Keep the boundary
visible.
Privacy notice for the temporary editorial field.
Who operates HEARD
HEARD is an independent PROBNAYA project. PROBNAYA is not represented here as a registered company. The responsible operator’s legal identity, monitored contact and applicable processing basis have not yet been confirmed for real-source operation. Real-source publication is therefore Preview-only and not approved for a public launch.
What is processed, and why
The bounded field selects public English expressions about life with AI from official Bluesky searches, configured Mastodon hashtag timelines, official Hacker News recent-story discussions and top-level comments retrieved through the official YouTube Data API v3. During an authenticated refresh, server code handles public post/comment content, source references, transient account identifiers, publication time and safety metadata. Hacker News usernames and YouTube channel IDs are used only for per-snapshot distinct-account counting, source opening and HMAC suppression; no account-history or channel-profile endpoint is read. YouTube persists at most twelve video IDs with topic and expiry metadata, never titles, comment text or attribution. Unused profile data returned by an API is discarded. No profiles, histories or follower graphs are fetched.
After hard safety and relevance gates, OpenAI transiently classifies at most thirty candidate texts using a fixed strict schema. It receives exact text, source type and broad recency, but no username, handle, DID, native ID, URL, avatar or profile metadata. It returns only a class, form, topic, numeric score and fixed reason codes; it does not produce public wording. HEARD sets store:false, but does not claim that provider security or abuse-monitoring retention is zero. The purpose is a temporary editorial field, not an archive, judgment of people or public-opinion measurement.
The sources have different audience and discovery bias. None is representative. HEARD does not sell this data, build author profiles, infer personal traits, collect visitor reactions or make automated decisions about people. No analytics, visitor accounts or submission forms are added. No claim of absolute anonymity, zero risk or universal legal compliance is made.
Before and after opening
Pages load their own stylesheet and scripts without remote fonts or preconnects. Before selection, the ordinary field contains no text, author attribution, source URL or native identifier. The original voice is retrieved only after the visitor selects an individual signal. That selection makes one bounded server-side revalidation request. For Mastodon, Hacker News and YouTube, current public API text and attribution are returned with no-store and rendered inside HEARD as escaped text, without provider HTML, scripts or iframes. This transient response is not persisted or logged.
OPEN ORIGINAL is a separate optional browser-to-provider visit; only then can that provider receive the visitor’s network information and apply its own logging. Bluesky’s existing official-embed boundary, including a public DID as opaque transport, is unchanged.
How long
Raw provider responses and candidate text remain in application memory only for one bounded operation, at most thirty seconds, and never enter PostgreSQL or application logs. A bounded reservoir keeps provider, an opaque encrypted source reference, keyed content/account/reference fingerprints, fixed editorial decisions and evaluation/expiry times for seven days; it contains no text, display attribution or source URL and the fingerprints cannot reconstruct the source text. Decisions from prior rubric versions remain only until their existing expiry and are not reused. Resolved voice text and attribution exist only in the active no-store request and browser panel. Sources are eligible from the previous seven days and must remain eligible through the complete snapshot expiry plus five minutes. Snapshots are fresh for six hours, available but stale from six to twelve hours, and unavailable at twelve hours. A successful refresh atomically replaces the previous snapshot only when its quality contract passes; failures preserve the previous snapshot without extending its original expiry. Source references share the same twelve-hour hard deadline. YouTube discovery video IDs expire after at most 72 hours. Rate buckets live at most one hour; daily model-budget rows only through their operational window; minimal refresh audit rows at most thirty days; removal request metadata at most two years. Durable suppressions contain only versioned HMAC digests and no adjacent plaintext identifier. These are pseudonymised operational data, not anonymous data.
Questions, objections, removal
Use the removal page for the configured contact status and single-post or account-wide requests. No active channel is implied while configuration is missing. Before real-source publication, the operator must validate the contact, objection handling, hosting terms, legal basis and transparency duties. You may also contact Portugal’s data-protection authority, CNPD, at CNPD. This notice does not limit applicable rights.