Privacy Policy
Last updated: 2026-08-22
This Policy explains what personal data BiKhialesh processes, why, and your rights under the EU General Data Protection Regulation (GDPR). We designed BiKhialesh to be anonymity-first and to collect as little as possible. The data controller is Masoud Alali, who operates BiKhialesh from the Netherlands. For any privacy question or to exercise your rights, contact [email protected].
What data we process
We process: account data you provide — your handle, display name, and optional bio, photos, and location (we keep a short history of changes to your handle and display name for safety and abuse prevention); sign-in data — if you use Google or Apple, the basic account identifier the provider returns to us, and if you use email sign-in, your email address; a record of your acceptance of our Terms — the version accepted and when — and the time you confirmed being 18 or older; the content you post, plus your reactions, bookmarks, word votes and suggestions, and reports; your private favorites list — accounts you save for yourself, which is never shown to the saved account or to anyone else; records from the retired follow feature — who you followed and who followed you before that feature was withdrawn — which we retain with your other account records; if a post you submit does not match the active words, the attempted text, kept briefly for troubleshooting; notifications we send you inside the service; technical data needed to run and secure the service, including IP address, device model and app version, locale and timezone, session identifiers, push-notification tokens if you enable notifications, and server logs; website usage statistics that are not linked to your account (see "Usage statistics"); automated safety assessments of posts — scores and flags produced by our moderation systems, which can include a signal that a post may relate to self-harm, used only to prioritise human review and never shown to other users; and machine representations (embeddings) of your content used for search, ranking, categorisation, and safety. We do not ask for your real name to use the service. Posting anonymously hides your identity from other users; it does not mean we hold no technical data about the session.
Public content and sharing
BiKhialesh is a public platform. Posts and profiles that are not restricted are visible to anyone, including people without an account, and public pages — such as word pages — can be indexed by search engines. The service also generates share images for posts so they can be shared outside BiKhialesh. "Anonymous" means the author label is hidden; it does not make the content confidential. Anyone can copy, save, screenshot, or re-share public content, and copies held outside the service — search-engine caches, screenshots, re-posts — are beyond our control: deleting or detaching content on BiKhialesh does not remove copies that have already left it. Please keep this in mind before you post.
Why we process it (legal bases)
Under Article 6 GDPR we rely on: performance of our contract with you (Art. 6(1)(b)) to run your account and deliver the service; our legitimate interests (Art. 6(1)(f)) in keeping the service secure, preventing abuse, moderating content, improving the platform, and measuring how the service is used, balanced against your rights; your consent (Art. 6(1)(a)) for optional things such as push notifications, which you can withdraw at any time; and compliance with a legal obligation (Art. 6(1)(c)) where the law requires us to retain or disclose data, for example to handle illegal content under the Digital Services Act. We do not sell your personal data.
Service providers and international transfers
We share data with providers who process it on our behalf under data-processing agreements: Hetzner (hosting and backups, in the EU); Cloudflare (content delivery, security filtering, bot protection, image storage, and routing of our contact email); OpenAI (automated safety classification and risk assessment of post content, and generation of machine representations — embeddings — of post content for search, ranking, and categorisation); Anthropic and Google (Gemini API), which may receive post text and word-suggestion text for automated safety classification, risk assessment, categorisation, and translation only when we have configured them as fallback providers alongside OpenAI — embeddings and the dedicated content-safety check remain with OpenAI; Google (push notifications via Firebase Cloud Messaging); Apple (delivery of push notifications to Apple devices via APNs); Sentry (error and performance monitoring); and an email-delivery provider for sign-in codes and service messages. These providers may process data only on our instructions. Sign-in works differently: when you sign in with Google or Apple, that provider also processes your data as an independent controller under its own privacy policy. Operational logs and monitoring data are otherwise processed on infrastructure we control. Where data is transferred outside the EU/EEA — for example to OpenAI, Anthropic, Google, Cloudflare, or Sentry in the United States — we rely on the European Commission's Standard Contractual Clauses and, where applicable, adequacy decisions, together with additional safeguards. We do not share your data for others' independent marketing.
Automated content moderation
To keep the platform safe, posts are screened by automated systems: a content-safety classifier and a risk-scoring step that uses OpenAI (or, where we have configured fallback providers, Anthropic or Google's Gemini API). A post may be published and then withheld, or hidden pending review, when its risk score is high or it matches a prohibited category. These systems support human moderation rather than replacing meaningful human oversight, and they do not produce legal or similarly significant effects on you in the sense of Article 22 GDPR. When automated screening leads to your content being restricted, we tell you the main reason and you can ask a person to review the decision by replying to the notice or writing to [email protected]. Your content is also turned into embeddings used to rank and categorise posts; this is not a decision about you as a person.
Usage statistics (analytics)
To understand how the website is used — which pages are visited, which features are used, and whether the service is working — we run our own analytics software (Umami) on our own servers in the EU (Hetzner, Finland). It sets no cookies and stores nothing on your device. Each visit is counted with a short-lived identifier computed on our server from your IP address, your browser type, and a value that changes every day; it cannot be turned back into your IP address, your IP address itself is not stored, and the identifier is different the next day, so visits cannot be linked across days. We record the page visited without the identifier of any post, profile, or hashtag in the address and without any query parameters, the site that referred you (domain only), browser, operating system, device type, screen size, language, country, and product events such as "post published" or "word voted". We never record post text, your user id, your account, or whether a post was anonymous, and no event is recorded when you publish an anonymous post. This data is not shared with anyone and is not combined with your account. We process it under our legitimate interest in understanding and improving the service (Art. 6(1)(f) GDPR). You have the right to object at any time: turn off "Usage statistics" in Settings on each device you use; we also honour your browser's "Do Not Track" setting. Raw usage records are deleted after 90 days. The BK mobile app also counts usage. It sends to our own server the screen name, the event (e.g. "post published"), app version, operating-system version, language, screen size, and a random token that lives only until the app is closed. Our server derives your country and a daily-changing identifier from your IP address and then discards the address; it is never stored. No account, user id, post, profile, or hashtag is sent, and nothing is sent when you publish anonymously. The data stays on our EU servers, is shared with no one, and is deleted after 90 days. Basis: our legitimate interest (Art. 6(1)(f) GDPR). You may object at any time by turning off "Usage statistics" in the app's Settings. Apart from this, we use only the cookies needed to run the service: your sign-in session (bikhialesh_session); two short-lived sign-in helpers (g_oauth while you sign in with Google, g_restore while you restore a closed account); and your language and theme choices (locale, theme). These do not require consent because the service cannot work without them.
How long we keep data
We keep data only as long as needed for the purpose it was collected. Account data and content are kept while your account is active. When you request deletion, your account is closed immediately, content posted under your name leaves public view, and a 30-day restoration window begins in which you can get everything back by signing in again. When the window ends, deletion is finalized: your direct account identifiers and ordinary activity records are permanently erased or irreversibly replaced, and content you posted anonymously — which stays on the service throughout — is permanently detached from your account. A residual record stripped of your direct identifiers may remain, and narrowly required dispute, safety, legal-hold, and integrity records may remain in pseudonymised form for defined periods. If you have enabled the "deeper anonymity" option in your settings, anonymous posts detach earlier, on the schedule described there. Once detached, content belongs to no account, may remain on the service, and can no longer be edited, deleted, or exported through your account. Some concrete periods: server and access logs are kept for no more than 28 days; raw usage-statistics records are deleted after 90 days; sign-in sessions expire after at most 30 days; uploaded images you never save to your profile are deleted after about 24 hours; text of posting attempts that fail the word requirement is deleted after at most 30 days; residual copies in backups are erased on our normal rotation. Where the law requires us to preserve certain records — for example for a pending dispute, an illegal-content obligation, or a legal preservation order — we keep the minimum necessary for as long as that duty lasts, and the steps above may be delayed for the affected data.
Your rights
Under the GDPR you have the right to access your data (Art. 15), correct it (Art. 16), erase it (Art. 17), restrict or object to processing (Art. 18 and 21), and receive your data in a portable, machine-readable format (Art. 20) — BiKhialesh already offers a self-service data export. Where processing rests on consent, you can withdraw it at any time without affecting earlier processing. These rights apply to personal data: where content has been permanently detached from any account (see "How long we keep data"), we can no longer attribute it to an account, and under Article 11 GDPR the rights in Articles 15 to 20 — including erasure — no longer apply to that content, unless you can provide information that reliably enables us to attribute it to you; after detachment, that will normally not be possible. Such content can still be reported like any other post, and we can still remove it under our own rules. To exercise any right, contact [email protected]; we will respond within the time the GDPR allows. You also have the right to lodge a complaint with a data-protection supervisory authority in the EU/EEA, in particular in your country of residence or work. The lead supervisory authority for BiKhialesh is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Data breaches
If a personal-data breach occurs that is likely to put your rights at risk, we will notify the competent supervisory authority without undue delay and, where the law requires, within 72 hours of becoming aware of it, as set out in Articles 33 and 34 GDPR. Where the breach is likely to result in a high risk to you, we will also inform affected users directly and explain what happened and what you can do.
Children
BiKhialesh is for users aged 18 and over. We do not knowingly process the personal data of anyone under 18. If you believe a child under 18 has given us their data, contact [email protected] and we will delete it.
Contact
For any privacy question, to exercise your rights, or to reach the person responsible for data protection, contact [email protected]. The data controller is Masoud Alali (Netherlands).
For authorities: [email protected] is our single point of contact under Articles 11 and 12 of Regulation (EU) 2022/2065 (Digital Services Act). Communication in English or Dutch.