Yeetline

What this server can and cannot see

Being honest about this is more useful than a promise, so this page is a list rather than reassurance.

It cannot see

It can see

Taken together that is metadata, and metadata is not nothing: who talks to whom, how often, and when, is real information. Yeetline does not pretend otherwise. What it guarantees is that the contents are not part of it.

What staff can do

Moderators can kick, suspend and delete accounts and remove messages. None of that lets them read anything: deleting a message removes the sealed envelope from the server, it does not open it first.

Administrators can additionally see the deployment itself — its settings, its health, its logs — and can reach every piece of metadata above.

The honest limit

A server can always be replaced by whoever runs the deployment. You are trusting the operator with the code that is served to your browser. A deployment that wanted to could ship a page that keeps a copy of your keys, and no amount of encryption inside that page would stop it.

That is true of every web application. It is why, if the contents matter, the answer to "how do I know?" is a client you installed rather than one you were served.

What is kept, and for how long

This deployment sets its own retention: how long messages, files and the audit log are kept before they are deleted. /privacy on this server is generated from those actual settings rather than from a template, so it is true of this deployment specifically.

Deleting a message removes it here. Everyone who already received it has a decrypted copy on their own device, and nothing on this server reaches that.

Last changed 2026-09-12