Privacy Policy
Last updated: July 2026
Avelune is an anonymous peer support community for mental health. We take your privacy seriously — this policy explains what information we collect, why we collect it, and how you can control it.
By using Avelune, you agree to the practices described here. If you do not agree, please do not use the service.
1. Who we are
Avelune ("we," "us," or "our") is an independent project operated at avelune.app. We are not a healthcare provider, therapist, or medical service. Avelune is a peer support community only — not a substitute for professional mental health care.
2. What information we collect
Account information
When you create an account we collect your email address (for authentication and account recovery) and a username you choose. Your username is displayed to other users. Your email address is never shown publicly.
Content you post
Posts, comments, and direct messages you create are stored in our database. You choose what you share. Posts and comments are visible to other signed-in users. Direct messages are visible only to the participants of that conversation.
We also operate a public preview page (avelune.app/explore) that shows a small, rotating sample of recent posts — by username only, never your email or any identifying account information — to people who have not yet signed up. This is enabled by default. You can turn it off at any time under Settings → Privacy, after which your posts will only ever be shown to signed-in members. The preview page is marked noindex so its contents are not archived by search engines, and replies/comments are never displayed there.
Support connections
If you use Connect to signal that you could use support, or to offer support to another member, we log that a connection formed — who reached out, who responded, when, and the topic — for safety oversight. We do not log the contents of the conversation itself; once connected, you're talking through our normal direct-message system, with the same privacy as any other conversation. If a message in that chat is later reported, only the reported message is reviewed — never the rest of the thread. If you post a request anonymously, your identity stays hidden from other members browsing the queue until someone connects with you.
Mood check-ins and wellness data
If you use the mood check-in feature, your mood scores and journal entries are stored privately and associated with your account. This data is only visible to you — no other user, including administrators, can read your personal wellness entries.
Feedback submissions
Submitting feedback requires being signed in, so we can follow up if you report a bug or ask a question. We store your message, the category you selected, your user ID, and — for bug reports — anything you add under "steps to reproduce" and basic device/browser information captured automatically from your browser (never typed by you).
Rate limiting data
To prevent abuse, we store a one-way HMAC hash of your IP address when you create an account, and a hash of your email address when you request a password reset. These hashes expire automatically after one hour and cannot be reversed to identify you.
Ban enforcement data
When we ban or suspend an account for violating our community guidelines, a moderator may also block the IP address associated with that violation — stored as the same kind of one-way HMAC hash described above, but kept until a moderator manually lifts it (rather than expiring after an hour) so it can prevent that account from being recreated. This hash cannot be reversed to identify an IP address.
We also compute a device fingerprint from a handful of technical browser signals (screen size, timezone, and similar) when you create an account, and store a one-way hash of it. If your account is later banned or suspended, that hash can be blocked the same way, to make it harder to evade a ban by creating a new account from the same device. This hash also cannot be reversed to identify your device, and is not used for any purpose besides ban enforcement.
Usage data
Our hosting infrastructure (Cloudflare Workers) may log standard access metadata such as IP addresses, request timestamps, and response codes for security and reliability monitoring. We do not use this data for advertising or sell it to third parties.
3. How we use your information
- To provide and operate the Avelune service
- To authenticate your account and keep it secure
- To send you transactional emails (e.g. email confirmation, password reset)
- To investigate reports of harmful content or policy violations
- To send in-app wellness reminders if you opt in
- To improve the service based on anonymised usage patterns
We do not sell your data, use it for advertising, or share it with third parties except as described in section 4.
4. Third-party services
Avelune relies on the following infrastructure providers:
- Supabase (database, authentication, realtime) — data is stored in a Supabase project hosted in an EU or US region. Supabase's privacy policy applies to their processing.
- Cloudflare (CDN, edge compute, DDoS protection) — requests pass through Cloudflare's network. Cloudflare's privacy policy applies.
We do not integrate advertising networks, analytics SDKs, or social-media tracking pixels.
5. Data retention
Your data is retained for as long as your account exists. When you delete your account (Settings → Delete account), we permanently delete your profile, all posts, comments, direct messages, mood check-ins, and journal entries. Backups may retain deleted data for up to 30 days before being purged.
Content you reported to us for safety review may be retained for a reasonable period to complete that review even after account deletion.
6. Your rights
You have the right to:
- Access — request a copy of the personal data we hold about you
- Correction — update your username or email in Settings
- Deletion — delete your account and all associated data via Settings → Delete account
- Portability — download a full export of your data at any time via Settings → Your data → Download my data. The export includes your profile, posts, comments, messages, reactions, mood check-ins, journal entries, and notifications in machine-readable JSON format.
- Objection — contact us if you believe your data is being processed unlawfully
To exercise any of these rights (or if you have trouble accessing the self-service tools), use the feedback option in Settings or reach out via the About page.
6a. How we protect your information
- All data is transmitted over HTTPS. Security headers (CSP, HSTS, X-Frame-Options) are enforced on every response.
- Passwords are never stored — authentication is managed by Supabase, which uses bcrypt hashing.
- Owner/admin accounts require two-factor authentication (TOTP) once enrolled, enforced both in the UI and at the server level on every admin action.
- Sensitive account actions (password change, account deletion) require re-entering your current password before proceeding.
- All destructive and moderation actions by administrators are recorded in an append-only audit log.
7. Cookies and local storage
Avelune does not use advertising cookies. We use browser local storage to persist your authentication session (managed by our auth provider) and to save drafts, preferences, and conversation ordering — all locally on your device.
8. Children
Avelune is not intended for users under the age of 13. We do not knowingly collect data from children. If you believe a child has created an account, please contact us and we will delete it promptly.
9. Changes to this policy
We may update this policy from time to time. When we do, we will update the "last updated" date at the top. Continued use of Avelune after a change constitutes acceptance. For significant changes we will post an in-app notice.
10. Contact
Questions about this policy? Use the feedback option in Settings or reach out via the About page.