Safety & Moderation Policy
Anonymous shouldn't mean a free pass for abuse — here's how we moderate.
1. Instant Filtering
Our first line of defense is an aggressive, synchronous filtering engine powered by Leo-Profanity. Every message submitted to the platform is instantly scanned prior to being persisted in our database. We have extended this system with custom dictionaries, including extensive Bengali datasets, to cover a broad spectrum of languages and dialects.
When extreme profanity or banned phrases are detected, the offensive content is masked before it ever reaches the recipient, and the sender earns a strike on their moderation record.
2. AI Context Analysis
Because modern harassment is nuanced and context-dependent, simple keyword matching is not enough. To catch subtle bullying, hate speech, threats, and identity attacks, every message is scored by OpenAI's moderation model.
When a message scores as high-toxicity, its content is masked — replaced with asterisks so the abuse never lands — and the sender is struck. The (censored) message still arrives rather than silently vanishing, so a false positive can never disappear a legitimate note without a trace.
3. Strikes & Shadow-Bans
Each masked message adds a strike, keyed to the sender's IP and device fingerprint rather than an attacker-resettable client value. Moderators can review the strike ledger and shadow-ban a sender on demand; the system also auto-shadow-bans a serial abuser once they cross a high strike threshold.
A shadow-banned sender's messages silently fail — the recipient receives no notification and sees no trace, denying trolls the feedback they need to adapt. A logged-in restricted account instead sees a clear "account restricted" notice, so a genuine user is never left guessing.
The data behind these safety signals is described in our Privacy Policy.
4. Encryption & True Deletion
Your inbox is encrypted at rest under a per-account key — the mechanism is detailed in our Privacy Policy. Deleting your account destroys that key. Delete means delete: no deactivation limbo, no recovery window.
5. Reporting and Continuous Improvement
We update our models and dictionaries as new slang and abuse patterns emerge.