Scope and who is responsible
This Privacy Policy explains how TeichAI (“Teich,” “we,” “us,” or “our”) collects, uses, discloses, and retains personal information when you visit or use Teich Forum, join its waitlist, create an account, communicate with community members, submit a report, or interact with related forum features (collectively, the “Service”).
TeichAI is responsible for the forum-specific processing described here. Some companies that support the Service also process information under their own terms and privacy notices, particularly Clerk for identity and account management, GitHub or Hugging Face if you choose social sign-in, UploadThing if forum image uploads are enabled, and our hosting and infrastructure providers.
This Policy does not govern third-party websites, repositories, model hosts, datasets, or services linked from forum posts or other TeichAI projects with their own notices. It also does not cover information processed solely in an employment or contractor relationship.
Information we collect
Information you provide
- Account and identity information: email address, username, display name, profile photo, authentication method, and, when requested by our identity provider, first and last name, password, verification status, or multifactor settings. The forum application does not store your password; Clerk processes authentication credentials.
- Profile information: biography, public-facing name, avatar, role, account status, and account preferences.
- Community content: threads, replies, tags, mentions, edits, upvotes, dislikes, bookmarks, follows, blocks, and the time associated with those actions.
- Communications: Teich Mail, waitlist submissions, account and support communications, and information you send when contacting us.
- Safety and moderation information: reports, reasons, supporting details, appeals, staff notes, case assignments, enforcement actions, suspension details, and related records.
- Files and media: images you upload to posts, replies, Mail drafts, Mail entries, or your account, together with file name, size, storage key, URL, owner, and upload time.
Information collected automatically
- Technical and device data: IP address, browser and device type, operating system, referring page, request time, pages or routes requested, and diagnostic or security events. The forum’s rate limiter converts a signed-out visitor’s IP address into a one-way keyed hash and does not persist or log the raw IP in the forum database; infrastructure providers may still process IP addresses in ordinary network and security logs.
- Session and security data: cookies or similar identifiers, session status, authentication events, bot-detection signals, and rate-limit bucket data used to keep accounts and the Service secure.
- Usage data: content views, notification state, Mail read and folder state, feature interactions, timestamps, and records needed to deliver requested actions. Discussion view counts may be stored in aggregate with the discussion.
Information from others
We receive account and authentication data from Clerk; profile or account data from GitHub or Hugging Face when you choose that provider for sign-in; upload metadata from UploadThing; information about you that other users include in posts, Mail, mentions, or reports; and security or diagnostic information from infrastructure providers. The data received from a social provider depends on your settings and the permissions shown during connection.
Sensitive information and what not to post
Private Mail, account credentials handled by Clerk, precise report details, and some User Content may be considered sensitive under certain laws. Teich Forum is not designed to collect government identification numbers, financial account credentials, health records, precise location, biometric templates, or other regulated sensitive data.
Please do not post secrets, private keys, passwords, verification codes, confidential datasets, government identifiers, payment-card data, medical records, or another person’s sensitive information. If you voluntarily place personal or sensitive information in a public profile or post, it becomes public and may be copied or used by others outside our control.
How we use information
We use personal information to:
- create, authenticate, secure, and maintain accounts and waitlist entries;
- display profiles and community content and deliver threads, replies, reactions, follows, bookmarks, Mail, mentions, and notifications;
- store and serve uploads, synchronize account changes, and provide settings and account-deletion controls;
- personalize basic forum state, such as whether content is saved, upvoted, disliked, read, or available to your role;
- detect spam, fraud, abuse, attacks, policy evasion, and unauthorized access; enforce rate limits and access controls; and investigate security incidents;
- receive and investigate reports, document moderation decisions, enforce the Terms of Service, and protect users, Teich, and the public;
- operate, debug, maintain, measure, and improve the Service and develop new features;
- communicate about verification, invitations, security, service changes, moderation, support, and legal notices;
- comply with law, respond to lawful requests, establish or defend legal claims, and enforce agreements; and
- create aggregated or de-identified information that cannot reasonably identify an individual, which we may use for legitimate purposes.
We do not use private Mail or forum content to train general-purpose artificial-intelligence models. If that practice changes, we will update this Policy and provide any notice or choice required by law before the new use begins.
Legal bases for processing
If a law requires us to identify a legal basis, we rely on one or more of the following:
- Contract: processing needed to provide the Service you request and administer our Terms of Service, such as maintaining an account or delivering Mail.
- Legitimate interests: operating and improving the community; securing systems; preventing abuse; moderating content; understanding performance; communicating with users; and protecting legal rights. We consider the impact on your rights before relying on this basis.
- Consent: when you make an optional choice that legally requires consent, such as connecting an optional service or receiving a type of communication that requires opt-in. You may withdraw consent prospectively.
- Legal obligation: complying with applicable law, lawful requests, recordkeeping duties, and valid legal process.
- Vital or public interests: in rare cases, protecting someone’s life, safety, or other vital interests, or performing a task recognized in law.
What is public and what is limited-access
Member directory and public attribution profiles: the searchable member directory is available only to active signed-in members. Individual profiles remain publicly reachable when linked from a public discussion so readers can understand authorship. Public profiles show display name, username, avatar, biography, role, and public discussions; signed-out visitors do not see join month or follower and following counts. Profile pages ask search engines not to index them, but links may still be followed.
Public discussion attribution means people may still enumerate authors who have posted publicly by following profile links from those discussions. This residual risk is accepted so public contributions retain meaningful authorship. Public pages and information can still be cached, archived, quoted, or copied by users and services outside Teich’s control.
Account-limited information includes bookmarks, blocks, account settings, email address, sessions, and authentication details. Access is limited to you, authorized staff, and service providers as necessary for their functions. Administrators may have broader access than moderators where needed for account administration.
Teich Mail is visible to the two thread participants and is not end-to-end encrypted. Staff BCC sends independent one-to-one threads; recipients do not see one another. Authorized staff may access limited context around a Mail entry when it is reported, reasonably needed for safety, abuse prevention, support, or system integrity, or required by law. Recipients can save or share Mail, so do not treat it as a secure channel.
Reports and moderation records are limited to authorized staff and relevant providers. A person affected by a report may receive enough information to understand and appeal an action, but we generally do not disclose a reporter’s identity unless necessary for fairness, safety, law, or with the reporter’s permission.
How we disclose information
We may disclose personal information in these circumstances:
- To other users and the public: according to the feature you use and the visibility described above.
- To service providers: companies that provide identity, hosting, database, storage, uploads, email delivery, security, error monitoring, and technical support. They receive information needed to perform services for us and are expected to protect it.
- At your direction: when you connect a third-party account, follow an external link, post an externally hosted image, or otherwise ask us to interact with another service.
- For safety and legal reasons: when we reasonably believe disclosure is necessary to comply with law or valid process; investigate violations; detect or prevent fraud, abuse, or security threats; protect rights, property, or safety; or establish, exercise, or defend legal claims.
- During an organizational change: in connection with financing, due diligence, a merger, acquisition, reorganization, asset transfer, or similar transaction, subject to appropriate confidentiality and any notice required by law.
- With consent: for another purpose that we clearly describe and you authorize.
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising, and we do not use third-party advertising cookies. We also do not disclose personal information to data brokers. If those practices change, we will update this Policy and provide legally required choices before beginning them.
Service providers and external content
- Clerk provides account registration, sign-in, sessions, verification, bot protection, profile images, waitlist or invitation workflows, and connected-account management. Clerk may set cookies and process identifiers, credentials, device, security, and account data.
- GitHub processes information if you choose GitHub social sign-in or visit a linked repository. The permissions screen controls information shared for sign-in.
- Hugging Face processes information if you choose Hugging Face social sign-in or visit linked models, datasets, or Spaces. The permissions screen controls information shared for sign-in.
- UploadThing processes uploaded forum images and related file metadata when uploads are enabled. Images may be delivered from UploadThing-controlled domains.
- Infrastructure providers host the application, database, network, and related systems and may process request metadata and logs to deliver and secure them.
Posts can include links or images hosted by unrelated third parties. When your browser loads external content, the third party may receive your IP address, browser information, and the page or resource requested and may set its own cookies. Teich does not control those practices. Use caution before opening external links or media.
Emails and notifications
We or Clerk may send service communications such as verification codes, invitations, password or account notices, security alerts, moderation updates, and important policy or service changes. These transactional or relationship messages are part of providing and protecting the Service and may not have a marketing unsubscribe option.
In-product notifications may be generated by replies, mentions, upvotes, follows, and moderation actions. Dislikes do not generate notifications. Mail has a separate unread-thread count. You may mark notifications and Mail as read and can stop some interactions by blocking another member. If we introduce optional promotional email, we will provide any consent and unsubscribe controls required by law.
Retention and account deletion
We retain personal information only for as long as reasonably necessary for the purposes described here, including providing the Service, preserving community context, resolving disputes, enforcing rules, maintaining security and audit history, and meeting legal obligations. The period depends on the data, its sensitivity, the feature, user expectations, risk, and legal requirements.
- Account data is generally retained while the account is active. When you delete your account, Clerk deletes or deactivates identity data according to its processes, and the forum marks the local account deleted and clears its stored email address.
- Public profile and attribution data such as local user ID, username, display name, and avatar URL may remain after account deletion to preserve authorship, integrity, safety, and moderation history. The public member profile becomes unavailable, but previously published contributions may remain visible unless removed separately.
- Threads and replies remain until you delete them, staff removes them, or they are no longer needed. Deleted or hidden content may remain available to authorized staff for moderation, appeals, safety, and audit purposes.
- Teich Mail may remain for thread participants and for safety, integrity, and legal purposes after account deletion. Removing your mailbox copy does not recall the other participant’s copy.
- Reports, staff notes, moderation actions, and security records may be retained after content or account deletion so we can document decisions, detect repeat abuse, resolve appeals, and protect the Service and community.
- Uploads may remain while associated content or records are retained. Unused drafts and orphaned files may be deleted as part of maintenance, but you should not use draft storage as a permanent archive.
- Rate-limit, request, and diagnostic records are kept for the duration needed to enforce limits, investigate failures or abuse, and secure infrastructure. Provider logs and backups expire according to operational schedules and may persist temporarily after deletion from live systems.
To reduce retained public content, delete individual threads or replies using available controls before deleting your account. We may retain information longer when required by law, subject to a preservation request, or necessary for legal claims, fraud prevention, safety, or enforcing agreements. We may retain aggregated or de-identified data that can no longer reasonably identify you.
Security
We use administrative, technical, and organizational safeguards designed for the nature of the Service, such as managed authentication, signed sessions, role-based access controls, reverification for sensitive account actions, input validation, content sanitization, upload restrictions, rate limiting, webhook signature verification, and limited staff permissions.
No internet service or storage method is perfectly secure. We cannot guarantee that information will never be accessed, lost, altered, or disclosed improperly. Protect your password and verification methods, use multifactor authentication where available, sign out on shared devices, and tell us promptly about suspected compromise. Do not send vulnerability details through a public forum post; request a private reporting channel.
International data transfers
Teich, its contributors, and its providers may process information in the United States and other countries where they operate. Those countries may have privacy laws different from the laws where you live.
Where required, we use recognized transfer mechanisms and safeguards, such as adequacy decisions, contractual protections, or provider terms incorporating standard contractual clauses. You may contact us for information about safeguards relevant to your information, subject to necessary confidentiality protections.
Your choices and privacy rights
Depending on where you live and subject to legal exceptions, you may have the right to:
- know whether we process your personal information and access or receive a copy of it;
- correct inaccurate personal information;
- delete personal information;
- restrict or object to certain processing;
- receive portable data you provided in a structured format;
- withdraw consent without affecting earlier lawful processing;
- opt out of sale, targeted advertising, or certain profiling, if those practices apply;
- appeal a refusal of a privacy request where applicable; and
- complain to your local privacy or data-protection authority.
You can update profile and account information, manage security methods, remove some content, and delete your account through the Service’s settings. For other requests, send Teich Mail to an administrator or moderator with the subject “Privacy Request.” Describe the request and the account involved, but do not send a password or verification code.
We may need to verify your identity or authority before acting. An authorized agent may submit a request where law permits, but we may request proof of authorization and direct identity confirmation. We will respond within the period required by applicable law. A right may be limited when information must be retained for security, legal compliance, free expression, the rights of others, or another lawful exception. We will not unlawfully discriminate against you for exercising a privacy right.
United States state privacy disclosures
This section supplements the rest of the Policy for residents of U.S. states with comprehensive privacy laws. Whether a particular law applies to Teich depends on its scope and thresholds. The table summarizes categories of personal information we have collected through the Service, their sources, and the business purposes for which they may be disclosed.
| Category | Examples | Sources and purposes |
|---|---|---|
| Identifiers | Email, username, display name, account IDs, IP or hashed rate-limit subject | You, Clerk, GitHub, Hugging Face, devices; account access, community features, security |
| Customer-record information | Name, account and contact information | You and identity providers; account administration and support |
| Internet or network activity | Sessions, requests, views, interactions, security and diagnostic events | Devices and providers; service delivery, measurement, debugging, safety |
| General geolocation | Approximate region inferred from IP by infrastructure providers | Network requests; security, routing, and legal compliance |
| Audio, electronic, or visual information | Profile photos and uploaded images; Mail and posts | You and other users; profiles, content, communication, moderation |
| Professional or educational information | Details you choose to place in a profile, post, or Mail entry | You and other users; community discussion and networking |
| Inferences | Spam, abuse, trust, or moderation signals based on activity | Service activity; security, integrity, and policy enforcement |
| Sensitive information | Account credentials handled by Clerk, Mail contents, or report details where legally classified as sensitive | You, Clerk, and other users; authentication, communication, safety |
We disclose these categories as needed to the recipients described in How we disclose information, including other users for public content and service providers for operational purposes. We do not sell these categories or share them for cross-context behavioral advertising. We do not knowingly sell or share the personal information of people under 16. We do not offer financial incentives for personal information.
Where applicable, state residents can request access, correction, deletion, or portability and can appeal a denied request by replying to the decision. Because we do not currently sell personal information, use it for targeted advertising, or conduct legally covered profiling for significant decisions, there is no separate opt-out flow for those practices.
Children’s privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. People under 13 may not create an account or submit information to the Service. If local law requires a higher minimum age for a young person to consent independently, that person may use the Service only with legally valid parent or guardian involvement.
If you believe a child has provided personal information in violation of this section, contact a Teich administrator or moderator through Teich Mail with enough information for us to identify the account or content. We will investigate and delete or otherwise handle the information as required by law.
Information about other people
If you post or send information about another person, you are responsible for having a lawful basis and any permission required to do so. Do not publish private contact information, credentials, intimate material, confidential records, or sensitive personal information about someone else.
If another user has posted your information, use the report control or contact us with the exact location, the nature of the concern, and information needed to evaluate your request. We balance privacy requests with free-expression, public-interest, safety, recordkeeping, and legal obligations.
Changes and contact
We may update this Policy to reflect changes in the Service, providers, or law. We will change the “Last updated” date and, if changes are material, provide additional notice reasonably suited to the change, such as a prominent notice or account communication. Where required, we will request consent before applying a new practice to previously collected information.
For privacy questions, rights requests, or general legal questions, send Teich Mail to an administrator or moderator. Visit your Teich Mail to continue an existing thread. To start one, open a Teich staff member’s profile and choose Mail. Use the subject “Privacy Request,” and do not place sensitive personal information in a public post or report.
If you are in the European Economic Area, United Kingdom, or Switzerland, you may also lodge a complaint with the data-protection authority where you live, work, or believe a violation occurred. We encourage you to contact us first so we have an opportunity to address the concern.
Review the related terms of service or return to the forum.