1. What this policy covers
This Privacy Policy explains how SPOOKY handles information when you browse the archive, create an account, file reports, upload evidence, post comments, propose entities, suggest corrections, corroborate reports, flag content, or use moderation and notification features.
The archive is built around public user submissions. Do not submit information you are not comfortable sharing under this policy and the Terms of Service.
2. Information you provide
Account information: private email address, username, display name, email-verification challenge records, session records, role, settings, and timestamps. The archive does not store an account password.
Public contribution information: reports, creepypasta, comments, proposals, corrections, corroborations, flags, profile activity, locations, dates, witness counts, motif tags, linked entities, and any text you choose to submit.
Evidence uploads: photos, video, audio, filenames, file type, size, thumbnails, derived previews, and related report metadata. Photos are processed to remove EXIF/GPS metadata where supported, but visible details in the content itself may still identify people or places.
Optional location information: typed locations and coordinates you submit for the sightings map. The browser may ask for device location only when you choose that feature; the archive stores coordinates only if you submit them with a report.
3. Information collected automatically
The archive may process technical data needed to operate and protect the service, such as IP-derived connection information, browser/device details, request timestamps, session cookies, security events, rate-limit records, abuse-prevention signals, and logs generated by hosting or monitoring providers.
The app uses cookies or similar storage for login sessions and security. It does not need advertising cookies to operate.
4. How information is used
To operate the archive: accounts, sessions, submissions, evidence, comments, notifications, profiles, search, maps, moderation, backups, and support.
To protect users and the operator: rate limits, abuse detection, spam prevention, security review, takedowns, flag review, audit trails, legal compliance, and enforcement of the Terms and Content Policy.
To improve the archive: debugging, reliability, usability, search quality, entity organization, and future features such as digests or watched entities.
5. Public visibility and anonymous filing
Public submissions may be visible to anyone, indexed by search engines, discussed by other users, copied by third parties, or preserved in backups. Think carefully before posting names, addresses, workplaces, schools, exact coordinates, faces, license plates, or other identifying details.
Anonymous filing hides public attribution for qualifying field reports, but it does not make the report private. The archive may keep internal account linkage for moderation, corroboration, safety, abuse prevention, legal compliance, and operator protection.
6. Sharing and disclosure
The archive may share information with service providers that help host, store, secure, back up, monitor, analyze, maintain, or send essential account email for the app, subject to their role in operating the service. The configured mail-delivery system, and any mail infrastructure providers involved, process the destination address and message metadata needed to deliver sign-in codes.
The archive may disclose information when needed to comply with law, respond to valid legal process, protect rights and safety, investigate abuse, enforce policies, respond to copyright/takedown requests, or transfer the service as part of a merger, sale, or reorganization.
The archive does not sell user personal information as an advertising product. If that ever changes, this policy must be updated first.
7. Retention and deletion
The archive may retain account data, public submissions, evidence, moderation records, security logs, and backups for as long as needed to operate the service, preserve the archive, comply with law, resolve disputes, enforce policies, and protect the operator.
Deleting or hiding public content may not immediately remove copies from backups, logs, search engines, third-party caches, screenshots, or users who already accessed it.
8. Children and sensitive information
The archive is intended for adults. Users must be at least 18 years old, or the age of legal majority where they live, to create an account or submit content.
Do not submit health, mental-health, financial, government-ID, biometric, intimate, private-location, child-related, or other highly sensitive information unless you have a lawful reason and are comfortable with the risk of public discussion and moderation review.
9. Security
The archive uses reasonable operational safeguards for the stage of the project, including short-lived single-use email codes, keyed challenge hashes, hashed session tokens, secure cookie controls, upload processing, rate limits, and abuse-prevention measures. No internet service can promise perfect security.
Before public launch, the operator should configure HTTPS, a real legal/security contact, off-server backups, monitoring, and any hosting-provider security controls.
10. Your choices
You can choose what to submit, whether to use anonymous filing where available, whether to include coordinates, and whether to attach evidence.
You may use account settings, report editing/deletion, flags, or the legal contact channel to request review of content, account issues, privacy concerns, or safety issues. Some records may be retained for legal, safety, moderation, backup, or abuse-prevention reasons.
11. Contact
For privacy, safety, security, or data questions, contact the archive operator through the legal contact channel below. A real inbox must be configured before public launch.