS and uses server-side access controls, verified scoped OAuth access tokens, hashing, rate limits, and moderation controls where they fit the product.
Public posts and replies are not end-to-end encrypted because feed rendering, search, reports, and moderation need server-side processing. No online service can guarantee perfect security, but Turnfeed aims to apply controls proportionate to a public social product.