PRIVACY

Privacy policy

Last updated: 28 July 2026.

What this website collects

Nureiq does not use advertising trackers or third-party analytics cookies. If you create a profile, Nureiq stores your email, username, display name, password hash, profile settings, profile picture and banner, portfolio content, follows, blocks, badge awards, messages you choose to send, and the version and time of your Terms and Privacy acceptance. Security records also retain the action, outcome and time of important authentication, recovery, safety and owner events. Source addresses and submitted login identifiers are replaced with keyed fingerprints instead of being stored in plaintext. Your email address and private security details are never shown on your public profile; a generic email-verified indicator may be shown after verification.

Why it is used

Account data operates your profile, portfolio, follows, safety controls and direct messages. Private reports are available to the owner for community safety. Nureiq rejects obvious passwords, API keys, tokens and recovery codes in public profile content and messages; never submit those secrets anywhere on the site.

Retention

Your account data remains while your profile exists. Deleting your account removes it from the live service immediately. Application rollback snapshots are retained for up to 14 days, owner-only same-VPS operational backups for up to 7 days, and separately encrypted off-VPS backups for up to 30 days. Sensitive fields remain application-encrypted in operational snapshots. Deleted data can remain in those protected backups until they expire. Security events are retained for up to 90 days with a 5,000-event cap. Expired sessions are removed automatically. Technical rate-limiting records are temporary and held only in memory.

Account security

Passwords are stored as salted scrypt hashes, not readable passwords. Emails, direct-message bodies, private report details and authenticator secrets are encrypted at rest with an application key stored separately from the data volume. Login cookies are HTTP-only, secure and strict same-site. Standard sign-ins use a non-persistent browser cookie. If you explicitly choose “Keep me signed in” on a private device, the cookie can persist for up to 30 days and the server ends it after 7 days of inactivity. Sessions always have idle and absolute time limits, and raw session tokens are never stored. Optional authenticator-app verification and one-use backup codes are available in Security settings.

Nureiq uses Resend to deliver email-verification and password-reset messages. Resend receives the destination email address and message contents only when Nureiq sends one of those transactional emails. Verification and reset tokens are random, stored only as hashes and expire automatically.

A long one-time recovery code remains a separate break-glass proof of account ownership. Store it in a password manager. Using it changes the password, replaces the code, signs out existing sessions and disables authenticator verification so a lost authenticator cannot permanently lock the account.

Profiles, links and direct messages

Profiles, approved profile pictures, approved banners, portfolio work, profile apps, follower lists and badges are public. A linked Discord account stays hidden by default and appears only when its owner enables public Discord visibility; this shows that a Discord sign-in is connected, not the private Discord identifier or email address. Uploaded profile pictures and banners are cropped, re-encoded as WebP to remove embedded metadata, and held privately for owner safety review before publication; rejected or withdrawn pending images are removed from the live service. Profile apps are validated external HTTPS links and do not give Nureiq access to those services. Direct-message text is encrypted at rest, but messages are not end-to-end encrypted: the service decrypts them for participants and the owner may review relevant content when investigating a safety report. Messages accept only standard English letters A–Z, numbers 0–9, spaces and new lines. Read timestamps are stored with messages; typing indicators are temporary and expire after a few seconds. Do not use DMs to send passwords, recovery codes, financial details or other secrets.

Online status is optional. While a signed-in member has Nureiq open, the browser sends a temporary heartbeat that can display only Online or Offline on member surfaces. Exact activity times are never shown, the heartbeat is held only in memory, and Online expires after about two minutes without activity. Members can hide this status in Privacy settings.

Message notifications are optional and enabled separately on each device. Nureiq stores the device's push subscription encrypted at rest and sends a generic alert through the browser or operating system push service. Notification payloads do not contain the private message text. You can remove a device subscription from Notification settings or through your browser settings.

The Nureiq Discord bot

The bot processes questions submitted through its slash commands. Mentions, replies and ordinary Discord messages are ignored, and the bot does not request the Message Content gateway intent. Approved FAQs and server knowledge are handled locally where possible. Paid AI is used only when a slash-command question needs language generation. Ordinary member messages are never accepted as server facts.

Optional member memory is user-controlled, limited and expires. Routing logs avoid storing message text. A shortened question and answer preview may be retained privately for up to 30 days after feedback. Safe conversational replies can be promoted automatically after Helpful votes from two different members and expire after 30 days; a Needs work vote blocks that answer from reuse. Server facts, permissions, moderation, current information, coding, secrets and admin actions never auto-learn from votes.

Third parties

Discord processes activity under its own policies. If you choose Google or Discord sign-in, that provider supplies Nureiq with your verified email, account identifier and basic profile name. Nureiq uses that data only to create or sign in to your account and does not retain provider access tokens. An existing signed-in member can explicitly connect Discord from Security settings after confirming their Nureiq password; Nureiq does not silently link accounts by matching email. Questions that require AI may be sent to OpenAI through Nureiq's private automation workflow using minimized context. The website's server icon is loaded from Discord's content delivery network.

Your choices

You can hide your online status, limit who may message you, block another member, file a private report or delete your website account from Profile settings. Bot memory can be viewed or removed using the bot's memory commands. Website and Discord bot data are separate.

Privacy questions

Use the Nureiq Discord help desk for privacy questions. Never include account credentials, recovery codes or private keys in a request.