Privacy
VampSocial, operated by Vampelium. Last updated 13 August 2026.
This page describes what the software actually does. If anything here disagrees with the service, this page is wrong and should be corrected.
What is stored
| Data | Why |
|---|---|
| Your account identifier, and the email address and username on your Vampelium account | To know whose posts are whose. VampSocial never sees your password. The identifier is the one vampelium.com issues, so it is never sent to your browser or anybody else's — a public timeline that carried it would let anyone match a handle here to the same account on another Vampelium service |
| Your handle, display name and bio | They are your profile |
| Your posts, replies, quotes and reposts | They are the service |
| Earlier versions of posts you edited | So an edit cannot quietly change what a reply was answering. Deleted with the post |
| Images you upload, re-encoded, with your descriptions | To show them |
| Who you follow, block, mute, like and bookmark | To build your timeline. Bookmarks and mutes are private |
What is deliberately not stored
- How long you looked, and what you abandoned. There is no dwell time, no scroll depth, no record of the order you saw things in, and nothing that reconstructs a session. See “What is recorded about reading” below — that section is new, and this line used to claim more than it can now.
- No third-party anything. No analytics, no advertising identifiers, no embedded scripts. The page loads code from this origin and nowhere else.
- No remote images. Every image is stored here and served from here, so nobody learns who read what by watching their image server.
- Your password. Sign-in happens at vampelium.com.
What is recorded about reading
Two things, and only in aggregate on the post:
- That a post was in front of you. On a computer that means you moved the pointer over it; on a phone, that it was on screen long enough to read rather than scrolled past.
- That you opened one. Tapping into a post to read the replies.
One row per person per post per kind, kept for three weeks and then deleted. It records that it happened, not when within the day, not in what order, and not alongside anything else you did. It is used for one purpose: to work out how many of the people who saw a post wanted to read it, which is what lets a good post from a small account outrank a dull one from a large one.
Signed-out reading is not recorded at all. If you are reading a shared link without an account, none of the above happens.
This is a change. Earlier versions of this page said nothing about how you read was stored, and that was true when it was written.
Photographs lose their location
A photograph from a phone usually carries EXIF metadata, and that routinely includes the exact coordinates where it was taken. Every image uploaded here is decoded and re-encoded before it is stored, which removes that metadata — along with the camera details, the timestamp and any mismatched thumbnail hidden in the container. The original file is never kept.
Posting a picture of your desk should not publish your home address. This
is the part of the service most worth checking someone actually implemented,
so: it is in src/social/images.ts, and if the re-encoder is
unavailable the upload is refused rather than stored unprocessed.
Who else sees it
Your posts are public — that is what posting is. Cloudflare, because the service runs on their platform. Nobody else: your posts are not sold, shared in bulk, or used to train anything.
What blocking is, and what it is not
Blocking somebody is mutual invisibility inside VampSocial. They disappear from your timeline and you from theirs; neither of you can follow, reply to, quote, like or open the other's profile; and their posts and pictures stop loading for you while you are signed in.
It is not a padlock. Your posts are public, so anyone who signs out — or opens a private window — can read them, including somebody you have blocked. The same is true of the pictures in them. We would rather say this plainly than let a block feel like secrecy it cannot provide: if something must not be read by a particular person, blocking them is not the tool, and neither is any block button on any public service.
Taking a copy
Settings → Your data gives you a JSON file containing your posts, your drafts, who you follow, who follows you, what you have saved, who you have blocked or muted, and your muted words. The photographs themselves are not in the file — each entry names the address the picture is served from, which works for as long as the account exists. Nothing is behind a request form and nothing waits for a person to approve it.
Getting rid of it
Deleting a post removes its text, its images and its edit history. A tombstone stays so replies to it do not become orphans; it holds nothing you wrote.
Settings → Delete this account deletes the whole account. It stops being visible to anybody the moment you ask. The photographs are then removed from storage in batches, and the records naming them are removed after the bytes are gone rather than before — the other order would leave pictures in a bucket with nothing left that knows they are there. Until the removal starts, you can still stop it; once it has, you cannot, and the page says so rather than offering a button that would not work.
Signing out somewhere you no longer are
Settings → Signed-in devices ends every session, this one included. A sign-in here lasts seven days, and without this there would be nothing you could do about a session on a machine you no longer have.