We're finalizing our policies. This reflects our current practices and may be updated.
Privacy Notice
Summary
GhostedByVC is pseudonymous by design. GhostedByVC collects no email, no real name, and no profile, for posters or for readers. There is no personal data tied to an account except an optional contact handle a member chooses to publish (see Contact handle below). Reading is fully public and requires no account.
What we collect
If you only read (no account)
Reading the feed, fund pages, and posts requires no account and no login.
- No analytics or third-party tracking SDKs. The product is built with no fingerprinting trackers and no third-party analytics.
- Rate-limiting only. To defend against abuse and bots, requests are rate-limited. Rate limits are keyed by a salted one-way hash of your IP address, stored only in a short-lived cache for counting requests. The raw IP is never stored in our database and is never linked to any post or content, and the hash cannot be reversed to your IP without a secret key.
- Bot defense and the hosting platform may process request metadata to block automated abuse.
If you have an account (to post, vote, or report)
To act, you redeem an invite code and choose a username and password. GhostedByVC then holds:
- Username — a pseudonym you choose. This is the only identity on the site. Using a real name is discouraged; posts are shown under this handle.
- Password — stored only as an argon2id hash. The raw password is never stored and cannot be recovered. Because there is no email, there is no password reset: a lost password means a lost account.
- Your content — the posts you write (title, story, and the structured fields: stage, outcome, rough timeline) and your upvotes.
- Optional profile tags (founder stage + city) — entirely optional and self-declared (not verified). You can skip them, and you can later hide them. Your founder stage and a coarse city region can be shown publicly; they are automatically masked (k-anonymity) when too few other founders share the same combination, so the tags can't single you out. Your raw city entry is stored but shown only to you — only the coarse region (e.g. "Bangalore") is ever public. You may also attach a per-post credential (e.g. "a Seed-stage founder"); that, too, is optional and masked the same way.
- Invite linkage — which invite code you redeemed and which you've minted, for abuse forensics. This links to other accounts only, never to a real identity.
- Session — when you log in, a cookie holds a random token; only a keyed hash of it is stored server-side, never the raw value. The cookie is
HttpOnly,Secure, andSameSite=Lax. - Personal access tokens (optional) — if you create a token (for example, for an AI agent to act as you within granted scopes), only a keyed hash of it is stored, never the raw token.
- Reports you file are visible to admins only; your identity as a reporter is never disclosed.
What we explicitly do NOT collect
- No email address.
- No real name, phone number, or postal address (other than an opt-in contact handle a member may choose to publish themselves — see Contact handle).
- No profile bio, photo, or avatar. A public profile page lists the posts you made under your handle, a coarse, approximate contribution score, and — only if the member opts in — a contact handle they choose to publish (see Contact handle below). Posts may include image attachments and link previews you choose to add; any image you upload is re-encoded server-side, which strips its embedded metadata (e.g. EXIF/GPS) before it is stored.
- No raw IP stored with your content, ever — only the salted, short-lived, cache-only hash described above, used purely for rate-limiting.
- No third-party advertising, analytics trackers, or fingerprinting.
How the pseudonymity model limits privacy risk
- Because little personal data is held, a database breach exposes no email, no real name, and no raw IP — with one exception: a contact handle a member opted into publishing IS stored, and a breach would expose it (the single field a member can choose that reduces their own anonymity — see Contact handle).
- Credentials are useless if leaked: passwords are argon2id-hashed, and session and access tokens are stored only as keyed hashes (keyed by a secret that lives outside the database), so a database dump alone yields no usable login.
- Rate-limit IP hashes are salted, short-lived, cache-only, and never joined to posts, so content cannot be mapped back to an IP.
- One limitation: a persistent handle is linkable, and tags can compound it. Posting under a stable username means all posts can be tied to each other. For a founder naming VCs, that pattern can be collectively identifying even though no real-name data is held. Everything under a handle is public. Writing style, specifics, and timing can each narrow down who someone is. In particular, your founder stage, your city, and the funds you post about can together narrow down who you are — which is exactly why the stage and city tags are automatically masked (k-anonymity) when too few founders match, and why the tags are optional and default-skippable. GhostedByVC collects no personal data that ties a handle to a real identity except an opt-in contact handle a member chooses to publish (see Contact handle), and cannot make a public, persistent handle unlinkable.
- External links in posts are marked
noopener noreferrer nofollow, and the site sendsReferrer-Policy: no-referrer, so clicking out doesn't leak which GhostedByVC page you came from. - A private channel is itself a de-anonymization vector. Because a direct-message conversation lets one member press another for identifying details, a member's private channel could be used for social engineering. We mitigate this structurally: receiving DMs is off by default (you opt in), a contribution-history floor gates who can start a conversation, a monthly cap limits how many new conversations any one member can open, and block and report are always available. See Direct messages below.
Direct messages
GhostedByVC has an optional, in-app direct-message feature. It is built to the same pseudonymity standard as the rest of the site:
- Pseudonymous — DMs are handle-to-handle. No internal IDs, emails, or real names are attached to a message or revealed to the other party.
- Web-session only — DMs can be sent and read only from a logged-in browser session. Automated agents / API tokens (PATs) can never send or read DMs.
- Opt-in to receive — your inbox is closed by default. You choose to open it; turning the feature on for the site opens no one's inbox.
- Ephemeral — messages are deleted after 30 days by a daily server sweep. There is no archive.
- Sanitized — DMs follow the same content rules as posts: no images, and any links are marked
nofollow. Message text is never executed as code. - Admins see only reported content — if you report a message, an admin sees a snapshot of that one reported message (kept so the evidence survives the 30-day sweep). Admins never browse your inbox or any un-reported conversation.
- Never indexed, never cached — DMs are kept off every public, crawlable, or cached surface. They never appear in search engines, the sitemap, or any shared cache.
- Block + report — you can block a member (which hides the conversation and stops further messages in both directions) or report a specific message to the moderators.
Contact handle
GhostedByVC has an optional contact handle — a Telegram, Signal, or other handle a member may publish on their own profile so other logged-in members can reach them off-platform. It is the single field a member can choose that reduces their own anonymity, so it ships with the strongest warnings in this notice:
- Opt-in and member-chosen. Nothing is inferred or pre-filled. You add it yourself, after an explicit warning, and you choose whether to publish it.
- Stored in our database — a breach would expose it. Unlike the rest of the site, this handle is stored in our database (it is not transient and not secret). It is the one field whose leak would link your pseudonym toward a real-world identity. Add it only if you accept that.
- Member-visible only. Anonymous readers, search engines, and automated agents (API tokens / MCP) never see it. Only a logged-in member can reveal it, and only by clicking — it is never in the page source, the sitemap, or any social-card metadata.
- Reversible. You can remove it at any time; removal deletes the stored value.
- Your OWN handle only. You may publish a way to reach you; posting anyone else's private contact details — another member's or a VC's — remains prohibited (see our Content Policy).
Public content
Posts are public — anyone on the internet can read them, and search engines may index them. Your chosen username is shown with your posts. The internal author ID is never exposed. Individual names inside posts are hidden ("a partner") unless an admin explicitly reveals them (see our Content Policy).
- Public profile pages. Each handle has a public page at
/u/<handle>that anyone can read (no account needed). It collects every post you made under that handle in one place, alongside an approximate contribution score and a coarse account-age band — never an exact value. If the member opts in, the page also offers a contact handle they chose to publish, revealable only by a logged-in member (see Contact handle). These pages are excluded from search-engine indexing (noindex), but are reachable by anyone with the link. Because a profile gathers all of a handle's posts together, it can make the linkability described above easier to act on. - Profile tags (stage + city). If you add them, your founder stage and a coarse city region appear on your profile, automatically masked (k-anonymity) when too few founders match so they can't single you out; you can opt them down to self-only or hidden. Naming a person in a post still routes to human review (unchanged) — there is no compelled relationship assertion, and no structured per-fund relationship tag.
- Opt-in leaderboard. There is a public ranked leaderboard that lists contributors only if they explicitly opt in (off by default). It shows your rank, your handle, and an approximate, rounded contribution score — your exact score is private and shown only to you on your own profile. Rank order and changes over time may be correlatable to your posting; the opt-in prompt warns you before you join, and you can opt back out at any time. The operator and system accounts never appear. The leaderboard is
noindexbut link-reachable.
Data retention
- Posts and accounts persist until removed or banned through moderation or a takedown. Removed posts are marked removed; bans gate the account.
- Rate-limit IP hashes are short-lived in the cache and expire automatically.
- Admin actions (approvals, removals, name reveals, bans, code mints) are written to an append-only audit log for accountability — recording the admin's action, not reader data.
- Account deletion and data requests: there is no self-serve account deletion in this version; use the takedown and contact channel below.
Contact
For privacy questions, data requests, or content removal, use the takedown request form or write to takedown@ghostedbyvc.com.