Skip to main content

Privacy Policy

Last updated: May 12, 2026

1. Information We Collect

Registered Users

  • Name, email address, and password (encrypted)
  • Profile information you choose to provide (bio, location, avatar)
  • Content you post (text, images, comments, reactions)
  • Date of birth (for age verification / COPPA compliance)

Guest Users

  • Session identifier
  • IP address
  • Browser user agent
  • Last visit timestamp

Live Session Participants

When you join a live audio/video session, we additionally collect:

  • Recording consent records (timestamp, IP address, browser user agent, cryptographic hash of the consent text you agreed to)
  • Session participation metadata (join/leave times, session ID)
  • Audio and video recordings (only when the session host has enabled recording and you have provided explicit consent)

Recordings may be stored on MCL servers and on IPFS. Content stored on IPFS is distributed across a decentralized network and may persist even after deletion from the Platform. You have the right to decline recording and leave the session at any time. See our Terms of Service Section 7 for full details on live session recording consent.

2. How We Use Your Information

  • To provide and operate the Platform
  • To authenticate users and maintain account security
  • To send notifications and email digests (with opt-out)
  • To enforce our Terms of Service and Community Guidelines
  • To improve Platform features and performance

3. Data Storage

Your data is stored on locally-hosted servers in Brandenburg, Meade County, Kentucky. Account data and metadata are stored in PostgreSQL. Media files (images, videos) are stored on IPFS (InterPlanetary File System), a decentralized storage network. Content stored on IPFS may be replicated across multiple nodes and may persist even after deletion from the Platform database.

4. Data Sharing

We do not sell your personal information. Data may be shared:

  • With other MCL county nodes for content federation (only content you mark as regional)
  • When required by law or valid legal process
  • With service providers who help operate the Platform (Cloudflare for DNS/security, Sentry for error tracking)

5. Cookies and Tracking

MCL uses session cookies to maintain your login state and track guest activity. We do not use third-party advertising cookies or tracking pixels. IP addresses are logged for security and anti-abuse purposes.

6. Your Rights

  • Access your personal data at any time through your Profile page
  • Update or correct your information
  • Request deletion of your account and associated data
  • Opt out of email notifications and digests
  • Request a copy of your personal data (email [email protected])

7. Data Retention

Account data is retained as long as your account is active. Upon account deletion, your personal data will be removed from our database within 30 days. Content previously stored on IPFS may persist on the decentralized network beyond our control. For full details on retention periods for each data category, see our Data Retention Policy.

8. Data Breach Notification

In compliance with the Kentucky Personal Information Security and Breach Investigation Act (KRS 365.732), MCL will notify affected users without unreasonable delay if we discover a breach of security involving your personal information (defined as your name combined with your Social Security number, driver's license number, or financial account information). If a breach affects 1,000 or more Kentucky residents, we will also notify the Kentucky Attorney General and major consumer reporting agencies. Notification will include:

  • A description of the breach and the types of information involved
  • Steps we are taking to address the breach
  • Actions you can take to protect yourself
  • Contact information for follow-up questions

9. Personal Information Disposal

In accordance with Kentucky identity protection standards, when personal information is no longer needed for business purposes or legal compliance, MCL disposes of it through secure deletion from our databases and IPFS unpinning. Our automated data retention system enforces scheduled disposal of expired records.

10. Children's Privacy (COPPA)

MCL does not knowingly collect personal information from children under 13. If we discover an account belongs to a child under 13, we will promptly delete it and all associated data.

10a. Age Tiers and Minor Safety

For purposes of safety screening and feature access, MCL groups accounts into three age tiers based on the date of birth provided at registration:

  • Adult (18+) — full access to all platform features, subject to other eligibility checks (e.g. Verified Local).
  • Minor (13–17) — full social access within the same age tier, but cross-age direct messaging, voice calls, and video calls are restricted by default. Certain features (Dating, Marketplace for vehicle/firearm-adjacent categories) are gated to 18+.
  • Under 13 — accounts are not permitted. If detected, the account is suspended and personal data is deleted in accordance with COPPA.

The age tier is computed server-side from the date of birth on file and is not user-editable after registration. Adjusting it requires a support request and a written explanation; we will additionally verify with the parent/guardian where appropriate.

10b. Family Links (Parent / Guardian Relationships)

Adult users may submit a Family Link claim asserting a parent, guardian, grandparent, adult-sibling, or other-family relationship with a minor account. A verified Family Link unlocks cross-age direct messaging, voice calls, and video calls between the two accounts (otherwise blocked by default for cross-tier pairs).

The claim flow is:

  1. The adult submits the claim (relationship type + written reason) against the minor's account email.
  2. The minor must accept the claim from their Profile → Family Links page.
  3. MCL staff review and either verify or deny the claim.
  4. Either party may revoke a verified Family Link at any time; revocations are immediate.

For each Family Link record we store: parent user ID, child user ID, relationship type, written claim reason, status timestamps (submitted, child-accepted, verified, revoked), the staff reviewer's user ID, and any admin notes. We do not require government documentation. Misrepresenting a family relationship is a violation of the Terms of Service and may result in account termination.

10c. AI Safety Screening for Minor Activity

Text content (posts, comments, messages) authored by or directed at a minor account is screened by our on-premises Greenwave AI service (large-language model running on hardware MCL physically owns in Brandenburg, KY). When at least one party in a conversation is a minor, the screener applies a stricter rule set with expanded detection of grooming patterns, off-platform contact pressure, requests for identifying information, and other risk signals defined by NCMEC and similar child-safety guidelines.

Content is screened to evaluate whether it should be hidden pending moderator review. Flagged items generate an internal report visible to MCL moderators. Content authors are notified when their content is hidden. We do not share screening outputs with third parties; AI inference is performed entirely on MCL-controlled hardware.

10d. Voice and Video Room Safety Monitoring

Voice rooms and video calls that include a minor participant are subject to continuous safety monitoring for the entire duration of the session:

  • Audio monitoring — audio is continuously captured in rolling thirty-second segments, transcribed by our on-premises speech-to-text service (Whisper), and the transcript passed to Greenwave for review against our minor-protection rule set. Each segment's audio file is deleted immediately after transcription; only the transcript is retained (see 10e for retention windows). Audio is not stored, recorded, or shared as continuous audio — only segment-by-segment transcripts.
  • Video frame monitoring — still frames are captured continuously from the video feed in rolling thirty-second windows for the entire duration of the session, and each frame is screened by our on-premises vision model for explicit or unsafe imagery. Unflagged frames are discarded immediately. Frames that the model flags as unsafe may be pinned to MCL's IPFS storage so moderators can review the report; flagged frames are retained for the retention window stated in 10e. Video is not stored or recorded as continuous video — only sampled frames during minor-tier sessions.

When a transcript or video frame triggers our minor-protection rule set, the following protocol activates automatically:

  1. An internal moderator report is opened, attached to the live session and the speaker (if identifiable).
  2. Repeat triggers within the same session may auto-mute, auto-remove, or auto-end the session.
  3. Where the content meets the legal threshold for mandatory reporting, MCL will report to the National Center for Missing & Exploited Children (NCMEC) or other authorities as required by federal law.

Hosts and participants in a monitored room will see an in-room indicator while monitoring is active. Monitoring is automatically disabled for rooms in which the host and all participants are confirmed adults.

10e. Retention Windows for Safety Data

  • Greenwave inference logs (model, duration, outcome): 180 days
  • Voice transcripts produced for safety sampling: 30 days (deleted automatically; longer only if part of an active moderator report)
  • Flagged video frames pinned to IPFS: 90 days from the report's closure
  • Family Link records: life of the relationship plus 90 days after revocation
  • Internal reports generated by AI screening: same retention as user-submitted reports (see Moderation Policy)

11. Security

We implement industry-standard security measures including encrypted passwords, HTTPS, and DDoS protection via Cloudflare. However, no system is completely secure, and we cannot guarantee absolute security.

12. Changes to This Policy

We may update this Privacy Policy periodically. Registered users will be notified of material changes. Continued use constitutes acceptance.

13. Contact

For privacy questions or data deletion requests, contact [email protected].