Skip to content
Legal

Privacy Policy

What we collect, why we collect it, and what you can do about it. Doxlore asks for as little as it can get away with.

Last updated 16 August 2026

1. What we collect

When you create an account, we store:

  • your email address, used to sign you in, verify your address, and reset your password
  • a one-way hash of your password (the password itself is never stored and cannot be recovered by us)
  • whether your email has been verified, and whether the account is suspended
  • a username, either one you choose or one generated for you, shown publicly next to your comments

When you take part in a discussion, we store:

  • the text of your comments, along with the topic and account they belong to
  • any image you attach, which is converted and compressed in your browser before upload
  • reports and takedown requests you submit, including the contact details you provide on the public takedown form
  • the timing between your keystrokes while composing a comment (intervals only, never the keys themselves), used as an automated spam signal

We also process your IP address transiently in order to rate-limit sign-in attempts and posting, which is what stops the site being flooded by automated traffic.

Doxlore has no profiles or avatars. If you don’t choose a username, one is generated from the first part of your email address plus a random number. Your full email address is never shown to other users, but an auto-generated username can expose a fragment of it. Usernames are shown next to your comments and are how @mentions notify people when someone replies to them.

2. Cookies

Signing in sets two cookies holding your session tokens. Both are httpOnly, meaning they cannot be read by JavaScript running in your browser, and they exist solely to keep you signed in. There are no advertising or analytics cookies.

Your theme preference is kept in your browser’s local storage and never leaves your device.

3. Why we process it

  • to operate the service: authenticating you, publishing your comments, and showing discussions
  • to keep the platform usable and safe: filtering profanity, rate-limiting abuse, reviewing reports, and enforcing suspensions
  • to communicate with you about your account: verification, password resets, and acknowledgements of reports or takedown requests
  • to meet legal obligations and respond to valid legal requests

4. Who else sees it

We do not sell your data. It reaches third parties only where the service needs them to function:

  • our hosting and database providers, which store the data described above
  • Cloudinary, which hosts uploaded images
  • our email provider, which delivers verification, password reset, and notification messages
  • an AI provider (Google Gemini, or Groq as a fallback), which receives the text of published comments on a topic in order to generate the summary of viewpoints shown alongside it, and separately screens comment text (and, where needed, an attached image) for spam and inappropriate content as part of moderation

Only published comment content is ever sent to the AI provider for these purposes. Email addresses, IP addresses, and keystroke timings are never included.

5. How long we keep it

Account data is kept while the account exists. An account that never completes email verification is deleted automatically once its verification code expires. Comments and images stay until they are deleted by you or removed by a moderator. Reports and takedown requests are retained as a record of moderation decisions. Cached copies and backups may persist for a short period after deletion before expiring.

6. Your choices and rights

You can delete any comment you posted at any time. Depending on where you live, you may also have the right to request access to your data, correction of it, deletion of it, or a copy in a portable format, and to object to certain processing.

To exercise any of these, write to legal@doxlore.app. If your concern is about material published about a brand, product, or franchise you hold rights in, the takedown form is the faster route.

7. Security

Passwords are hashed, session tokens are held in cookies your browser will not expose to scripts, and signing out or resetting your password immediately invalidates every existing session. No system is perfectly secure, and we cannot guarantee absolute security, but we do not store anything we do not need.

8. Children

Doxlore is not intended for anyone under 18, and accounts may not be created by them. If we learn that we hold data from someone under that age, we will delete it.

9. Changes

We may update this policy. Where a change is material we will take reasonable steps to let you know, and the date at the top of this page will always reflect the current version.