LEGAL

Privacy Policy

We collect as little data as possible. Here is exactly what we do and do not do.

OIO.SO is built around a fundamental belief: your data belongs to you. We do not sell, share, or monetize user information. We do not run ads. We do not track behavior across the web.

WHAT WE STORE
Username — chosen by you, public
Display name and bio — chosen by you, public
Avatar — stored on IPFS, public
OIO identity — encrypted at rest, never exposed
Bitcoin wallet ID — used to receive donations
Posts — stored on IPFS, public by design
WHAT WE DO NOT COLLECT
✗ Email address
✗ Phone number
✗ Real name or government ID
✗ IP address logs — automatically purged every 24 hours
✗ Browsing behavior or tracking cookies
✗ Third-party analytics
IP ADDRESS POLICY — AUTOMATIC PURGE

Server access logs — which may temporarily contain IP addresses as part of standard network operation — are automatically rotated and purged every 24 hours.

Log files are limited to a maximum of 10MB and are never retained beyond a single rotation cycle. No IP address data is stored in our database, analyzed, or shared with any third party.

This policy is enforced at the infrastructure level — not just as a promise — through automatic log rotation configured directly in our container runtime.

DECENTRALIZED IDENTITY

Your identity on OIO.SO is cryptographic. When you register, you receive an OIO KEY — a unique cryptographic key that serves as your authentication credential. We do not know who you are. Only you hold your OIO KEY.

If you lose your OIO KEY, we cannot recover it. There is no email reset. This is a feature, not a bug — it means no one can be forced to reveal your identity.

DECENTRALIZED STORAGE

All content is stored on IPFS — a distributed network with no central point of control. Once published, content exists across multiple nodes worldwide. No single authority, including OIO.SO, can remove content from IPFS. This makes your content resistant to censorship and takedown requests.

AUTOMATIC DELETION — YOUR RIGHT TO BE FORGOTTEN

OIO.SO automatically deletes all posts from its index 30 days after publication. This is a core privacy protection — not an optional feature.

Upon deletion, OIO.SO removes the content reference from its database, making the post invisible to all users and inaccessible through any OIO.SO URL. Search engines are notified to deindex the content, preventing further distribution of potentially sensitive information published intentionally or unintentionally.

This policy reflects our commitment to minimizing data retention and protecting users from the long-term consequences of public content. It also reduces the platform's exposure to legal and jurisdictional risk globally.

NO SURVEILLANCE

We do not monitor, moderate, or control what you publish beyond enforcing our Terms of Service in response to reported violations. We do not have the ability to read your private messages — because we do not have private messages. All content on OIO.SO is public.

BITCOIN PRIVACY

Bitcoin transactions are public on the blockchain. Donation amounts and wallet addresses are visible to anyone with a block explorer. We recommend using a wallet address that is not linked to your real identity if you require additional financial privacy.

About Terms of Service Documentation