Account identity
Baithak stores your email address, a password hash, a recovery-key hash and your public profile. Your email address is used for signing in and is not published on your profile. Passwords use salted scrypt hashes; session tokens and recovery keys are stored as hashes. Signing in does not verify an email address or a real-world identity. The founding administrator role requires the configured owner email and a separate private invite.
Information you choose to share
We store your profile fields, posts, uploaded images, follows, reactions, votes, Circle memberships, reports, messages and feed preferences. Posts, profiles, replies, Circles and reposts are visible to signed-in members. Images attached to them can be viewed by permitted members. Public product and policy pages are accessible without an account. Do not treat Circle posts as private.
Information with restricted visibility
Bookmarks, mute/block preferences and account exports are account-scoped. Messages can be read through the app only by their participants. Reports are visible to administrators. Messages are not end-to-end encrypted; people operating the underlying infrastructure may access stored records.
Data on your device
Local storage saves your theme and written post drafts. Message drafts and unconfirmed sends are saved in session storage scoped to your account and conversation, normally cleared when the tab session ends. Message retry identifiers prevent duplicates. Removing a sent message clears its body for both participants; a timestamped placeholder remains to preserve conversation ordering. Drafts belong to your account identifier on that device. The service worker caches static application assets and a generic offline page. It does not cache feeds, profiles, messages or API responses. If you use a shared device, sign out and clear browser storage when finished.
Your choices
Edit your profile, delete individual posts, restrict messages, mute or block accounts, and download a JSON export from Settings. Member account deletion removes the profile and its owned social records and uploaded images. Messages involving that account are deleted as part of this operation. The founding administrator must retain an account to operate the Site.
Retention and operations
Content is retained until you or an authorized administrator remove it. Sessions expire after 30 days and can be revoked by signing out or changing your password. Expired sessions and short-term rate counters are pruned. The owner operates storage, moderation, infrastructure logs and backups; backups may retain removed information until their retention period ends. Baithak has no advertising trackers or behavioral ranking profiles in its application code.
Sample profiles
The 100 sample profiles are fictional content created for reviewing this release. They have no credentials and cannot generate activity. They do not stand in for real account holders and are excluded from real community statistics. You can hide them using feed controls.
Privacy questions
Use the Report option for concerns about member content. Use Settings to export or delete your account data. If account access is lost, use your saved recovery key on the password recovery page. Never post a recovery key publicly. Baithak does not provide a staffed privacy mailbox in this MVP.