Privacy

VampSocial, operated by Vampelium. Last updated 13 August 2026.

This page describes what the software actually does. If anything here disagrees with the service, this page is wrong and should be corrected.

What is stored

DataWhy
Your account identifier, and the email address and username on your Vampelium accountTo know whose posts are whose. VampSocial never sees your password. The identifier is the one vampelium.com issues, so it is never sent to your browser or anybody else's — a public timeline that carried it would let anyone match a handle here to the same account on another Vampelium service
Your handle, display name and bioThey are your profile
Your posts, replies, quotes and repostsThey are the service
Earlier versions of posts you editedSo an edit cannot quietly change what a reply was answering. Deleted with the post
Images you upload, re-encoded, with your descriptionsTo show them
Who you follow, block, mute, like and bookmarkTo build your timeline. Bookmarks and mutes are private

What is deliberately not stored

What is recorded about reading

Two things, and only in aggregate on the post:

One row per person per post per kind, kept for three weeks and then deleted. It records that it happened, not when within the day, not in what order, and not alongside anything else you did. It is used for one purpose: to work out how many of the people who saw a post wanted to read it, which is what lets a good post from a small account outrank a dull one from a large one.

Signed-out reading is not recorded at all. If you are reading a shared link without an account, none of the above happens.

This is a change. Earlier versions of this page said nothing about how you read was stored, and that was true when it was written.

Photographs lose their location

A photograph from a phone usually carries EXIF metadata, and that routinely includes the exact coordinates where it was taken. Every image uploaded here is decoded and re-encoded before it is stored, which removes that metadata — along with the camera details, the timestamp and any mismatched thumbnail hidden in the container. The original file is never kept.

Posting a picture of your desk should not publish your home address. This is the part of the service most worth checking someone actually implemented, so: it is in src/social/images.ts, and if the re-encoder is unavailable the upload is refused rather than stored unprocessed.

Who else sees it

Your posts are public — that is what posting is. Cloudflare, because the service runs on their platform. Nobody else: your posts are not sold, shared in bulk, or used to train anything.

What blocking is, and what it is not

Blocking somebody is mutual invisibility inside VampSocial. They disappear from your timeline and you from theirs; neither of you can follow, reply to, quote, like or open the other's profile; and their posts and pictures stop loading for you while you are signed in.

It is not a padlock. Your posts are public, so anyone who signs out — or opens a private window — can read them, including somebody you have blocked. The same is true of the pictures in them. We would rather say this plainly than let a block feel like secrecy it cannot provide: if something must not be read by a particular person, blocking them is not the tool, and neither is any block button on any public service.

Taking a copy

Settings → Your data gives you a JSON file containing your posts, your drafts, who you follow, who follows you, what you have saved, who you have blocked or muted, and your muted words. The photographs themselves are not in the file — each entry names the address the picture is served from, which works for as long as the account exists. Nothing is behind a request form and nothing waits for a person to approve it.

Getting rid of it

Deleting a post removes its text, its images and its edit history. A tombstone stays so replies to it do not become orphans; it holds nothing you wrote.

Settings → Delete this account deletes the whole account. It stops being visible to anybody the moment you ask. The photographs are then removed from storage in batches, and the records naming them are removed after the bytes are gone rather than before — the other order would leave pictures in a bucket with nothing left that knows they are there. Until the removal starts, you can still stop it; once it has, you cannot, and the page says so rather than offering a button that would not work.

Signing out somewhere you no longer are

Settings → Signed-in devices ends every session, this one included. A sign-in here lasts seven days, and without this there would be nothing you could do about a session on a machine you no longer have.

VampSocial Terms Vampelium