Help and safety

Trust and safety

Privacy policy

Last updated September 15, 2026

Who operates afterthat

afterthat is operated by SECUNDUS LLC, a Florida limited liability company doing business as afterthat, which is responsible for the information described in this policy. The contact for privacy and support questions is help@afterthat.chat.

Information we collect

We collect information needed to sign you in, show the rooms you joined, and keep those rooms working:

  • Your email address, display name, bio, profile links, and profile images you upload.
  • Your organization, series, event, organizer, and member relationships, including event-specific and series-specific profile choices.
  • Event and series information that organizers create, such as names, descriptions, locations, dates, and time zones, plus organization and event images.
  • Messages, attached images, and related timestamps in event rooms, series rooms, and DMs. Messages are not end-to-end encrypted.
  • Your own directed block choices and the shared-room or DM display-name snapshot shown in your private blocked-people list. Incoming block choices are not shown to you.
  • Authentication and security information: a hashed magic-link token that expires after 15 minutes, a session record that can last up to 30 days, short-lived hashed embedded-chat handoff codes and grants, sign-in challenge results, and rate-limit counters. Raw magic-link, embedded-chat code, and grant values are not stored.
  • Product-email choices and, when you opt out, a minimal HMAC-derived address-and-category suppression marker. It contains no raw email address or user ID and lets us honor that choice if you later create or delete an account.
  • Information you include when you contact support or report abuse, such as a room link and your description of the issue.
  • When operational analytics are enabled, a pseudonymous account identifier and a small set of successful actions, broad page areas, browser details, and sanitized application failures. We do not send message or profile text, email addresses, invitation codes, room identifiers, form values, or full page addresses to analytics.

An invitation can show the event name, description, location, time, and organization or event images before someone joins. Room members can see the messages and member profiles for rooms they can access. We do not use a known invitation link to make a member profile public outside that access.

An event organizer can approve an exact website origin to display that event's chat in an iframe. You still sign in on afterthat and explicitly connect or join. The approved website does not receive your afterthat session, chat grant, account details, member list, messages, or uploaded images. The frame can send that website only a bounded readiness or height update so it can be displayed correctly.

Uploaded images

Profile photos follow your profile choices for each room. When you use a separate event or series profile, that room shows its photo or initials instead of your base-profile photo. An invitation does not make member photos public. Organization and event images can appear on their invitations.

We process uploaded images into a supported format and remove embedded source metadata, such as camera and location tags. Removing or replacing an image stops new access to the old image through afterthat; deletion from storage follows through cleanup. Account deletion removes access to your profile photos. Organization and event images remain community content even if the person who uploaded them deletes their account. Sent message images remain with conversation history after account deletion and are visible only to people who can access that conversation. Removing the message stops new access to its image. Copies that other people already downloaded are outside these controls.

How we use information

  • To send a requested sign-in link and maintain your signed-in session.
  • To create and display organizations, series, events, memberships, profiles, messages, and consensual DMs.
  • To apply member controls, message removal, organizer moderation, bans, and account deletion.
  • To rate-limit requests, protect the service from abuse, investigate reports, troubleshoot failures, and provide support.
  • To comply with legal obligations and protect the rights and safety of members, organizers, and the service.

We use privacy-limited operational analytics to understand broad usage, improve important journeys, and diagnose application failures. Automatic click and form capture, session replay, advertising profiles, precise location, and analytics cookies are disabled. Server events use a one-way pseudonymous account identifier and ask PostHog not to create person profiles.

Service providers

We use the following providers to run afterthat. They may process information on our behalf for the purposes below and under their own terms and privacy policies.

  • Netlify hosting and delivering the application.
  • Neon hosting the application database.
  • Resend sending sign-in email.
  • Cloudflare the Turnstile sign-in challenge, DNS, private image storage, and realtime chat update signals when enabled.
  • Zoho Mail receiving and answering support email.
  • PostHog privacy-limited product analytics and application error monitoring when enabled.

When realtime chat delivery is enabled, Cloudflare processes connection metadata, opaque room and subscription identifiers, and content-free update signals. Message text and images are not sent through this realtime broker; your browser retrieves conversation content from afterthat after an access check.

We may also disclose information when required by law, to respond to a valid legal process, or to protect members and the service from fraud, abuse, or a serious safety threat.

Cookies and similar technology

afterthat itself uses one first-party HttpOnly session cookie to keep you signed in. It uses SameSite protection and expires after up to 30 days. The Cloudflare Turnstile sign-in challenge is a separate provider service and may process device or network signals under Cloudflare’s policy. PostHog is configured with in-memory browser state rather than analytics cookies or persistent browser storage. We do not use advertising trackers.

Message drafts are stored on your device in local browser storage, separated by your account and room. Draft text is sent to the service only when you submit it, is cleared after a successful send, and may remain available for the current browser session if device storage is unavailable.

Retention, removal, and account deletion

Magic-link tokens expire after 15 minutes. Sessions last up to 30 days. Rate-limit records are kept for their operating windows and cleanup. Messages you post are retained indefinitely, including after account deletion under “Deleted member,” unless you or an authorized organizer removes the message, or the organizer deletes a one-off event room under the service controls. A removed message is cleared and shown to participants as “Message removed,” while a durable change record keeps the removal synchronized.

Organizer moderation notes and action records are retained as private community safety records for the organization where the action occurred. Account deletion replaces copied actor and target profile labels in those records with “Deleted member,” while retaining the note and action history.

Member reports retain the original organization, room and optional message reference, reporter and reported-account identifiers, room-profile label snapshots, the selected reason, any note, and the private resolution record. We do not copy a reported message's text into the report. A message reported by three different current room members is hidden from every reader, including its author, until it is restored; its text stays stored and a restore records who restored it. These safety records remain with the original organization if a room moves or is deleted. Account deletion replaces copied reporter, reported-person, and resolver labels with “Deleted member,” while retaining report notes and the stable identifiers needed to keep the reported person from seeing the record.

For product email, we store only a cryptographic hash of an unsubscribe credential. An unused link continues to work until it is revoked or replaced when you turn that category back on. Account deletion removes associated unsubscribe credentials, but we retain a minimal address-and-category HMAC marker to honor your opt-out. That marker contains no raw email address or user ID. Explicitly turning the category back on clears the opt-out. Provider copies may have their own retention under the provider's policy.

You can delete your account at /settings/delete after the required recent sign-in confirmation. Deletion removes your private profile details, memberships, organizer roles, sessions, and sign-in access. Your retained account row is labeled “Deleted member” so existing messages and DM history keep a valid author reference. The text of messages you wrote is not deleted or anonymized and may still contain personal information.

Deletion blocks your DMs, removes block-list rows involving your account, and the other participant keeps the conversation history. If you were the sole organizer, your organization closes and future or undated events are canceled; existing conversations remain available to their existing members. An organization with another organizer stays active. A later sign-up creates a new account and does not restore the deleted account’s access or history. Backups may retain earlier copies until their normal expiry.

Your choices and rights

  • Correct your base profile in Settings. You can separately edit your profile for an event or series from that room. Each uses your current base profile until you customize it.
  • Review and remove your own directed blocks from the Blocked people page in Settings. Removing a block does not reopen an old DM.
  • Request access to or an export of your information by emailing help@afterthat.chat. Self-service export is not available yet.
  • Delete your account from Settings, subject to the confirmation described above.
  • Ask questions or raise a privacy concern by email. We may ask for information needed to verify a request before responding.

Depending on where you live, you may have additional privacy or consumer rights. Nothing in this policy limits rights or protections that the law requires us to provide.

Children and international processing

afterthat is for adults 18 and over. Do not use the service if you are under 18. If you believe a person under 18 has provided information, contact help@afterthat.chat so we can review the situation.

Our providers may process information in the United States or other countries where they operate. Their policies describe their handling of international transfers and safeguards. We use the providers listed above only for the service purposes described here.

Security and changes

We use access controls, expiring hashed sign-in tokens, HttpOnly sessions, rate limits, and transaction checks to protect the service. No online service can promise absolute security, so protect your email account and do not forward sign-in links.

We may update this policy when the service or its practices change. We will update the date above and describe material changes on this page. Continued use after an updated policy takes effect means the updated policy applies to future use, subject to any rights the law gives you.

Material changes on September 15, 2026: SECUNDUS LLC now operates afterthat and is responsible for this information in place of Nicholas Underwood personally. Signing in now includes confirming that you are 18 or older and agree to the Terms and this policy. What we collect and how we use it are unchanged.