Skip To Main Content
SIGNAL.Powered by FIVE FIFTHS
Privacy & Data

Privacy Policy

A plain-language look at how SIGNAL by Five Fifths handles information, privacy choices, participation data, and platform safety.

Updated October 3, 2026

Information SIGNAL Processes

  • Account Data: email address, authentication records, account identifiers, age confirmation, roles, and security/session information handled through Supabase Auth.
  • Profile Data: username, display name, pronouns, timezone, broad city/region/country, bio, interests, skills, accessibility preferences, profile visibility, links, music, status, custom appearance, photos, wallpapers, and featured connections.
  • Participation Data: private Pulse check-ins, Session creation and registration, attendance, Circle membership and chat, Commons opportunities and responses, Realm campaigns and applications, and private verified Passport records.
  • Social and Communication Data: friendships, follows, blocks, mutes, private messages, notifications, activity-sharing choices, and optional communications preferences.
  • Safety Data: reports, moderation decisions, blocked words, media-moderation results, restricted audit records, and evidence needed to investigate abuse or protect the service.
  • Technical Data: necessary request, security, error, rate-limit, storage, and authentication information produced while operating the service. First-party product analytics record bounded feature events and signed-in route use as described below.

Information SIGNAL Does Not Request for Ordinary Participation

SIGNAL does not ask for a precise home address, medical diagnosis, payment card, government identification, or advertising profile. Pulse describes present participation preferences and is not a health assessment. Members should not put sensitive personal information in public fields, chats, applications, or messages unless truly necessary.

How Information Is Used

Information is used to authenticate members; operate profiles and product features; apply visibility and safety controls; provide deterministic, explainable Pulse matching; deliver notifications; moderate content; investigate reports; prevent spam and fraud; maintain verified Passport records; secure the service; meet legal obligations; and understand aggregate product reliability and feature use.

Visibility and Privacy Controls

Members control public profile visibility and selected activity sharing. Blocks, mutes, filtered words, Circle privacy, and source-level RLS restrict applicable content. Pulse history, reports, private messages (which are not end-to-end encrypted), applications, responses, moderation records, and Passport history are not public profile content. No control can guarantee that a recipient will not copy information they were authorized to see.

Circle Chat and Deleted Content

Active Circle members can read current chat for their Circle. When a message is deleted, ordinary members receive a deletion marker rather than the retained body. Deleted text may remain in a restricted evidence store available only through authorized owner/platform review paths for safety, disputes, and legal obligations.

Media Uploads and Moderation

New user images are uploaded to private quarantine, validated, re-encoded to reduce unsafe metadata, and evaluated by a configured moderation provider (videos are checked using sampled frames) before publication. Approved media is published; ambiguous media remains private for review; rejected media is not published and is removed from quarantine after its moderation record is safely created. Moderation metadata may be retained for audit, repeated abuse, and legal or safety handling.

Communications

Essential service communications may include authentication, verification, security, account changes, safety or moderation notices, critical participation changes, outages, and material policy updates. These are separate from optional newsletters, fundraising, Five Fifths or eHub news, community announcements, events, and feature marketing. Optional communications require affirmative consent and can be unsubscribed from at any time.

Analytics

SIGNAL uses first-party analytics stored in Supabase: allowlisted feature events, route names, account identifiers, entity identifiers, timestamps, and limited structured properties. Signed-in page-view tracking follows the browser analytics-consent choice; server-side feature events support service operation and analysis. Reports, private-message text, profile text, emails, usernames, and precise locations are excluded from analytics event properties. The database provides a default 13-month pruning function; its production schedule must be configured and monitored. Account-linked events are removed during approved deletion. SIGNAL does not use advertising trackers, sell member data, fingerprint devices, or build cross-site behavioral profiles.

Cookies and Local Storage

Supabase authentication uses necessary cookies to keep members signed in and refresh sessions. SIGNAL uses browser local storage for saved form drafts and may use it for member-controlled tutorial and display preferences. No optional advertising or marketing cookies are currently part of the application. If optional tracking is introduced, it must not load before any legally required consent.

Service Providers and Disclosures

SIGNAL uses Supabase for authentication, database, realtime, and storage, Microsoft Azure for web hosting/deployment and the Azure Content Safety moderation adapter when configured, and Titan SMTP for implemented transactional welcome and support-response email when configured. An HTTPS moderation webhook adapter can be selected instead; the operator must identify that provider before enabling it. Supabase Auth email uses the project's configured delivery service. Media or sampled video frames are sent to the configured moderation service; email recipients and rendered message content are sent to the configured email service. Optional external soundtrack links (including Apple Music, Spotify, YouTube or another selected site) are fetched for metadata. Artwork may be requested by a viewer’s browser when the profile loads. Following external links also contacts their services, subject to their own policies. Providers receive only the access needed for their service. Information may also be disclosed to comply with law, respond to valid legal process, investigate fraud or abuse, protect people, or complete a business transition subject to appropriate safeguards. SIGNAL does not sell information for advertising.

Retention and Deletion

Active account and participation records are retained while needed to provide the service. Expired Pulse state and abandoned quarantine media have bounded cleanup paths. Approved account deletion removes ordinary profile and account data, stored media, private conversations involving you and their messages, participation/Passport data, account-linked analytics, and authentication access. Authored activities and dependent participation records may be removed after shared-activity review. Restricted reports, moderation/audit records, security evidence, legal holds, and records needed to protect other members may remain restricted. Exact retention schedules and backup-deletion timelines require legal and operational approval.

Security

SIGNAL uses server-side authentication checks, row-level security, restricted RPCs, private storage, rate limits, moderation boundaries, security headers, and audit records. No online service can guarantee absolute security. Members should use a unique password and report suspected compromise promptly.

Member Choices and Contact

Five Fifths operates SIGNAL. Members can edit profile and safety settings, manage relationships and visibility, change optional communications, and request account action through available controls. Accessibility or privacy concerns may be submitted through the signed-in Trust and Safety page. Privacy and account-access inquiries can also be sent without login to support@the5thsignal.com. Request account deletion through the public deletion page or Account Data while signed in. Deletion requires verification and review; support provides the expected timeline. The operator must finalize the legal controller address, jurisdiction-specific rights process, effective date, response deadlines, and backup/provider retention schedules with counsel before Production rollout.

Adults Only and Policy Changes

SIGNAL is intended for adults 18 and older and is not designed for child accounts. Material policy changes will be communicated through reasonable service channels as required. Continued use after an effective change will be governed by the final reviewed Terms and Privacy Policy.