Liftedap

Privacy Policy

What we hold about you, why it exists, who else sees it, and how to take it back. Each item below is something the platform genuinely stores — there is no catch-all clause reserving the right to collect more.

In effect since 15 August 2026

01Who is responsible for your data

Liftedap operates this platform and decides what is collected here. Questions, requests and complaints about anything in this document go to [email protected], and are answered by a person within 30 days.

02What you give us

  • Account details — email address, handle, display name, and a password we never store: only a scrypt hash of it, which cannot be turned back into the password you typed.
  • Date of birth — collected because the age floor of 13 and the withholding of age-restricted material from under-18 accounts are enforced on every read, and neither works without it.
  • Profile art — an avatar and a banner, if you add them.
  • Content — videos, live broadcasts and their recordings, thumbnails, titles, descriptions, captions, playlists and comments.
  • Messages you send us — reports, copyright notices, appeals and support email, including whatever you choose to put in them.

03What the platform records as you use it

  • Watch and engagement events — what was played, for how long, likes, follows and subscriptions. These produce your studio analytics and the feed you see.
  • An activity log with an IP address — sign-ins, uploads, reports and other consequential actions. This exists for rate limiting and for investigating abuse, and it is the only place an IP address is kept.
  • Moderation results — the verdict for each upload, comment and broadcast, the category scores behind it, which layer decided, and the timestamps of any flagged frames.
  • Enforcement and support records — strikes, suspensions, and the separate record of occasions when crisis resources were shown to you. The second is recorded as support and is never counted as enforcement.

04Why we hold each of these

To run an account and show you your own library. To decide whether content can be published — which is the platform’s central obligation and the reason moderation results are kept alongside the content rather than discarded after the decision. To keep the service working, by rate limiting and detecting abuse. To meet legal obligations, including responding to copyright notices and to reports of illegal material. And to tell you what happened to your own content, which is what the moderation record on a watch page is for.

We do not sell your data, and we do not build advertising profiles from what you watch.

05Your media is encrypted, and the checks look at frames

Uploads are sliced in your browser and each slice is sealed with AES-256-GCM under a key unique to that video, which is itself wrapped by a master key held separately. Playback decrypts only the slices a request actually covers. Nobody browsing the storage layer sees a playable file.

To check a video before it publishes, your browser samples a small number of still frames and sends those for scoring. Text — titles, descriptions and comments — is checked first by a deterministic rule set that runs locally, and only reaches the AI layer if it needs to.

06Who else receives it

  • Netlify — hosting, the database and the encrypted object storage. Everything the platform keeps lives there.
  • Anthropic, through the Netlify AI Gateway — receives the sampled frames and the text being checked, for the moderation decision. Content is sent for scoring, not for training.
  • Google — if you sign in with Google, the exchange is brokered by Netlify Identity and we receive a verified email address. Separately, Google AdSense serves advertising in these pages and sets its own cookies, under Google’s policies rather than this one.
  • YouTube — the films and rolling broadcasts on the news pages are the newsrooms’ own YouTube uploads. Nothing is requested from YouTube until you press play on one: the poster frame is served through Netlify, and the player is only inserted into the page once you ask for it. From that point YouTube sees the request and sets its own cookies, under Google’s policies rather than this one. News photographs are fetched by Netlify rather than by your browser, so the outlet that published a story does not see you reading the headline.
  • Resend — sends transactional email such as password resets and moderation alerts.
  • Law enforcement — where the law requires it, and in the case of material depicting the sexual exploitation of a minor, where it requires us to report it.

07Cookies

The session cookie is set when you sign in. It is httpOnly, so page scripts cannot read it, and it holds a signed token identifying your account and nothing else. Signing in with Google adds a second cookie issued by Netlify Identity, which proves your address; roles, strikes, suspensions and the age gate are all read from your account row rather than from it.

Advertising cookies are set by Google AdSense. You can manage those through your Google ad settings or your browser. The platform sets no analytics or tracking cookies of its own.

08What is public, and what is not

Public by design: your handle, display name, profile art, the videos you publish and their descriptions, your comments, and your subscriber count.

Never public: your email address, your password hash, your date of birth, your watch history, your IP address, and the moderation record of your own uploads — which only you and the reviewers can see. A held video is invisible to everyone except you and staff. It is not deleted and it is not announced.

09How long it is kept

Content and account data stay until you remove them. Moderation results, strikes and the activity log outlive the individual video, because they are the evidence for decisions that can be appealed and the basis on which repeat violations are counted.

When you delete your account, the encrypted media is deleted from storage, and comments, likes, follows, watch events and reports are deleted with it. Moderation records are detached from you rather than destroyed: the reviewer’s decision survives, the person in it does not, and the IP addresses in your activity log are cleared.

10Your rights, and the two buttons

You can export everything and you can erase everything, without asking us first. Both are in Settings: Download my data produces a JSON file containing your account record, uploads, comments, likes, follows and watch history, and Delete account does what clause 9 describes.

You also have the right to correct what is wrong, to object to a particular use, and to complain to your data protection authority. For anything the buttons do not cover — a correction, a restriction, or a copy in a different form — write to [email protected].

11Children

Accounts require an age of at least 13. We do not knowingly collect anything from anyone younger, and an account we learn belongs to someone younger is closed and its data removed. If you believe a child has an account here, tell us at [email protected] and it will be looked at the same day.

12Where your data is processed, and changes to this policy

The platform runs on infrastructure that may process data outside your country, including in the United States, under the safeguards those providers offer for international transfers.

When this policy changes the date at the top changes with it, and a material change is announced before it takes effect. Anything you disagree with is a reason to write to [email protected] — including to tell us the description here does not match what you observed.