Privacy
Holhuashi is built to know as little about you as possible.
No accounts
There's no sign-up, no login, and no user profile anywhere on this site. Posting a message or starting an Ashi doesn't require or create an identity.
What we don't keep
We don't log IP addresses in any database. A hashed, short-lived copy of your IP is kept in a fast, temporary store purely to rate-limit abuse (stop one person from flooding an Ashi), and it expires automatically within minutes. It is never joined to your messages and never reviewable by Ashi moderators.
If an Ashi requires approval, a message you post is held privately until the moderator approves or rejects it. A rejected message is deleted outright, not just hidden; nothing about it is kept.
Moderation keys
When you create an Ashi, you get a one-time secret key so you can moderate it later. We only ever store a one-way hash of that key, never the key itself. If you lose it, we can't recover it, and neither can anyone who gets access to our database.
School verification
Starting a school Ashi means proving you have an email address at that school, since school boards aren't anonymous the way everything else here is at creation time. We send a one-time code to the address you give us, through Resend, a transactional email provider (see Resend's privacy policy). The email and code are held only in a short-lived store that expires automatically within minutes, and are deleted the moment the code is used or expires -- neither is ever written to our database.
What we do keep permanently is the domain half of that email (the part after the @), tied to the Ashi it verified, so a second school Ashi can't be created for the same school. We never keep the full email address, and there's no way to reverse this yourself -- if a school's Ashi is abandoned or was a mistake, contact us.
Reporting
When you report a message, your browser generates a random code and remembers it -- it isn't derived from your device, browser, or IP in any way, and it isn't a "fingerprint." We store a one-way hash of that code against the report so the same browser can't report the same message twice. We can't work out who you are from it, and we don't try to.
Bot protection
Posting runs through Cloudflare Turnstile to slow down automated abuse. Turnstile's own privacy practices apply to that check; see Cloudflare's privacy policy.
Questions
If something here is unclear or you think we're keeping more than we say, tell us.