Safety
Safety, and what it covers today
Two addresses sit below: one for harm to a person on something Nicholic runs, one for a vulnerability in it. Everything under them describes what exists today, including the parts that are missing.
Two addresses, one person
Two addresses, because the two reports are not the same kind of thing. A message saying someone is being threatened has to be read for what to do about a person. A message describing a defect has to be read for what to do about the code. One inbox for both would mean whichever arrived first set the pace for the other.
The same person reads both. There is no team behind either address, no rota, and nobody on call — one person, one time zone. That is stated here rather than left to be worked out when a reply takes longer than hoped.
What happens after you write, and when
These are targets, not guarantees, and the difference is deliberate. One person cannot staff a service level, and a published guarantee that gets missed is exactly the failure this site tells people to watch for. In practice these are usually beaten.
| Stage | Target |
|---|---|
| Acknowledgement that a safety report was received and read | Three working days |
| Acknowledgement that a vulnerability report was received and read | Three working days |
| A first substantive assessment of a vulnerability | Fourteen days |
| Public write-up after a confirmed incident | Seven days from confirmation |
Neither address issues a reference number, and there is no status page to check against. A reply comes from a person or it does not come at all, which is the reason the acknowledgement window is published in the first place.
If a target is missed, it gets reported as missed rather than quietly removed from this page.
Good-faith research
Reporting a vulnerability in good faith will not be treated as an attack. Nicholic will not pursue legal action against anyone who finds a problem, reports it privately, and gives a reasonable chance to fix it before saying anything publicly.
Good faith means not accessing more data than needed to demonstrate the issue, not degrading the service for anyone else, and not holding a finding for leverage.
Reporting something on TruXSocial
Tier 2 — generalAnything happening on the platform itself goes through the report control inside it, not through either address above. A post can be reported, and so can an account. A comment cannot yet — that gap is real, and it is listed further down rather than left for someone to find at the worst possible moment.
Five things are moderated, and only these five:
- Direct threats against a person.
- Terrorism.
- Scams.
- Fraud.
- Coordinated abuse — organised campaigns against someone, rather than one person being rude.
Choosing one of those is required; adding context is optional. That list is short on purpose and it is published so it can be held to, which is why it appears here in the same words the product's own rules use.
A single report does not open a review. More than one is needed, from accounts that are not connected to each other. The exact bar is not published, and the transparency page sets out why: a threshold that gets published is read once by every operation working around it and then sat underneath permanently.
While something is being looked at, it stays fully visible. Nothing is hidden first and judged afterwards.
The separate route for things nobody may host
Three things sit outside that list and outside the review process entirely, because they are not questions of judgement about speech:
- Illegal content involving a minor.
- Intimate images shared without consent.
- A valid legal order.
These go through a separate route on the platform that needs no account and does not ask whether you are the person affected. Detail is required rather than optional, because there is no category to fall back on. It is deliberately not a sixth category — folding it into the five above would make it a matter of degree, and it is not one.
That route works on the web. It is not in the phone app yet. Saying so on this page is the difference between a gap that gets closed and a gap that gets forgotten.
How a report will be decided
When a report clears that bar, a team of members will be drawn at random to look at it — not a standing panel, and not the person who runs Nicholic. The team dissolves once it has decided, so nobody accumulates the power to decide what stays up.
A decision will carry a reason, and the outcome will be one of exactly two: the post stays, or the post goes. There is no third setting, and the absences below are the shape of that.
- There is no warning, no strike count, and no probation.
- There is no shadowban, no quiet reduction in reach, and no downranking that an account is not told about.
- There is no rate limit applied to a person as a punishment.
- That process can suspend an account. It cannot ban one — a ban is a separate act, taken by the person who runs Nicholic, and written to a record.
Appeals, and what you are told
- Against a decision
- The person whose post or account it was can appeal, and has to say why. A fresh team is drawn that excludes everyone who decided the first time, and excludes the person appealing. No deadline to file is published, because none is set.
- Against a suspension
- An account that cannot sign in can still appeal, because that route checks the password rather than an open session. Being locked out does not lock you out of contesting it.
Whoever filed the report is told the outcome. That notice appears inside the product and nowhere else — no mail is sent, so a person who reports something and does not come back never finds out what happened. That is a limit worth knowing before relying on it.
What you can do yourself
Tier 2 — general| Control | What it does, and what it does not |
|---|---|
| Mute | Takes that account out of your home feed, out of threads, and out of search results. It does not stop them replying to you, mentioning you, quoting you, following you, or messaging you, and none of those stop reaching your notifications. |
| Block | There is none, and it is refused rather than unbuilt. The platform's own rules give the reasoning: cutting off another person's ability to see or reply to public speech is a moderation power, and it is not handed to individuals. |
| Private account | Gates your posts. Your comments on other people's public posts stay public, which is narrower than the same setting elsewhere, and is said here rather than assumed. |
| Follower approval | New followers wait for you to accept them. |
| Who can message you | Everyone, only people you follow, or nobody. |
| Message requests | A message from someone you do not follow waits in a separate list. It raises no notification, no push and no unread badge until you accept it, so an unwanted message cannot demand your attention the moment it arrives. |
| Read receipts | On unless you switch them off, and reciprocal by design: turning them off means you stop seeing other people's as well as hiding your own. |
| Activity status | Whether you show as online or typing. On unless you switch it off, and reciprocal in the same way. |
| Who can mention you | Decides whether a mention reaches your notifications. It does not stop anyone writing your name. |
| Two-step sign-in | An authenticator code plus one-time recovery codes, on the web and in the phone app. |
| Sign out everywhere else | Ends every other session at once. There is no list of where you are signed in, so this is a blunt instrument rather than a precise one. |
| Sign-in alerts | Off unless you switch them on, and they do not fire for a sign-in from the phone app. |
Two things that do not exist and are worth naming: there is no control over who may reply to a post, and no way to hide who follows you.
Direct messages are stored in a form the server can read. They are not encrypted end to end, which means somebody with direct access to the database could read them. No screen in the product shows one person's messages to another — but that is a different promise from the one encryption would make, and the two should not be mistaken for each other.
Leaving, and taking your things
Deleting a TruXSocial account takes one action in settings. It happens immediately, it is permanent, and there is no waiting period in which it can be undone. Nothing is anonymised and kept.
One weakness in that, written down because writing it down is this page's job: deletion does not ask for the password again. Anyone holding an open session can end the account. Every other sensitive change in the product asks first; the one action with no undo does not.
- The export returns what you put in: your posts, your comments, the messages you sent, your bookmarks, your reactions and poll votes, your feedback, the communities you joined, who you follow, and your account record.
- Every image you uploaded is listed as an address you can fetch. The files are not inside the document, because it is one file of structured text.
- It does not carry other people's messages, even from conversations you were in. Those belong to the person who wrote them, and the promise is that you can have what you put in — not everything you were able to read.
- One request, no queue, and nobody to ask. Until 18 August 2026 this returned the account record alone and everything else took an email; that was narrower than the fifth published commitment, and the export was widened rather than the commitment narrowed.
Age
The minimum age to sign up to TruXSocial is eighteen. Nothing checks it. There is no date-of-birth field, no age question anywhere in the product, and nothing estimating it in the background.
Both halves are published together on purpose. An age rule on its own reads as a control. An age rule beside the fact that nothing enforces it is a description of what is actually there. Nobody should read anything on this page as a promise that the people on the platform are the age they say they are.
Which child-protection rules that sits under is not settled, and follows from where the platform is formally offered. The TruXSocial page carries that blank.
What is not claimed
- There is no paid bug bounty. Reports are wanted and credited, but there is no money to pay for them, and saying so is better than leaving it ambiguous.
- There has been no independent security audit and no certification. Neither is affordable yet.
- There is no guaranteed fix time. A fix takes as long as it takes, and the assessment will say what is known.
- There is no 24-hour coverage. One person, one time zone.
- Nothing on the platform reads posts looking for harm. There is no classifier, no keyword filter, and no spam detection. A report carries a weight based on how that reporter's earlier reports turned out, and that is the whole of the automation.
- This is not a crisis service. Nobody here is watching for a person in danger, and nobody here can reach anyone on your behalf. If someone is in immediate danger, a local emergency number is the thing that helps.
- A comment cannot be reported from inside the product yet. Posts and accounts can.
- The route for unlawful content is not in the phone app yet.
What actually protects this website today
Tier 2 — generalMost of this site is static files. Posts are served by a small piece of code run by the host, reading from a database that holds only published writing. There are no visitor accounts and no visitor login. That code is the largest piece of surface this site has, and it is listed here because leaving it out would be the kind of claim this page refuses to make.
A post can also carry two sharing images, drawn from its title and summary in the writing tool when it is published or drawn again later, and stored beside it; the site serves them like any other file, from this site only. One is what a messaging app shows when a link to the post is pasted; the other is a taller image for stories, behind a Share control that appears on a post once its images exist. That control is the one place this site itself puts a script on a post page. The script waits for the control to be used, then hands that image — or, where the browser cannot share a file, the post's title and address — to the browser's own sharing sheet. The only thing it ever fetches is that image, from this site; it sends nothing anywhere and sets nothing.
Each of the following was checked on the deployed site, not assumed. Served over HTTPS only, with HSTS. A content security policy that blocks third-party script origins, plus nosniff, a deny-framing header and a permissions policy that switches off device access the site never needs. No analytics, no advertising, and no scripts loaded from another host. Fonts are downloaded at build time and served from this origin, so loading a page fetches nothing from another host.
What is deliberately not described here: where anything is hosted, how it is deployed, and what protects the accounts behind it. The reasoning is on the transparency page.
After an incident
If a safety, security or privacy incident affects anyone, it gets published — including incidents nobody outside would ever have discovered. Reports go in the incident log, with what happened, when it was found, what was affected, and what changed as a result.
If this site itself is unreachable during an incident, notice goes out through a second channel. [FOUNDER TO CONFIRM: name the out-of-band channel] Keeping one external account alive purely for this is the only reason to have one.