bye.kim

Privacy policy

Information you provide

When you create an account, the app stores your username, email address, password hash, display name, bio, and the time you accepted the Terms. Passwords are stored as salted scrypt hashes, not as plain text. Verification codes and one-time email/password links are stored as keyed hashes with expirations; raw link tokens are not stored.

Posts, replies, likes, reposts, bookmarks, follows, blocks, reports, verification or business-badge applications, poll options and votes, and private messages are stored to provide those features. Uploaded images, image descriptions, uploaded Reels, and administrator-uploaded custom badge emoji images are stored as files next to the configured SQLite database. Images are served from bye.kim’s own media path and cached as immutable files; each upload is limited to 8 MB, with per-account storage limits. Badge emoji uploads are limited to 256 KB each. Direct-link Reels store the URL you submit. Deleting your account removes associated database records and uploaded media through the account-deletion flow. Unused badge emoji uploads expire and are deleted after one day.

Sign-in and service providers

If Google sign-in is enabled and you choose it, Google provides the app with your Google account identifier, email, and display name. The app stores the account identifier and uses the email and display name for your account. You can link Google to an existing account from its Security settings after signing in. The app does not retain Google access or refresh tokens. Google handles information under its own privacy terms.

If Discord sign-in is enabled, the app requests permission to identify your Discord account and, when server joining is configured, permission to add your Discord account to the operator’s community server. If granted, the app stores your Discord account identifier and an encrypted Discord refresh token so an administrator can queue a server join. The token is stored until it is replaced or your bye.kim account is deleted; you can revoke the authorization through Discord’s authorized-app settings. Discord handles information under its own privacy terms.

For password sign-up, email changes, and password recovery, the app sends your email address and a transactional message to DeoMail. Verification messages include a single-use link and a short-lived code fallback; password recovery uses a single-use link. The app validates and consumes these credentials locally. DeoMail processes the messages under its own terms and privacy practices.

Cookies, local storage, and technical data

The app uses a signed, HTTP-only session cookie to keep you signed in and protect account-changing requests. Sessions expire after seven days. A random CSRF token is kept with the session. The app does not store drafts or other account content in your browser’s local storage.

Rate-limit records contain keyed hashes derived from request IP addresses and action types, rather than raw IP addresses. These records are periodically cleaned up. The app itself does not intentionally collect precise location data or use third-party advertising trackers. Your hosting provider, reverse proxy, or infrastructure may independently record connection and error logs; ask the operator about those systems and their retention.

Personal API keys

If you create an API key in Settings, the service stores its name, a short identifying prefix, permission scope, creation and expiry times, last-use time, and a cryptographic hash used to validate the secret. The full secret is displayed only once when created; the application does not store it in a recoverable form. API requests update the key’s last-use time and are subject to account-level and IP-based rate limits. The service does not intentionally store the API key secret in request logs, but infrastructure operated by the service provider may have separate logging practices.

Revoking a key prevents future use immediately. Key metadata and its non-recoverable hash may remain associated with your account until the account is deleted or the operator otherwise removes those records. Keep keys private and revoke any key that may have been exposed.

How information is used and shared

Information is used to operate accounts, show social features, deliver messages and verification email, enforce rate limits, respond to reports, protect the service, and handle account deletion. Posts, profiles, bios, uploaded images and alt text, poll options and vote totals, Reel captions, and approved badge details and emoji images are visible according to the feature’s public behavior. Links in posts first open on bye.kim, where the destination is shown before you choose to continue. Private messages are available to their participants and are stored in the service database; they are not end-to-end encrypted. Do not send sensitive information through them. When a Reel uses an external video URL, the request passes through bye.kim and is then redirected to that video host, which may receive the viewer’s connection data.

The operator may access stored information to run the service, review reports or applications, address abuse, or comply with applicable law. The app does not sell personal information. Information may be processed by the hosting provider, Google sign-in, and DeoMail when those services are used.

If you use the personal API, posts and replies created or edited with your key are processed and displayed in the same way as content submitted through the website. API authentication metadata is used to validate permissions, enforce rate limits, and support key management. API keys do not provide access to private account data through the documented endpoints.

Storage, security, and retention

Application data is stored in SQLite and uploaded-media files on the server configured by the operator. The app uses security controls such as password hashing, session protections, request limits, and database access checks, but no internet service can promise perfect security. The operator is responsible for server access, TLS, backups, deletion from backups, incident response, and any additional retention schedule.

Information is generally kept while the account is active or as needed to operate the service and address safety or legal obligations. Account deletion removes associated live database records and uploaded media files, but cannot promise immediate removal from backups or logs maintained by the operator or its providers. Unattached image uploads that are not used in a post and unused badge emoji uploads are eligible for cleanup after one day.

Your choices

You can edit your profile, revoke other sessions and API keys, and request account deletion from the app. For access, correction, deletion, or privacy questions that the app does not handle, contact the service operator. Rights and response times depend on the operator’s location and the laws that apply. You may also have the right to object to or restrict certain processing, depending on applicable law.

International access and policy changes

The operator and hosting providers may process information in locations different from yours. The operator should identify relevant locations and safeguards for the actual deployment. This notice may be updated as features or legal requirements change; the operator should publish a revised date and, where required, notify users of material changes.

Children and contact

The Terms require users to be at least 13, or older where local law requires. The service is not designed for children under that age. If you believe a child has provided personal information, contact the operator so it can be reviewed.

Privacy contact: contact@bye.kim.

Back to the feed