CURRENT SYSTEM · AUGUST 9, 2026
Privacy at HQ.ME
HQ.ME is currently a limited staging alpha. This page describes what the system does now; it is not a promise about features that have not been built or a substitute for legal review.
Information HQ.ME stores
HQ.ME uses Supabase Authentication to store account identifiers and email addresses. It also stores profile names, claimed handles, page drafts, immutable published revisions, handle redirects, provider connection metadata, normalized provider content, and limited security and synchronization records needed to operate and investigate the staging service.
Connected providers and X
Live X integration remains disabled. No founder OAuth or live X content import is active. If a separately approved staging test enables X, connecting will be optional, limited to the explicitly allowed signed-in founder, and will require that account owner to authorize it. The staged connection requests only tweet.read, users.read, andoffline.access; it does not request permission to publish, delete, like, or message on X.
Provider access and refresh tokens are encrypted before database storage and are used only by server-side provider code. They are not intended to appear in browser bundles, public pages, custom HTML, client-visible responses, or documentation.
Normalized and cached content
If live X testing is separately approved and the allowed founder authorizes it, HQ.ME can normalize the authorized profile and up to ten recent original Posts into HQ.ME objects. Cached objects can then let the creator design and render a page without making an X request for every visitor. Public HQ.ME pages use a minimized payload and do not receive provider credentials or internal account identifiers.
A temporary provider outage is different from confirmed deletion or unavailability. During an outage, HQ.ME may show the last cached version as stale. When HQ.ME receives reliable notice that source content was deleted, protected, suspended, withheld, otherwise unavailable, or must be removed, the content is suppressed and scrubbed rather than treated as a permanent archive.
Profile Song and third-party media
A creator may add a public Spotify track, YouTube media URL, or other HTTPS media link to The Jukebox inside the Identity Room. HQ.ME stores normalized public metadata rather than provider passwords, OAuth credentials, creator-supplied iframe HTML, or remote JavaScript. A creator may request autoplay, but a visitor’s saved “Never autoplay profile media” preference, reduced-motion setting, browser policy, and provider policy always take precedence.
Opening provider artwork, a player, or an external media link can send a network request to that third party, which may process visitor information under its own privacy terms. HQ.ME constructs players only for allowlisted providers from validated public content identifiers; unsupported sites remain external links and their code is not executed inside HQ.ME.
Reporting harm or abuse
Report phishing, malicious links, impersonation used for harm, harassment, stalking, threats, doxxing, exploitation, illegal content, or other urgent safety concerns to hqme.privacy@proton.me. Include the public handle or URL and a concise description. Do not send passwords, tokens, session cookies, magic links, or illegal material. HQ.ME does not claim automated moderation that does not exist.
Disconnecting and removing content
A signed-in owner can disconnect X from the HQ.ME Basement. Disconnect deletes the locally stored encrypted provider credentials and stops cached X content from appearing publicly. HQ.ME keeps only minimal tombstone identifiers needed to prevent accidental redisplay or duplication if the account reconnects. The page design and non-X content remain.
An owner can also use “Remove cached content” without disconnecting. During the staging alpha, anyone who cannot access those controls can request account, page, personal-data, or connected- provider cached-content removal at hqme.privacy@proton.me. A request does not require sending a social password, provider token, magic link, or session cookie.
Sharing and sale
HQ.ME does not sell provider credentials. The current system uses service providers such as Supabase and Vercel to authenticate accounts, store data, and host the application. Provider content selected by a creator may be displayed on that creator’s intentionally published public HQ.ME page.
Staging limitations
This service is not yet a general production release. Operational processes, retention periods, legal entity details, and complete terms still require founder and qualified legal review before broader public onboarding. The permanent staging privacy/removal contact above is active, but it is not a substitute for that review. Live X integration remains disabled.