Privacy Policy
Last updated: 2 August 2026
In short
CaHk is pseudonymous. Other members see your username and a random public ID — never your email address. We deliberately collect as little as possible: your email, what you post, and the small amount of technical data it takes to keep the place running.
But please note: what you post is public. Registration is restricted, but reading is not — anyone can read the discussions without an account, and search engines such as Google index them. Your username appears alongside your posts, so it can show up in search results. Write as though you are speaking in public, because you are.
We do not collect your real name, date of birth, gender, phone number, home address, identity documents, or payment details. We do not collect your location, contacts, or advertising identifier, and we do not track you on other websites. We use no third-party analytics, tracking, or advertising tools, and we never sell your personal information.
1. Who is accountable
CaHk is operated by SEEM SOCIAL INC., which is accountable for the personal information under its control. For any question, or to exercise your rights, email [email protected].
We follow the ten principles of Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA). Read this alongside our Terms of Use.
2. Our principle: don’t collect it
For our members, the link between a nickname and a real person is the most sensitive thing we could hold. Our first line of defence is not a wall — it is not collecting the data in the first place. What we never stored cannot leak, and cannot be demanded from us.
So, by design:
- other members see your username and a random 10-digit public ID — never a sequential account number;
- your email address is never shown to another member;
- a reporter’s identity is never disclosed to the person reported;
- uploaded images are re-processed, which removes the data a camera attaches to a photo — including where it was taken;
- there is no visitor tracking, no ad network, and no cookie consent banner — because we set no tracking cookies that would require consent.
3. What you give us
- Your email address, provided at registration. We also keep a tidied-up copy of it for one purpose only: enforcing one account per person.
- The domain of your registration email (for example utoronto.ca). Because registration is gated to approved institutions, this is in effect a record of your school or organisation. It is visible to staff and retained for the life of the account.
- Your username, and the icon colour and interface language you choose.
- Your password — never stored in readable form, only as a scrambled value that cannot be turned back into your password. Not even we can see or recover it.
- Two-factor details, if you enable it: the authenticator seed and your backup codes, both stored encrypted.
- What you post and do: threads, replies, uploaded images, reports, votes, bookmarks, your block list, and your notification preferences.
4. What the system records automatically
- Sign-in records. Each sign-in creates a session record holding the IP address of that connection, along with browser or app details that identify the kind of device. You can see every device signed in to your account, and sign any of them out, in your account settings.
- Rate-limit records. To stop flooding and abuse we keep short-lived counts. Some of these are keyed on IP address, so the record contains one.
- A push notification token, only if you turn push notifications on — issued by Apple, Google, or your browser.
We do notrecord a registration IP address, keep search history, or maintain a general browsing or activity log. (If the database fails while handling a request, the resulting error message can carry that request’s contents into our server error log. That is not deliberate logging, but we think you should know it is possible.)
5. Why we collect it
We use the above only to:
- create and maintain your account and sign you in;
- show discussions, notifications, search results, and translations you ask for;
- check registration eligibility and enforce one account per person;
- prevent spam, abuse, and attacks, and keep the platform running properly;
- enforce the Terms of Use and handle reports;
- contact you about essential matters such as account security and service changes;
- meet our legal obligations.
We do not use your information for anything else, and we do not build user profiles or serve targeted advertising.
6. Consent
Registering an account is your consent to the collection and use described here. You can withdraw it at any time — most directly by deleting your account (section 9). Some processing is necessary to provide the service at all, so withdrawing consent means you can no longer use the Platform.
7. Cookies and on-device storage
The website sets the following first-party cookies, and no third-party cookies at all:
- Session token — keeps you signed in, for up to 30 days. Scripts on the page cannot read it.
- Session cache — a short-lived copy of your own account record that makes pages load faster. Scripts cannot read it either, but it is not encrypted and it includes your email address. It exists only on your own device and is never sent to a third party.
- Two-factor challenge — exists briefly during two-factor sign-in only.
- Preferences — language, light or dark theme, text size, the signature-dots setting, and whether you have already seen the opening animation. These record your choices and contain nothing identifying.
All of these are either necessary for the service or a preference you set yourself. None is used for tracking or advertising, which is why there is no cookie consent banner.
On mobile, the app stores exactly two things on your device, both in the system Keychain/Keystore: your sign-in token, and a non-identifying preferences record. Separately, the operating system caches images it has loaded, and when a social embed loads, that platform’s web view keeps its own storage outside our control.
8. How long we keep it
- IP addresses. A daily sweep deletes expired session records along with their IP and device details, and clears the IP from any still-active session 90 days after sign-in without signing you out. Rate-limit records are deleted after 2 days; connection records used to count overall visitor numbers are deleted within 10 minutes. You can also sign a device out at any time in your settings, which deletes that record immediately.
- Account information. Kept until you delete your account, after which a retained account record remains — keeping your username but no email or contact details (section 9).
- Threads and replies. Kept indefinitely. If you delete your account, your threads, replies, and username remain, and the account is marked deleted.
- Moderation records. Once a moderator action is logged it cannot be changed or removed, and the log is kept indefinitely.
- Backups. Backups are encrypted before they are stored. Deleted data disappears from them only as they rotate.
9. Deleting content and your account
There is no edit feature, and individual threads or replies cannot be deleted. You can delete your whole account in settings. When you do:
- your email address and other personal details are erased (your username is kept), and the account can no longer sign in;
- threads, replies, and your username remain, and the account is marked deleted;
- a retained account record — keeping your username but no email or contact details — is kept indefinitely so that threads, votes, and moderation records stay coherent;
- notifications your activity generated may remain as summaries in other members’ notification lists until those members clear them.
If a post accidentally exposes your identity — you posted your own email, phone number, or name — report it with the reason “personal privacy” and we will prioritise it.
Note that deleting your account does not undo the consequences of a breach of the Terms, and moderation records are not erased by it.
Also note: because the Platform is public and indexed by search engines, copies of what you posted may survive elsewhere after you delete it. We can remove content from the Platform, but we cannot control copies that others have already made. If you want to speed this up, you can ask the search engine directly to drop its cached copy of a page that no longer exists.
10. Service providers
We do not sell or rent your personal information, and we do not share it for advertising or analytics. To run the Platform, data passes through the following categories of provider — each receiving only what its function requires, and each contractually bound to process it only on our behalf:
- Cloud hosting — runs the application and the database.
- Network protection and content delivery (CDN) — all traffic passes through it, to absorb attacks and speed up loading. Uploaded images and encrypted backups are held in the associated object storage.
- Email delivery — sends account email (verification, password reset, welcome, password changed). Those messages contain fixed template text and a link — never your posts or other personal information.
- Machine translation— only when someone taps “translate”, the text of that reply is sent to a translation service. No account details, username, or IP address accompanies it.
- Push notification services — the system services operated by Apple, Google, and browser vendors that actually deliver a notification to your device. Used only if you turn push on. The text of a notification passes through them to reach you. It contains the thread title and the opening of the reply, and it appears on your lock screen. Turning push off stops this.
- Social embeds — Instagram and Facebook posts load with the page, so those platforms receive your request; other platforms only if you tap to load.
None of these is an analytics, tracking, or advertising service — we use none of those. If you would like to know which specific providers we currently use, email [email protected] and we will tell you.
11. Where your data lives, and what that means
Our servers and providers are located outside Canada, principally in the United States and Europe. By using the Platform you consent to your data being processed and stored outside Canada.
We think you deserve the plain implication rather than the euphemism: a lawful order served in those jurisdictions could in principle compel access without involving us. That is a question of jurisdiction, not of technical protection, and no firewall changes it. Our answer is to hold as little as possible and delete it quickly (sections 2 and 8) — the less there is, the less any such order can reach. Restricting access to Canada and the United States is part of the same reasoning.
12. Law enforcement and legal demands
We disclose personal information to law enforcement or other third parties only where the law requires it — for example a court order, warrant, or other valid legal process that is binding on us. We check the legal basis of every request and provide only what that request genuinely requires.
Where we are permitted to do so and it would not obstruct an investigation, we will tell the member affected. We do not volunteer data for convenience.
13. How we protect it
- Every connection between you and the Platform is encrypted.
- Passwords are never stored in readable form, and two-factor details are encrypted as well.
- Off-site backups are encrypted before they are uploaded.
- Administrator and moderator accounts must use two-factor authentication, and the admin area is hidden entirely from everyone else.
- Once a moderation action is logged it cannot be changed or removed.
- We have protections that stop malicious code running on our pages, and we never store page code supplied by a member.
To be straightforward: apart from the items named above, what we store — including email addresses and post content — is not held in encrypted form; it is protected by strict access control instead. No system can be guaranteed secure.
14. Protecting your own account
- Turn on two-factor authentication. It protects the account even if your password leaks.
- Use a unique password. Never reuse one from another site — breaches elsewhere are routinely replayed as sign-in attempts.
- Review your signed-in devices. Your settings list every session and let you sign any of them out.
- Be wary of impersonation. Our emails only ask you to verify an address or reset a password. We will never ask you for your password.
- Think before posting.Nothing can be edited, individual posts cannot be deleted, and content remains even if you delete your account. Don’t put your own or anyone else’s contact details or identifying information in a public post.
15. Your rights
Under PIPEDA you have the right to:
- access the personal information we hold about you;
- have inaccurate information corrected;
- withdraw consent, by deleting your account;
- complain about how we handle your information.
Email [email protected] and we will respond within 30 days. There is currently no self-serve export, so we assemble access requests by hand. We may need to verify your identity first, to protect your account.
If you are not satisfied with our response, you can complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca.
16. Data breaches
If a security incident involving personal information creates a real risk of significant harm, we will report it to the Office of the Privacy Commissioner of Canada as PIPEDA requires, and notify affected members as soon as practicable. We also keep records of incidents as the law requires.
17. Children
CaHk is not intended for anyone under 16, and we do not knowingly collect personal information from anyone under 16. If you believe someone under 16 has registered, email [email protected] and we will remove the account.
18. Advertising
Where the Platform shows promotional material, we count only aggregate impressions and clicks. We set no cookie for it, build no user profile, do no cross-site tracking, and give advertisers no personal information.
19. Changes to this policy
We may revise this policy from time to time. Material changes will be announced on the Platform and the “last updated” date above will change. Please check back periodically.
20. Contact
SEEM SOCIAL INC., operating as CaHk · [email protected]
This policy is provided in Traditional Chinese and English. If the two versions differ, the English version prevails.