Privacy Policy
Last updated 31 August 2026
Nothing appears on a screen until a moderator approves it. Every photo and every event is looked at by a person in your own organization first, and nothing is ever shown to other members.
Hypeboard lets people submit photos and events to the screens in their organization’s building. This page explains exactly what it stores, who can see it, how long it is kept, and how to have it removed.
Who runs this
Hypeboard is operated by Snail Engineering, on server hardware it runs directly — see “Where the data is held” below for the two things that leave it. Each customer organization — including churches, nonprofits, schools, community groups and workplaces — has its own separate space. An organization’s moderators and administrators can only ever see their own organization’s submissions and members.
Where the data is held
Photos, event details and the database live on server hardware Snail Engineering runs directly. Two things leave that hardware, each to a separate outside company, and only for the reason stated:
- Backups. A daily copy of the photo library and the database is replicated off-site as part of a standard backup plan — to Backblaze, a cloud storage provider, and to a physically separate hard drive. A backup is written to be restored from after a failure and is not accessed as part of normal operation.
- Email. Every sign-in link, upload code, and approval or rejection notice is sent through an outbound email provider, which necessarily handles the address it delivers to and the content of that one message. It is used for no other purpose.
What is collected
If you have an account (the member app at
/app/, or a moderator using the console at
/admin/):
- Your email address and the display name your organization set up.
- A phone number, only if you add one to your profile yourself.
- The photos, captions and event details you submit.
If you submit from a QR upload page without an account:
- The name and email address you type on the page, and a phone number if the page asks for one. On pages that verify email, a six-digit code is sent to that address to confirm it is yours; a page that does not verify records what you typed and marks it as unconfirmed.
- The photos and event details you submit.
- Scanning a QR code and sending a photo does not create an account for you.
Automatically, by the server:
- Request logs containing your IP address, the time, and which URL was requested. Sign-in tokens and codes are stripped from these logs before they are written.
- Short-lived counters, keyed to your IP address, used to enforce rate limits.
- A sign-in token, so you stay signed in. It is stored as a cookie that only this site can read, and it is deleted when you sign out or delete your account.
There is no advertising, no third-party analytics, no tracking across apps or websites, and nothing here is sold or shared for marketing.
Where photos end up
An approved photo is displayed on TV screens inside your organization’s building, so anyone in that room can see it. It is not published on the open internet: every request for an image requires a credential, and screens are paired individually. A revoked screen stops working as soon as it is next online. One that has been taken off the network keeps showing what it already had for a while, but stops that on its own within two weeks either way, whether or not it ever reconnects.
Nothing reaches a screen without a person approving it first, and no submission is ever visible to other members inside the app.
If a submission is rejected
A moderator can decline a submission and, optionally, type a short reason. If you submitted with an account, or verified your email on a QR upload page, that reason is shown to you where you can see your submission history — and if you verified your email and have no account, it is also emailed to you.
Who can see your details
-
Moderators of your organization see the contact
details attached to the submission they are reviewing — that is
how a repeat problem gets stopped. On the statistics screens, phone
numbers and email addresses are shown to moderators only in masked
form (for example
jo•••@example.com). - Administrators of your organization see full contact details, and are the people who action a removal request.
- Snail Engineering, as the operator of the server, for support, backups and maintenance.
- Backblaze and our outbound email provider, but only as described above under “Where the data is held”, and for no purpose beyond that.
How long things are kept
| What | How long |
|---|---|
| Photos a moderator rejected | Deleted after 30 days, along with the file |
| Approved photos and events | Kept until removed by your organization. An organization can ask for an automatic limit, after which the photo and the submitter’s name, email and phone are deleted |
| Sign-in sessions | 30 days after you last used it, except a moderator or
administrator session at /admin/, which lasts
12 hours — that screen can show unapproved photos on a
shared computer, so it signs out sooner |
| Email sign-in links and codes | Valid for 15 minutes; the record is deleted a week later |
| Upload-page email verification | Valid for 30 minutes, then deleted nightly |
| Moderation record (who approved what) | 1 year |
| Records of blocked submission attempts | 180 days |
| Server request logs | About the last 10 days, on this server’s own disk |
Getting your data removed
-
If you have an account: open Settings at
/app/and choose Delete Account. You are asked whether photos that were already approved should stay on the screens with your name removed, or be deleted too — and whichever you pick is what happens. - If you submitted from a QR page: write to support@snailengineering.com from, or naming, the email address you used. Every photo and event submitted with that address is deleted, files included.
Children and young people
Hypeboard may be used by organizations whose communities include minors. It is designed with that use in mind: an account cannot submit anything until a moderator approves it, every submission is reviewed by a person before it appears anywhere, and no submission is ever shown to other members — approved photos go to the screens in the building, not to a feed people browse.
Hypeboard is not directed at children under 13, and no one reaches it except through their own organization. If you are a parent or guardian and want your child’s photos removed, write to support@snailengineering.com and they will be deleted — you do not need an account to ask.
How it is protected
- Sign-in tokens, codes and screen credentials are stored only as hashes, so a copy of the database does not yield a working credential.
- Traffic is encrypted in transit.
- Every query is scoped to one organization, and image requests are checked against the specific screen asking for them.
- There are no passwords in this system at all — signing in uses a one-time link or code sent to your email.
Changes
If what is collected or how long it is kept changes, this page and the date at the top change with it.
Contact
Questions, or a removal request: support@snailengineering.com.