Privacy Policy

Last updated: October 9, 2026

Draft — this document is pending legal review and may change before Loqva's official launch.

This policy explains what information Loqva collects, how it's used, and the choices you have. Loqva is operated by LogCore Technology LLC ("we", "us") and runs on servers we operate ourselves in the United States. We don't sell your information, we don't show ads, and we don't use third-party analytics or tracking scripts.

What's public

Loqva is a public forum. Your username, profile (bio, avatar, links you add, and any optional fields you choose to show), and everything you post or comment are visible to anyone, including search engines. Gender and birthday are only shown on your profile if you turn them on. Your votes are not public.

Public content is also open to AI systems: we allow AI search assistants and AI training crawlers to read public pages, and we notify search engines when public posts change. Earlier versions of edited posts and comments stay publicly viewable in their edit history, unless a moderator hides a version.

What we collect

  • Account information: your email address, username, birthday (accounts are for people 13 and older; it stays private unless you choose to show it on your profile), and a password hash (passwords are hashed with Argon2id; we never store or see your actual password). When you choose a password, we check it against known data breaches using Have I Been Pwned's privacy-preserving range service: only the first 5 characters of a one-way hash of the password are sent, never the password itself.
  • Profile information you choose to add: bio, avatar, social links, gender, birthday, and community interests.
  • Content: posts, comments, images you upload, private messages, and any appeals you file (including the conversation with staff about them). Private messages are visible only to you and the other person, but they are stored on our servers and are not end-to-end encrypted. Staff do not read private messages in the normal course of running the site; we may review them when investigating a report of abuse or when required by law.
  • Activity on the site: your votes, favorites, subscriptions, follows, blocks, notification settings, which threads you've viewed while logged in, and when you were last active (an activity signal sent periodically while the site is open in your browser).
  • Abuse-prevention signals: when you register, log in, or use the site while logged in (at most once a day), we record your IP address and a keyed hash of it, and a keyed hash of a random device identifier stored in a cookie (never the identifier itself). The raw IP address is kept for 90 days so site administrators can investigate abuse (every time an administrator views one, it is logged), then deleted; the one-way hashes, which can be compared for matches but not turned back into the original, are kept longer (see below). We use these only to stop ban evasion, vote manipulation, account takeovers, and automated abuse, and to email you when your account is signed in from a new device, as described in the Content & Moderation Policy.
  • Site statistics: when a page loads, your browser tells us which page it was and where you came from (the referring site's address only). We count unique visitors with a one-way hash of your IP address and browser, mixed with a random value that changes every day and is never stored, so the same visitor can't be recognized from one day to the next. Only daily totals are kept; nothing is stored about you personally.
  • Push notifications: if you turn them on, the push address your browser gives us for this device, and which notification types you want pushed.
  • Moderator reviews and applications: reviews you write about moderators (shown without your name; site staff can see who wrote them) and applications you send to become a moderator.
  • Messages to us: what you send through the “Talk to us” form, including your name and email address.
  • Sign-in security: if you turn on two-step verification, an encrypted authenticator-app secret, the public keys of your passkeys (passkeys never give us your fingerprint, face, or device PIN), and one-way hashes of your recovery codes. We also keep a list of your signed-in devices (browser and last-used time) so you can sign them out.
  • Rate-limit counters: short-lived counters (keyed by account, email address, or the hashed IP above) that limit how often actions like logging in or posting can be attempted. These expire automatically within an hour.

Cookies and local storage

  • A session cookie that keeps you logged in (expires after 30 days).
  • A device-identifier cookie used only for the abuse-prevention signals above (expires after 2 years).
  • A language-preference cookie.
  • Your browser's local storage keeps your recent searches on your device only (we never receive them), and the installable app version of the site caches pages for offline use.

We don't use advertising, analytics, or cross-site tracking cookies. Our own site statistics are cookie-free (see “Site statistics” above).

How we use information

  • to run the site: showing your content, delivering messages and notifications, and keeping you signed in;
  • to personalize your home feed and community recommendations based on your interests, favorites, and subscriptions;
  • to send account and security emails (email verification, password resets, email-change confirmations, sign-in alerts) and, only if you turn them on, digest emails and push notifications;
  • to keep the site safe: enforcing our rules, rate limiting, and detecting spam, ban evasion, and vote manipulation;
  • to investigate abuse: site administrators have a tool that brings together an account's activity and abuse signals and calculates a risk score with the reasons behind it. The score only guides a person investigating; it never takes action on its own, and every time an administrator opens an account this way, it is logged;
  • if you answer the optional questions when you join (what brings you here, your topics and how familiar you are with them, how technical you are, whether you'd like to moderate, and how you found us), to suggest posts and communities and to understand how people find the site. You can change or clear these answers any time in Settings;
  • to comply with the law.

Who we share it with

  • Cloudflare, which carries traffic to and from the site and so processes your IP address and requests as our network provider.
  • Have I Been Pwned, which receives only the first 5 characters of a one-way hash when you choose a password (see above), never the password or your account details.
  • An email delivery provider, which receives your email address and the message content when we send you an account email.
  • Browser push services (run by your browser's maker, such as Google, Apple, or Mozilla), which deliver push notifications you turned on. The notification content is encrypted so only your device can read it.
  • Legal and safety: we may disclose information if required by law, or if we believe in good faith it's necessary to protect someone's safety or our rights.
  • Business transfer: if LogCore Technology LLC is ever merged or acquired, this information may transfer to the new owner, who must honor this policy.

How long we keep it

  • Account and profile information: while your account is open.
  • Closed accounts: when you close your account, your profile disappears right away, and the private information we hold about it (such as your email address, sign-in records, and posts you deleted) is kept, visible only to site staff, for 365 days so abuse can still be investigated. Then it's deleted automatically, unless you ask us to erase it sooner.
  • Posts and comments you delete: hidden from everyone right away; the text is kept, visible only to site staff, for 365 days for safety investigations, then wiped.
  • Abuse-prevention signals: raw IP addresses 90 days; the hashes 365 days. If an account is banned for a serious violation (spam, harassment, threats, adult content, ban evasion, or vote manipulation), the hashes linked to that account are kept for as long as the ban lasts, then deleted.
  • Rate-limit counters: up to one hour.
  • Backups: encrypted daily backups for 14 days, plus one per month for 12 months, so deleted information can remain in a backup for up to 12 months.

Closing your account and erasing your data

You can close your account from your account settings. You're signed out everywhere, your profile disappears, and your votes stop counting. Your posts and comments stay on the site with your name removed, so existing discussions still make sense; you shared them under the Creative Commons license in our Terms, which can't be withdrawn. The private information linked to a closed account is kept for staff as described above, then deleted.

You can also ask us to remove your posts and comments and erase everything we hold about you: use "Request erasure" in Settings (while signed in), or email [email protected] from your account's email address. We carry out erasure requests within 30 days and email you when it's done. Erasure wipes the text of your posts and comments (other people's replies stay), their edit history, images you uploaded, your account, and your sign-in records. Backups age out on the schedule above.

Your choices and rights

Wherever you live, you have the same rights: to access your information, download a copy of it (Settings → Your data gives you everything you've created and your profile, as JSON and Markdown), correct it, delete it, object to how we use it, and withdraw consent for optional features such as digests and push notifications at any time. For anything you can't do in Settings, or any other privacy question, email [email protected]; we'll respond within 30 days.

Security

Traffic to the site is encrypted in transit, passwords are hashed with Argon2id, authenticator-app secrets are encrypted, and you can protect your account with passkeys or two-step verification. Site staff must use a passkey to access staff tools. No system is perfectly secure, but we work to protect your information and will notify affected users of a breach as required by law.

Children

Loqva is not for children under 13. We don't knowingly collect information from anyone under 13; if we learn that we have, we'll delete the account. If you believe a child under 13 has an account, email [email protected].

Changes

We'll update this policy when what we collect or how we use it changes, and give notice on the site before significant changes take effect.

Questions? Email [email protected].