Gabe ("we", "our", or "the app") is a truth-based social platform where users share content and vote on its veracity. This policy explains what data we collect, how we use it, and your rights.
1. What We Collect
Account data: name, username, email address or phone number, date of birth (for age verification, 18+), and password (stored as a secure hash).
Sign in with Apple: if you use Apple authentication, we receive your Apple User ID and, optionally, your email address. We never see your Apple password.
Sign in with Google: if you use Google authentication, we receive your Google User ID, email address, and name (as provided by Google). We never see your Google password.
Content: posts you publish, votes you cast, comments you write, and any images you upload.
Images: uploaded images are stored on Cloudinary (CDN delivery service). Each image passes a client-side AI moderation check (NSFW.js) before upload — explicit content never leaves your device.
Usage data: your GABE score, score history, total interactions, and behavioral patterns used for the moderation algorithm (anti-bullying obsession flag).
IP address: stored at signup for anti-abuse purposes (rate-limiting account creation per IP).
2. What We Don't Collect
Location data
Contacts or address book
Device identifiers beyond what is strictly necessary
Biometric data
Financial information
3. How We Use Your Data
To create and manage your account
To display your content and score in the app
To calculate your GABE score based on community votes
To send important service-related notifications (no marketing without consent)
4. Data Sharing
We do not sell your personal data. We do not share it with third parties except:
Infrastructure providers — strictly necessary to operate the service: MongoDB Atlas (database), Railway (hosting), Cloudinary (image CDN).
Authentication providers — Apple and Google receive your authentication request when you choose those sign-in methods. They do not see your activity on GABE.
Legal obligations if required by law.
5. Data Retention
We retain your data as long as your account is active. You can request deletion at any time by contacting us. We will delete your account and associated data within 30 days.
6. Your Rights
Access the data we hold about you
Correct inaccurate information
Request deletion of your account and data
Export your data
7. Security
Passwords are stored using bcrypt hashing. Communication between the app and our servers is encrypted via HTTPS. We apply rate limiting to protect against unauthorized access.
8. Children
Gabe is not intended for users under the age of 13. We do not knowingly collect data from children.
9. Changes to This Policy
We may update this policy. We will notify users of significant changes via the app. Continued use after changes constitutes acceptance.