ALTER Privacy Policy
Who we are and how to contact us
Jiss Tech LLC operates ALTER, a social app for speaking your mind, venting, and connecting through posts and conversations. In this policy, “we” means Jiss Tech LLC. This policy covers the ALTER app and its backend service.
For privacy questions, account deletion requests, or concerns about a child’s information, contact help@jiss.tech. Include your ALTER username when relevant, but never send a Google password or sign-in token.
Google sign-in and your account
ALTER uses Google sign-in. Google provides a credential containing account claims so our server can verify your identity. These claims may include a Google account identifier, email information, and profile information. We use the Google account identifier and verified-email status to validate sign-in, and store the identifier linked to your ALTER account. Google’s email, name, and profile photo are not copied into your public ALTER profile.
You choose an ALTER username and may provide a display name, avatar, profile photo, banner, and bio. We store your account and profile identifiers, creation time, account status, and the Privacy Policy and EULA versions you acknowledged or accepted, with the acceptance time. We also maintain session records so we can authorize requests and revoke access.
For an operator-assisted transfer of an existing persona to Google sign-in or between verified Google accounts, we check an approved Google email address and store a verification value derived from it, the destination account, and an expiring, single-use reservation. Transfers between Google accounts also store a verification value derived from the current Google identifier to prevent changing the wrong account. The reservation does not store the email address itself, and this information is not added to your public profile. For transfers between Google accounts, both verification values are cleared when the transfer is completed; unused reservation records remain until operator cleanup or account deletion. Ordinary Google registration does not store your Google email address in the account record.
ALTER does not ask you to create an ALTER password or PIN, and does not receive your Google password. Google controls its own sign-in interface, account security, and data practices under its privacy policy at https://policies.google.com/privacy.
Location, device storage, and technical information
Nearby features use a broad region you select. A region attached to a post is visible to that post’s audience. ALTER does not use device GPS or request precise location for these features, and does not collect contacts, microphone recordings, or biometric identifiers for sign-in.
The app stores preferences and unfinished post drafts on your device. These can remain between app launches. Feed and profile content is cached in memory during use and rechecked with the server; feed snapshots are not saved for offline reuse. Previously saved feed snapshots are cleared when the updated app initializes account storage. Signing out clears account drafts and cached account content through the app’s cleanup process. Other devices and copies made through operating-system backup features are outside that local cleanup.
An ALTER session token authorizes your signed-in session. Native apps keep the token and account identifier in secure device storage so you can stay signed in between app launches; signing out removes that saved session through the app’s cleanup process. The website keeps its session in an HttpOnly cookie that application JavaScript cannot read. The cookie lets you stay signed in after reloading or reopening the browser. Signing out revokes the server session and clears its cookie; a connection is required to finish signing out. Sessions expire after 365 days without renewal; authenticated activity renews active sessions. Google or your device may separately remember your Google sign-in choice. Network requests necessarily expose connection information, including an IP address, to the receiving server and infrastructure providers. Our backend uses request information for security and rate limiting; application request-body logging is disabled.
Native push notifications
If you grant operating-system permission for push notifications, ALTER automatically schedules a generic reminder to vent or check in about every three to four days (84 hours). There is no separate in-app reminder switch. Opening the app does not restart that interval. Delivery depends on your notification permission, a current device registration, connectivity, and provider availability; it is not guaranteed. You can revoke notification permission in your device settings.
To schedule these reminders, we store registration eligibility, its update time, and limited scheduling and delivery status. These records do not record what you type, which posts you read, or your location. A previous app version may have stored a foreground activity timestamp; new activity timestamps are no longer collected for reminders. Reminders require a current eligible notification registration and do not add a fake like, follower, message request, or unread activity item.
In supported iOS and Android builds, ALTER can send optional device alerts for likes, replies, follows, follow-request decisions, message requests, and new messages in accepted conversations. The app asks for the operating system’s notification permission. You can check notification status in ALTER Settings and change alert permissions in your device settings. In-app activity remains available when device alerts are off.
When you enable device alerts, we associate the device’s notification delivery token and platform with your ALTER account and signed-in session. We store registration and refresh times, and delivery records containing notification and token references, activity type, attempt count, status, and scheduling times. These records let us route alerts, handle temporary delivery failures, and retire outdated registrations.
Android alerts use Google Firebase Cloud Messaging. Supported iOS alerts use Apple Push Notification service when enabled for that build. The provider receives the delivery token, app and platform information, normal connection metadata, an internal ALTER account identifier and activity-notification or reminder identifier, and generic alert text. We do not include usernames, post, comment or message text, Google sign-in credentials, or ALTER session credentials in push payloads. Opening an activity alert requires sign-in and a fresh authorization check before its associated activity is shown. A reminder opens the app without claiming new social activity.
Google and Apple process notification delivery identifiers and technical information under their own service terms and privacy practices. Firebase also uses app installation identifiers to route notifications. Turning off alerts does not erase identifiers or records already held by a provider, and ALTER account deletion does not automatically delete a Firebase installation or your Google or Apple account. See https://firebase.google.com/support/privacy and https://www.apple.com/legal/privacy/.
After our server processes a sign-out or account deletion, it removes the associated delivery registrations and queued alerts. Replacing a registration or receiving an invalid-token response also retires that registration. An offline or failed sign-out request may not reach the server immediately. Alerts already handed to a provider or displayed by your device cannot be reliably recalled; a generic alert may still arrive. Device settings control how alerts appear, including on a lock screen.
How we use information
We use information to sign you in, maintain your persona, display and deliver content, manage follows and communities, deliver messages and notifications, save drafts and selected posts, and apply blocking and account controls. We also use it to respond to support requests, investigate reported abuse or security issues, improve reliability and usability, and comply with applicable legal obligations.
Reports contain the reporting account, a content or persona reference, the reason provided, and the report status and time. Support correspondence contains what you choose to send and the contact information needed to reply. Please share only what is needed to explain the issue.
Administrative actions, such as moderation and verification changes, produce audit records containing the acting administrator’s persona identifier, action, target reference, timestamp, limited reason or status information, and previous/new usernames when an administrator changes a handle. Audit records do not copy post, comment, or message text. They support accountability and investigation and can remain after the affected account or content is deleted.
Post and reply screening with Profanity.dev
Before publishing a post or reply, ALTER screens its text for prohibited slurs. Ordinary swearing is permitted, subject to the other community rules. Our server applies a local word filter and uses the Profanity.dev API for additional screening. Text from private profiles is also screened before publication.
For API screening, our backend sends the submitted post or reply text, split into smaller sections when necessary, to Profanity.dev. We do not attach your ALTER account identifier, Google credentials, session token, GIF reference, or device identifier. The provider receives the submitted text and the connection information of our backend. Private messages, profile fields, and unfinished or saved drafts are not sent to this API.
Profanity.dev and its infrastructure providers process submitted text to provide their service. Their service is described at https://www.profanity.dev/. ALTER does not control or promise a particular retention period for the provider. Our application does not log screening text or provider responses. A bounded in-memory cache stores text hashes and screening outcomes instead of text; decisions may be reused for up to five minutes.
Automated screening can miss prohibited language or reject permitted text. A rejected submission is not published, and the app lets you revise it. If screening is temporarily unavailable, publication waits until a successful retry. Contact help@jiss.tech if you believe a moderation decision is incorrect.
GIF search and media from KLIPY
ALTER uses KLIPY to let you search for and choose GIFs. Opening the GIF picker requests trending results directly from KLIPY. Searching sends the words you enter directly from your device to KLIPY. These search words are not sent to ALTER’s analytics or stored as searches by the ALTER backend. Do not include private account details or sensitive personal information in a GIF search.
GIF previews and GIFs attached to posts or direct messages load directly from KLIPY’s media servers, including when another user views a post or a conversation participant views a message. KLIPY therefore receives search or media requests, the requesting device’s IP address, and normal network/request information. The media URLs supplied by KLIPY may contain its delivery or measurement parameters, which are preserved. ALTER does not add an ALTER account identifier, Google credential, or separate customer/device identifier to these requests.
Selecting a GIF stores its provider reference, media and preview URLs, dimensions, and description with the post, message, or unfinished draft. Unsent message drafts and retry state are held in app memory during use. ALTER does not re-host the GIF files. KLIPY controls its media delivery, availability, and its own processing, described at https://klipy.com/support/privacy-policy. Choosing not to search does not prevent KLIPY media requests when you view GIF posts or receive GIFs in accepted conversations.
KLIPY’s policy describes using request, search, and viewing information for service operation and improvement, measurement, and advertising-related purposes. ALTER’s limited PostHog event rules do not control KLIPY’s separate processing. Review KLIPY’s policy for its practices and choices.
ALTER Plus and purchase information
Administrators can grant an account complimentary Plus access. We store the recipient account, grant duration and expiry if any, status, granting or revoking administrator, and audit timestamps and reason codes. These records let us provide and manage the gift separately from paid store access. Other users see the normal Plus membership badge, not whether membership was purchased or gifted.
If you use ALTER Plus, we store your selected profile theme, avatar style, username color, and post-text color. These account-level appearance choices are public where your profile and posts are displayed. A public Plus badge indicates that our server currently confirms active membership; it is separate from account verification. Public profile responses expose this membership status and appearance choices, not your subscription price, product, store, expiration, transaction details, or payment information. When membership expires or current access cannot be verified, fresh responses omit the Plus badge and use the default appearance.
We also store private bookmark collections, saved feed filters, and drafts you choose to save to your library. Library drafts are stored on our servers so you can access them on other devices; the current composer draft is saved on your device unless you separately save a library copy. Library contents are private to your account and are not sent to our analytics providers.
Where subscriptions are enabled, RevenueCat and the applicable app store process purchases and subscription status. RevenueCat receives an internal ALTER account identifier, purchase history and store transaction or receipt information, subscription product and entitlement status, and technical information needed to operate its SDK, including device, app, platform, and connection information. We do not send it your posts, messages, drafts, Google credentials, or email address. The app store handles payment details; ALTER does not collect payment card numbers.
ALTER stores verified subscription status, expiration, product, store, environment, and limited webhook records to keep access current, avoid duplicate processing, and show subscription counts to authorized administrators. RevenueCat and the store may retain purchase records separately for their own service, financial, fraud-prevention, and legal purposes. See https://www.revenuecat.com/privacy and your app store privacy information. Contact help@jiss.tech for requests involving purchase records held separately from your ALTER account.
Deleting an ALTER account removes its active subscription access record, profile customization, and organizer data from ALTER. It does not automatically cancel an app store subscription or delete RevenueCat and store records. Manage or cancel your subscription through the store before deleting your account; contact help@jiss.tech if you need help.
Analytics and error reporting
When enabled for a deployment, ALTER uses PostHog for a small set of manually recorded events: successful Google sign-in, publication of a post, following or unfollowing, and the names of app screens viewed. Publication events contain no post text, post identifier, or region; follow events contain only the following state. Screen events contain no route parameters, conversation identifiers, or message text.
These events use pseudonymous identifiers. For a signed-in account, the identifier is derived from an internal account identifier using a one-way hash; it is not your username, email, or Google account identifier. Pseudonymous information may still be personal information. The app resets analytics identity when accounts change. PostHog person profiles, session replay, automatic screen and touch capture, and automatic collection of post or message content are disabled.
ALTER uses Sentry, when configured and enabled, to diagnose application errors. The mobile and web integration reports sanitized JavaScript errors, safe code locations, app version and environment, and a fixed error category; signed-in errors can include the same kind of pseudonymous account identifier. Native crash capture is disabled. The backend reports sanitized unexpected server errors with a route pattern and status, without account identifiers or request bodies.
Our Sentry filters remove original error messages, request data, breadcrumbs, attachments, and arbitrary context that could contain user content or credentials. PostHog event filters restrict outgoing properties. Provider project settings suppress stored IP and location enrichment for these events, but the providers still receive connection information while handling network requests. These safeguards do not mean the providers never process IP addresses.
Telemetry is controlled by deployment settings; this version has no individual analytics switch in Settings. Reading this policy is not an affirmative consent to optional tracking. Contact help@jiss.tech with questions or to exercise applicable privacy rights. PostHog and Sentry describe their own practices at https://posthog.com/privacy and https://sentry.io/privacy/.
When information is disclosed
Information is disclosed to other users as described above and to providers needed to operate ALTER, including Google for sign-in and Firebase notification delivery, Apple for supported iOS notification delivery, KLIPY for GIF search and media delivery, RevenueCat and app stores for purchases, hosting and infrastructure providers for service delivery, and PostHog and Sentry for the limited purposes described in this policy. A provider may process information in a country different from yours.
We may disclose information when reasonably necessary to respond to a valid legal request, meet a legal obligation, address fraud or abuse, protect people’s safety or rights, or investigate a security incident. Any such disclosure remains subject to applicable law. This policy does not give other users permission to reuse your private information.
Retention and account deletion
To delete some data while keeping your ALTER account, use the options on your own posts to delete them, or manage your profile and saved items in the app. For other data deletion requests, email help@jiss.tech with the subject “ALTER data deletion”, your ALTER username, and the data you want removed. We may verify account ownership. The retention exceptions and limits below also apply to these requests; you do not need to delete your account to contact us.
Reminder eligibility, last reported activity, and account-linked scheduling state are retained to provide the feature and prevent repeated sends, and are removed with account deletion. Revoking notification permission prevents device alerts; once ALTER observes the change, it also removes the delivery registration. Revocation does not remove already delivered alerts. Complimentary access records are also removed with account deletion, while limited administrative audit records follow the separate audit retention described below.
Account information and submitted content are kept to provide your account and the associated features until you delete them or we remove them. Content does not automatically expire after a set number of days. Feed content is cached in app memory during use; unfinished local drafts can remain until published, cleared, or removed during account cleanup.
Push registrations remain linked to their account and session until revoked, replaced, found invalid, or removed with the account or session, including when expired sessions are cleaned up. While the delivery service is running, queued alerts older than 24 hours are discarded and completed or discarded delivery records older than seven days are removed. Cleanup resumes when a paused delivery service restarts. Removing a registration or its associated notification also removes its delivery records. Message-read positions and GIF references follow the retention rules of their conversation and account-deletion rules. In-app notification history is separate from this delivery queue and follows the account and content deletion rules above. Provider records and backup copies follow their separate retention processes.
To delete your account in the app, open Settings and choose Delete account. Confirm with the same Google account using a fresh sign-in credential. If you cannot use the app, email help@jiss.tech with the subject “ALTER account deletion” and your ALTER username. We may need to verify account ownership before acting; do not email passwords or tokens.
Successful deletion removes the account and Google identity link from the active ALTER database, along with the persona and its profile media associations, legal acceptance records, sessions, authored posts and comments, saves, reactions, memberships, follows, blocks, notifications, push registrations and queued delivery records, and associated reports. Conversations involving the deleted persona and their messages are removed, including the other participant’s messages in those conversations. Comments on your deleted posts are also removed. The app clears account data on the device performing deletion.
Deleting ALTER does not delete your Google account or remove the original media from KLIPY’s catalog. Uninstalling the app, signing out, or revoking Google access alone does not request deletion of your ALTER account. Deletion does not recall copies saved by other people or immediately clear content already cached on their devices. Administrative audit records, separate support correspondence, provider request records and telemetry, or infrastructure backup copies, where present, are not automatically erased by the account deletion and are subject to their applicable retention and deletion processes. Audit records may be retained to investigate abuse, explain administrative decisions, and meet legal obligations. Contact us to request deletion of information held separately; information may need to be retained where legally required.
Your choices and privacy requests
You can edit your username, display name, avatar, profile photo, banner, and bio, choose available profile appearance options, delete your posts, manage saved posts and follows, leave communities, block or unblock users, and delete your account through the available app controls. You can also manage ALTER’s Google connection through your Google account.
Depending on the law that applies to you, you may have rights to access, correct, delete, or receive a copy of your personal information, object to or restrict certain processing, withdraw consent where processing relies on it, or complain to a privacy regulator. Email help@jiss.tech to make a request. We will assess requests under applicable law and may ask for proportionate information to verify identity. The current app does not provide an automatic data-export tool.
Age requirements and children
ALTER is intended for people aged 13 and older and is not directed to children under 13. New users must confirm that they are at least 13. This is a self-declaration, not verified age. We do not collect a date of birth through registration.
Children under 13 must not create an account or submit information. If you believe a child under 13 has provided personal information to ALTER, contact help@jiss.tech so we can investigate and take appropriate deletion and access-restriction steps. Additional rules for minors may apply where you live.
Security and policy changes
We use access controls, verified Google credentials, session checks, rate limiting, and data minimization in telemetry to reduce unauthorized access and unnecessary disclosure. No service can guarantee absolute security. ALTER is not a confidential medical service and does not promise end-to-end encryption or anonymity.
We may update this policy as the service or applicable requirements change. The effective date identifies the current version. Material changes will be presented in the app or through another appropriate notice, with additional choices or consent where legally required. You can contact help@jiss.tech about any change.