Send Feedback

We'd love to hear from you

Safety & Community Guidelines

HuniWhisp is a place to be honest about the things you can’t say elsewhere. These guidelines explain how we keep that space safe without getting in the way of real, raw, human posting.

Our approach: allow by default, act on report

Like most major platforms, we don’t pre-screen and block your posts. Most content is allowed to post and stays up. When something crosses a line, we act on it after it’s reported — by another member or by our team. The one exception is illegal or imminently dangerous content, which we may remove and escalate immediately without waiting for a report.

If we remove one of your posts, we’ll normally tell you why in a notification, and you can reply to it to appeal. We’d rather explain than leave you guessing.

What’s welcome here 💚

  • Confessions, venting, dark thoughts, and things you’ve never told anyone
  • Talking openly about mental health, sadness, and struggling — including suicidal feelings
  • Seeking and giving peer support; unpopular opinions; dark humour; messy, complicated feelings
  • Disagreement and debate, as long as it’s aimed at ideas, not at hurting people
  • Respectful discussion, review, and sharing of religious works — including the Quran and the Bible — anywhere on Huni, not just Bookworms
  • Sharing about pregnancy — including teen, unplanned, or uncertain pregnancy — and asking for support or advice

Pregnancy & teen pregnancy 🤍

Pregnancy can bring up a lot — joy, fear, uncertainty, or all of it at once. Whatever you’re carrying, you’re welcome to share it here. Posts about pregnancy, including teen or unplanned pregnancy, are supported, not judged. This is a safe, non-judgmental space to be honest about how you’re feeling and to ask for support.

You don’t have to have it figured out. Confidential help and health services exist wherever you are — a doctor, a clinic, a counsellor, or a trusted adult can talk things through with you privately. If you’re a teen and that feels scary, you’re still allowed to ask for help; reaching out early is exactly what help is for.

Please look after each other’s privacy too: share your own story, and don’t expose someone else’s pregnancy or private details without their consent.

Safety Center — what we scan, and how reports work

We try to be honest about exactly how safety works here, so nothing on this page is a vague promise. Every protection we describe is a real, shipped mechanism — we’d rather under-claim than tell you we do something we don’t.

What we scan for

New posts and comments pass through an automated scanner the moment they’re submitted. It looks for a fixed set of serious patterns and sorts them into three buckets:

  • Illegal / imminent harm — child sexual content & grooming, human trafficking, terrorism planning, credible imminent threats of violence, selling drugs, selling weapons, and solicitation of commercial sex. This is the only bucket we remove automatically at post time, and we escalate it to a human (and, where required, to authorities) straight away.
  • Distress & self-harm — suicidal ideation and signs of crisis. We never remove or punish this for being a cry for help. Instead we surface crisis resources and route it to Huni Haven. In the rare case where a senior admin reasonably believes someone is in imminent danger, we may — as a last resort and solely to get help to them — lift their anonymity to reach the trusted contact they set up and/or emergency services. It is the one time we ever do this, it is permanently logged, and it is done for the person’s protection.
  • Everything else we watch for — doxxing, swatting threats, stalking, targeted harassment, predatory advances, blackmail/sextortion, hate, and scams. These are notauto-deleted; they stay up and are actioned only when reported, with the scanner’s context attached so a reviewer can act fast.

Scanner calibration — fewer false alarms, clearer rejections

We’ve tuned the scanner to be more lenient with borderline matches. Medium-confidence flags no longer quietly archive your post — instead they sit in a real moderation queue for a person to look at, so a turn of phrase that pattern-matches a serious topic doesn’t disappear on you. Posts that genuinely show signs of self-harm or distress still route to Huni Haven exactly as before.

The scanner now reads context, not just keywords. It weighs the whole sentence around a match, so a survivor recounting what happened to them, someone reporting or quoting a threat, a news or educational post, fiction, or plain condemnation are no longer treated like someone actually doing harm — those are kept, and where a serious topic is involved they’re sent to a person to review rather than removed. Genuinely dangerous content — a real threat, a solicitation, hate that glorifies or incites violence — still hard-flags with no excuse, even when it’s short or lightly disguised. And when a moderator marks something a false alarm, the scanner learns from it and stops removing that content, so the same mistake doesn’t keep happening.

Behind that learning sits Huni Keeper™ — our human-supervised moderation assistant. The Keeper studies the moderation decisions our human team has already made, spots new violation patterns emerging on the platform, and proposes them to our moderators. Nothing it learns takes effect until a human adopts it, and when its evidence is ambiguous it asks our team instead of guessing. It also tends the support inbox: simple questions our guides already answer may get an instant, clearly-labeled automated reply — while anything complicated or sensitive (bugs, payments, legal, account security, reports about a member, safety-flagged messages) always escalates to a human, and replying to the Keeper always reaches a person. Every enforcement decision on this platform is made by a person.

The Keeper now also works through the flagged queue on a schedule our admins set — anywhere from hourly to weekly, or switched off entirely. On each pass it takes a small batch of posts that are already waiting for review and reads each one in full — the whole post together with what our image scan found, rather than matching fragments of a sentence. Then it does exactly one of five things, and nothing else: mark it clear so a post that was fine leaves the queue sooner; route it to support, which moves the post into our support lane and sends the author a warm note instead of a punishment; add the 18+ (NSFW) tag to mature content posted without one, so it simply blurs in feeds while staying up; screen a graphic image behind a tap-to-reveal blur with the words untouched; or escalate it, which pages every admin and deliberately leaves the post in the human queue. It cannot remove, hide, or delete anything. It cannot issue a strike, suspend an account, or reveal who wrote a post. It never reads direct messages at all — though it may deliver one: if you’re not subscribed to update emails, platform maintenance and update announcements arrive as a one-way message from the Keeper. Sending isn’t reading — it drops off the announcement and never sees what you write back. Every decision it makes is written to an admin log and any of them can be undone by a person.

We also auto-tag adult posts NSFW — a lot of people don’t know when to use the tag, so if a post reads as sexual or explicit we add it for you, which keeps that content behind readers’ filters and away from under-18 accounts. This too is context-aware: it weighs the whole sentence, so sex-education, health, medical, and news posts aren’t tagged just for mentioning a word. It’s only a tag, never a block — and you can remove it any timeif it doesn’t apply to your post.

If a post you wrote does get flagged and you try to submit the same content again, we’ll stop it at submit time and show you a small explanation — which categories tripped the scanner, and when it was flagged before — so you can edit and try again instead of wondering what went wrong. Rewording the post or changing what you’re sharing is usually all it takes.

Report categories & the P0 fast-track

When you report something, you can tell us what kind of harm it is. The most dangerous categories — sexual content involving a minor (child safety), non-consensual intimate imagery (NCII), doxxing, swatting threats, and threats of violence — are treated as P0: every moderator is paged to review it right away, every time. The reported post is also hidden from public view (reversibly) when the report is corroborated — by our own safety scanner, by a second independent reporter, or by the reporter’s established track record — so a single false report can’t silence a post; an uncorroborated report still pages every moderator immediately. Stalking, impersonation, and harassment are P1; spam and other reports are P2. A P0 hide is never a hard delete — the author and our team can still see it, and we restore anything reported in error.

There’s also a dedicated name & copyright claim lane: if someone is impersonating a real person, squatting a username to trade on someone else’s identity, or using a name you hold rights to — including a revealed name, a pen name, or a brand — report it under that category and it’s handled at P1, the same urgency as stalking and harassment.

Identity resolution — the standard we hold ourselves to

HuniWhisp is anonymous by design. We will only move to connect content to a real person in three narrow situations: an imminent threat to life, child sexual abuse material, or a lawful legal compulsion (a valid court order or subpoena). We do not de-anonymise users for ordinary rule-breaking, embarrassing posts, or because someone asks.

The same standard travels with your invites: your personal invite link and code never expose your identity beyond your public username — no email, no contact details, no activity history — so sharing an invite never reveals who you are or what you’ve posted.

Every claim maps to a mechanism. We learned the hard way that a safety promise with nothing behind it is worse than no promise at all. So if it’s written on this page, it exists in the product — and we publish updates here when the system changes, so you can hold us to it.

As part of that, public statistics and counts now exclude operator and staff accounts (admins and super-admins). The numbers you see across the site reflect real members — not us padding the room. Operator profiles also stop showing public counts, so nobody mistakes a staff account for an unusually prolific user.

Private messages: encrypted and scanned for safety

Direct messages are encrypted (AES-256-GCM) at rest with a server-held key, and travel over HTTPS — but privacy isn’t a free pass for abuse. The same safety scanner that runs on posts runs on message text server-side. Only if it detects a serious safety pattern is that one message flagged and surfaced to moderators for review, with every such access written to an audit log. For safety, legal compliance, and moderation, authorized staff can review DM content — DMs are not end-to-end encrypted.

What you see depends on what tripped it: predatory or illegal patterns show nothing (so evidence is preserved and an offender isn’t tipped off), self-harm or distress brings up crisis support, and personal-info or scam patterns show a gentle heads-up. It never blocks or delays your message.

Uploaded photos and voice notes are automatically screened

The safety scanner doesn’t stop at text. Photos, voice notes, and audio or video clips you attach to a post pass through an automated media screen after you post. Voice notes and clips are transcribed first, and the transcript runs through the exact same battle-tested scanner as written posts; images are checked by an automated vision system. Both paths may involve AI processing of the media itself — our Privacy Policy spells out precisely what is sent and to whom.

What it looks for

The same fixed pattern set as everywhere else: explicit and violent content, the illegal/imminent-harm bucket (child sexual content, trafficking, credible threats, drug and weapon sales), and scams. It is a safety check, not a taste check — raw, honest, messy media is exactly what HuniWhisp is for.

What happens on each outcome

  • Someone struggling — a voice note that sounds like a cry for help is treated the way we treat written distress: never removed, never punished. We surface crisis resources and route it to Huni Haven so support can find it.
  • Self-harm or blood, non-graphic — an image showing self-harm, fresh wounds, scars, or blood is placed behind a SensitiveGate™ screen: it is blurred for everyone, of any age, and only shows after a deliberate tap — with crisis support right on the screen. The post itself stays up (your words are never hidden); only the graphic image is held back, so a cry for help is still seen and supported, just not splashed across the feed. Blood and gore are scrutinised especially closely — we would rather over-blur an ambiguous wound than surface it.
  • Graphic self-harm — an actively-graphic image (cutting with visible blood, fresh wounds shown explicitly) is the most triggering, most contagious kind, so it is removed from public feeds — but the person is treated as someone who may be in danger: the post is routed to support, a human is paged for a wellness check, and the author gets a supportive notice (not a punishment) explaining why and pointing them to help.
  • Unverified-alert patterns — the media stays up but the post is de-amplified and labelled, same as flagged text.
  • The illegal tier — child sexual content and other illegal or imminently dangerous media is removed automatically, with human review behind every removal and prompt restoration of false positives.
  • Everything else — stays up, and is actioned only if reported, with the scan’s context attached for the reviewer.

A photo and a drawing aren’t the same thing — Huni Depiction Sense™

The screen now asks one more question about every image: is this a photograph, or is it clearly a drawing, render, or game screenshot — anime or manga, 3D or CGI, illustration, painting, comic, obvious digital art? The answer never changes what the scanner found. It changes how certain the scanner has to be before the platform acts on it.

  • Clearly rendered or drawn — we require morecertainty before acting on a weapons or gore finding — nudity gets no such leniency; it is held to the same bar whether drawn or photographed. A rifle in a game screenshot is not a rifle in the room, and we would rather not treat it as one. Classical and fine art is the one exception: a museum statue or a classical painting is not explicit content — unless the post it appears in sexualizes it, in which case the ordinary rules return. That exception never applies to any depiction of a minor.
  • A photograph, or an image we can’t tell apart from one — we require less certainty on a weapons finding, and only that one. A photographed weapon is acted on sooner than a drawn one.
  • Not clear whichnothing changes at all. That is also what happens if the check fails or comes back unreadable: it does nothing rather than guess.

Every one of those adjustments is clamped into the fixed band we seeded for that category in the code — the same band the automatic learning loop is held inside — so a wrong reading can only ever nudge a threshold a little way within limits the platform set in advance. The per-category confidence levels themselves are not set by hand — there is no screen that writes them, and the learning loop is the only thing that touches them.

What it never does

It never blocks or delays your post while scanning — publishing is instant, and the screen runs quietly in the background afterwards. A screening failure never punishes you or removes anything. And no human looks at media that screens clear: a person only ever sees what the system flags or another member reports.

And whether an image looks real never applies to child safety or self-harm, in either direction. A drawn, animated, rendered, or AI-generated sexual depiction of a minor is treated exactly like a photograph of one — being fictional is not a defence here, and it never will be. Self-harm imagery is unmoved too, because what makes it dangerous is what it shows a struggling reader, not how it was made. Hate symbols and scam or phishing images are left exactly where they are as well. The SensitiveGate™ blur is not relaxed by any of this as the app ships: graphic media stays behind its screen whether it was photographed or drawn. To be exact rather than absolute — a setting exists that could relax that screen for clearly-rendered gore or adult art. It is off, and self-harm imagery is excluded from it outright, so even switched on it does not apply to a self-harm finding.

When media is blocked — removal, a strike you can appeal, and evidence that survives

A blocked verdict removes the image everywhere at once — the post it was attached to, galleries, and profiles too: profile pictures and cover images included. A blocked or confirmed media violation records a strike automatically, with a notification stating the reason — appealable like any other strike, and reversed automatically if review finds the system was wrong. And the removed media is not destroyed: it is preserved in encrypted form as evidence, with access restricted and every access logged, for as long as needed to report to and cooperate with the proper authorities — removal never erases the proof of real harm. Self-harm removals stay outside the punitive parts entirely: no strike, ever — they route to support instead. The full commitment is in Terms §16b.

Huni Media Pass™ — asking permission, not getting around the rules

Some people have a real reason to post imagery the screen would otherwise de-amplify. De-amplifying is one flag on the post, and that one flag does four visible things: the post stops being boosted in the feed, it wears an “Unverified” badge on the card, sharing it asks you to think twice first, and it stops unfurling as a link preview off-platform. The post itself stays up and stays readable — the same treatment flagged text gets. So instead of loosening the rules for everyone, you can ask. You explain what you need and why, an administrator reads it, and they either grant it or turn it down.

A group’s owner or admin can ask on the group’s behalf — and you should know what that means before you post in one. A group’s pass applies to every member posting in that group, worked out from the post’s group at the moment the image is screened. That includes members who never asked for it and may not know it is there.

Requesting one — /media-permissions. A pass can only ever cover three things: explicit sexual imagery, graphic violence or gore, and weapons. That list is fixed in the app and checked again every single time the scanner reads a pass, so a pass can never quietly grow to cover anything else. Every grant is scoped to what was asked for and can be revoked at any time. Most carry an expiry, and 180 days is the default — not a ceiling. The administrator deciding it sets the length, up to ten years, and a pass can be left standing with no expiry date at all.

What a pass does not do — the whole list

A pass changes one thing: whether the categories it names raise that de-amplification flag. Because it is one flag, a pass lifts all four of the effects above together, or none of them. Everything below survives it, every time.

  • It never skips the scan. The upload is queued for the same screen and read by it, pass or no pass — the pass is consulted at the very end, after the scan has already found whatever it found.
  • It never lifts the blur. The SensitiveGate™ screen stays exactly where it was — graphic media still sits behind a deliberate tap for everyone.
  • It puts the 18+ tag on. When a pass lets adult imagery through, the platform adds the NSFW tag to the post itself — you don’t have to remember to. The honest limit of that: it establishes the tag, it doesn’t police it afterwards. Editing a post rewrites its tag list, so an author can still take the tag off. Posting adult imagery untagged breaks the Terms, and we act on it when we find it — but the tag is not locked.
  • It cannot touch child safety or self-harm. Child-safety findings, self-harm findings, and the removal of graphic self-harm imagery all act exactly as they do on this page, with or without a pass.
  • It cannot override a refusal or a known-bad match. If our screening provider refuses to process an image, or the image matches the known-bad-image library, a pass makes no difference at all.
  • A member we know to be under 18 never benefits from one — including an account that held a pass and later changed its stated age. A member we know to be under 18 can’t request one either. Both checks turn on the age we actually know: an account that has never told us an age is not treated as a minor here.
  • It hides nothing from the record. The finding is always written into the admin record, and the record names the pass that suppressed it and the categories it covered. It is filed at the seriousness it would have carried without the pass, so it can never sort below the findings we did act on. A pass changes what is done about a finding, never whether it is recorded.
  • It stops the moment we switch the feature off. Turning it off stops every existing pass from applying, at once, without anyone having to revoke them one by one.

If something of yours was screened and you think we simply got it wrong, a pass isn’t the route — say so at /appeals.

Huni Voices — audio posts, same rules, mind your voice 🎙️

Huni Voices is the audio-post category: you record or upload a voice clip, with an optional text caption. Audio posts are moderated exactly like everything else — clips are transcribed and the transcript runs through the same safety scanner as written posts, and the same report tools apply to every audio post and caption.

One honest caution: your voice can be identifying. Anonymous posting hides your username, but it can’t disguise how you sound — someone who knows you may recognise your voice. If anonymity matters to you, don’t say your name, workplace, or other identifying details out loud, and think twice before posting a voice the people around you would know. And never include someone else’s voice in a recording without their consent.

Post covers — built-in gradients, and member-supplied images

When you write a post you can optionally add a cover — a banner that gives it a nicer header. We want this on the record, because it touches image safety. There are two kinds, and the difference between them matters.

Built-in covers — Huni Post Covers™

These are decorative first-party graphics only: a fixed, pre-vetted set of colour gradients built into the app that you choose from a list. Picking one uploads nothing, and a built-in cover can never depict a real photo or a real person — there is no way to put an image of your own into that set. It can never be used to attach or conceal a real image, and it does not bypass any of the image and media safety rules above. At least one gradient in every mood stays free for everyone, on the web and in the apps; the others unlock with Huni Coins. Which gradient you can pick is the only thing that ever changes — never what a cover is allowed to be.

Your own post image as a background

You can also choose to use an image you attached to the post as that post’s background. That choice never weakens safety: a post whose image is flagged as sensitive or that carries the NSFW tag will not render that image as a background — the image stays behind its normal blur and warning screens instead, and the safety rules above apply to it exactly as if it were a regular attachment. A cover is never shown in place of your own picture: if you upload an image, that image is what appears, and it still passes through the automated media screen exactly as described.

Huni Custom Covers™ — premium, and not switched on yet

We have built a premium option that will let paying members supply their own image — including an animated one — as a post cover. It is not available today. Nobody can use it yet: it ships switched off, and it stays off until our image safety screening is fully configured for it. Because a member-supplied cover can show a real photo of a real person, it does not inherit the promise above, so it is built with its own rules — this is how it will work when it is turned on:

  • It is a file, never a link. A custom cover is an image uploaded to HuniWhisp and stored like any other post image, so it inherits the same automated screen, known-bad image matching, blur screens and takedown tools described above. It can never point at something hosted somewhere else.
  • Reviewed before it shows. Your post publishes straight away, but the cover only appears once it clears screening. If the screen fails or can’t read the file, the cover stays pending — it is never approved by default.
  • Never on Huni Haven, never on support or crisis posts. Custom covers are refused outright in Haven and on anything routed to support, where a decorated header has no place.
  • Nothing can strobe or flash. Animated covers are normalised at upload — resized, frame-capped, and held to a minimum time per frame — so a cover cannot be made to flicker at a rate that could hurt a photosensitive reader. It loops a few times and then stops.
  • Feeds stay still. While you scroll, a custom cover shows only as a still image. Animation plays on the post’s own page, and only after the reader taps play. Anyone who has reduce motion turned on always gets the still image, everywhere.
  • Adults only. Setting a custom cover is 18+, and it is refused when we can’t establish a member’s age.

A cover is content like any other: if you think one breaks these rules, use the Report option on the post — it’s on every item’s menu — and pick the category that fits. It reaches the same review queue, and a cover can be taken down exactly like any other image.

Direct messages — the safety scanner runs here too

Direct messages used to be checked only for dangerous links. Now the full safety scanner — the same one we run on posts and comments — runs on every direct message you send. It looks for the same serious pattern set: selling drugs, selling weapons, commercial-sex solicitation, human trafficking, credible threats of violence, signs of self-harm or distress, and predatory advances aimed at minors.

The scan is best-effort and runs in the background — it never blocks you from sending, and it never gets in the way of a normal conversation. To keep your encrypted-at-rest copy safe, the scanner reads the plaintext message before it's encrypted for storage. The plaintext is not retained; only the verdict is. The scanner does not pull benign chit-chat into anything — it triggers only on the fixed pattern set, the same way it does on posts.

And when a message trips a crisis-level flag, trained staff are paged in real time so someone can respond quickly — the page carries only the flag’s category, never the message text, so the content stays sealed unless a full audited safety review is needed.

Sensitive-info notifications — sender and receiver both get told

When a direct message trips a sensitive-information category — for example someone shares a home address, full name + workplace, phone number tied to a real person, or moves into doxxing, swatting risk, blackmail, or a predatory advance — we send a quick warning to both sides of the conversation.

  • The sender gets a notification explaining why sharing that content is risky — for example that the message could be screenshotted and forwarded — and that the message has been flagged for our team to review.
  • The receiver sees a warning banner above the message bubble so they know to read carefully and not share their own personal info in reply.

The message itself isn’t deleted — both people see exactly what was sent — because the warning is the point. If you think the flag was a false alarm, you can keep talking. If you think the other person was trying to harm you, use Report and we’ll review.

Sharing stays private by design — on-platform and off

When you share a post or your anonymous profile, the share is visibility-aware: it carries the item’s privacy state with it, so it can never expose more than the post already shows.

  • Private, group-only, deleted, moderated, or anonymous posts can never generate a public link-preview card or QR code, and an anonymous post never carries your identity to an external app (Huni Visibility-Aware Share™).
  • Your shareable anonymous profile (/u/anon/your-handle) and its QR show only your handle and rough activity counts — never your username, email, avatar, real name, IP, or exact join date — and we keep those pages out of search engines (Huni Profile Share™).
  • Offline reading keeps a few recent public posts only on your device, encrypted, and wipes/refreshes them when you reconnect. Nothing you save offline is stored on our servers.

Messages from HuniWhisp admins — how to know it’s real

Sometimes our team needs to talk to the author of a post — about a report, a moderation decision, or a safety concern. Admins can open a direct conversation with the author of any post, including fully anonymous ones, and two guarantees always hold:

  • Your anonymity is preserved. The conversation never shows the admin your username or profile — to them you are simply the author of that post, and nothing in the thread links back to who you are.
  • The first message always carries an official notice pinned at the top, telling you it is an official message from a HuniWhisp admin about one of your posts and that your identity stays anonymous in the conversation. That notice is your verification: a genuine admin contact always opens with it.

If someone claims to be HuniWhisp staff in an ordinary message without that notice, treat it as impersonation — share nothing and use Report. Our team will never ask for your password, payment details, or personal information in a conversation.

Your money & saved cards are protected 🔒

A few promises about anything money-related on HuniWhisp:

  • Huni Coins are spend-only. They’re an in-app credit for perks and features — not money, with no cash value. The wallet never asks you to “cash out” or request a payout, because there is nothing to pay out.
  • Saved cards: we never see your full card number. If you save a card (on the web), only your card type and last 4 digits are kept. Your full number and security code are read in your own browser and are never sent to us, stored, or logged. What we keep is encrypted and stays inside HuniWhisp — never sold or shared.
  • Purchases are web-only for now. Premium, coin top-ups, and donations are available on the website; in the apps they show “coming soon.”
  • We’ll never DM you for payment details. HuniWhisp staff will never ask for your card number, security code, or password in a message. If someone does, it’s impersonation — share nothing and Report it.

The Anonymous Admin badge — an official voice, identity still anonymous

Sometimes our team needs to say something in public — clarify a rule under a post, calm a heated thread, answer an “is this allowed?” question — without attaching a personal username. When an admin chooses Speak as Anonymous Admin while writing a post or comment, it appears as Anonymous with a small 🛡️ HuniWhisp Admin badge next to it. Here is how to read that badge:

  • The badge is server-verified. Our servers attach only a yes/no “this is an admin voice” flag — never a name, never an account — and they refuse the flag from anyone who isn’t actually an admin. The badge cannot be faked by typing it.
  • It’s opt-in, per post and per comment. Admins are community members too — their own personal anonymous confessions are not badged, because their personal anonymity matters as much as yours. The badge appears only when an admin deliberately chose to speak officially.
  • No badge means not official. If someone merely claims to be HuniWhisp staff in plain text — in a post, a comment, or a DM without the official admin-conversation notice — treat it as impersonation: share nothing and use Report.

Typing indicators — a count, never a name

On a post’s comment section, you may see “someone is typing a comment…” when another viewer is composing one at that moment — the same live hint you know from direct messages. We want the anonymity guarantee behind it on the record: the indicator only ever shows a count. No username, no profile, no draft text — and the signal is momentary, not stored. Until someone actually presses send, nothing they typed exists anywhere.

Safety scanner that learns from review

When a moderator confirms a flagged post was genuinely dangerous — or marks one as a false alarm — that decision is captured into a small dataset we use to improve the scanner over time. The dataset records the category, a short excerpt of what was written, which pattern matched, and which of HuniWhisp’s supported languages the content was in — but never anything that re-identifies a member. The goal is fewer false alarms, fewer missed real ones, and better coverage as the platform grows into new languages.

We record this in plain language so you know it’s happening: admin reviews feed improvements to the scanner. No individual is identified; the value is in the pattern, not in the person.

What Huni Keeper™ may do on its own. The same review record is what the Keeper learns from, and it now works the flagged queue on a schedule our admins set, reading each waiting post in full — words and images together, and flagged comments with their whole conversation so sarcasm and quoting are not mistaken for violations. Its whole vocabulary is five moves: clear a post so it leaves the queue, route it to support with a kind note to the author, add the 18+ tag to untagged mature content, screen graphic media behind a tap-to-reveal blur, or escalate it to every admin and leave it in human hands. It never removes, hides, or deletes content, never issues a strike or suspension, never unmasks an author, and never reads direct messages — the only thing it ever does in a DM inbox is deliver a one-way platform announcement (see above), and it never reads replies. Everything it does is logged and reversible by a person. If you think it got your post wrong, say so at /appeals.

Organization submissions — double-layer safety on the queue

When a verified school, club, or organization runs an anonymous-submission inbox on its HuniWhisp space, the submissions members send in pass through two safety layers before they can ever be published. The point is to make sure the people running the queue — usually a student officer, club lead, or community organizer — never have to wade through the worst of it.

Layer 1 — pre-publication scan, before the inbox

The same scanner that runs on every post and comment runs on every submission the moment it’s sent. If the submission hits the illegal-or-imminently-dangerous bucket — child sexual content or grooming, human trafficking, terrorism planning, credible threats of violence, selling drugs, selling weapons, or solicitation of commercial sex — the submission is refused at submit time and never reaches the organization’s inbox. The submitter sees an explanation. The organization’s admins never see the content.

Layer 2 — the moderation assistant next to every pending submission

Submissions that pass the pre-publication scan land in the inbox with a colour-coded verdict from the moderation assistant attached:

  • Green — clean approve. The scanner flagged nothing concerning. One tap publishes.
  • Amber — approve with an edit. The scanner flagged something borderline (a link that needs trimming, a soft personal-info share). The assistant says exactly what it caught so the admin can fix it before publishing.
  • Red — reject. The scanner caught something the admin will almost certainly want to reject (heavy harassment, doxxing, hate). The rejection reason is pre-filled with the scanner’s verdict so the admin doesn’t have to write one from scratch.
  • Escalate — the assistant detected an active-threat pattern and asks the admin to escalate to HuniWhisp’s safety team instead of acting on it alone.

The organization’s admin always makes the final call. The assistant is a suggestion engine, not a gatekeeper — an admin can approve over an amber verdict, reject over a green one, or escalate at any point. Every approve, reject, and escalate decision is written to the platform’s admin audit trail with the target tagged as an organization submission, so the record is there if anyone needs to look back.

What the admin does next becomes part of how the scanner learns. Approved-with-edit notes and reject reasons feed the same safety-learning surface described above — so every careful decision an organization admin makes helps every other organization on the platform get safer pending queues over time.

Biometric sign-in — your fingerprint or face never leaves your device

On supported devices you can choose to sign in with fingerprint or face unlock (Touch ID, Face ID, or Windows Hello) instead of typing your password. We want the privacy guarantee on the record: your biometrics never leave your device. Your phone or computer’s own secure hardware checks your fingerprint or face and simply signs a one-time challenge; HuniWhisp only ever receives and stores a public key — never your fingerprint, never your face, never anything that could reconstruct them.

Those keys live in an isolated, encrypted, access-audited vault kept separate from the rest of your account. Biometric sign-in is off by default and opt-in, it never replaces two-factor authentication, and you can remove an enrolled device at any time from your dashboard. (Voice sign-in is experimental and not enabled.)

What staff can — and can’t — see

For safety, moderation, and lawful emergency response, HuniWhisp staff (admins and super-admins) can review content across the platform — including spaces you might reasonably assume are sealed off. We’d rather you hear that plainly from us than discover it. The trade-off we make is simple: broad oversight is allowed, but every use of it is logged, and a short list of things stays off-limits to us by design.

What an admin can access — always written to the audit log

  • Private and organization groups — a member-only or unverified-org space can be viewed by staff without joining it, so there is no walled room we cannot check.
  • Private diaries and their entries — a diary you marked private is still readable by staff for safety review.
  • Direct messages — DMs are encrypted at rest with a server-held key (not end-to-end), so for safety, legal compliance, and moderation they can be decrypted and read by staff.
  • Your posts, stories, and comments — public or removed, staff can see them for the moderation and audit picture.

Each of these accesses writes a tamper-evident row to our admin audit log — which staff member, when, what they opened, and from where — so oversight is accountable and never silent.

The walls we will not cross

  • The Authority Evidence Vault — server-blind once you finalize. Admins get in only if you opt in, and then only through the five-gate, you-are-notified path described just below.
  • Private Huni Mirrors — your reflective past-self / present-self space is not surfaced to staff.
  • Organization anonymous salary & survey data — submitted under an anonymity promise to members; staff do not de-anonymize it.

This shape — broad audited oversight paired with a short, named set of cryptographic and policy no-go zones — is a HuniWhisp™ proprietary mechanic; the rights claim is recorded in Terms §28.

Authority Evidence Vault — compile a report and lock it with keys only the right people hold

If something has happened to you or someone close to you and you want to take it to the police, a cybercrime unit, a domestic-violence agency, NCMEC, a school safety office, or a mental-health crisis service, HuniWhisp gives you a private place to compile, encrypt, and carry the evidence to whoever needs to receive it. The Vault is a tool you control — we are not the messenger, and we never get to read what you put inside it after you lock it.

How it works

  • You start a draft and pick the authority category, the recipient’s name (free text), and the jurisdiction. You can write your own narrative timeline — who, when, where, what happened — and attach images, audio, video, PDFs, or written statements as evidence.
  • You pick how the bundle will be unlocked: a printable QR code, a biometric tied to your device or the recipient’s device (Touch ID, Face ID, Windows Hello via WebAuthn’s PRF extension), a passphrase, or any combination of those with a Shamir N-of-K threshold — for example “QR and biometric required” or “2 of 3 of QR, biometric, passphrase.”
  • When you tap finalize, your browser generates a random AES-256-GCM master key, encrypts every evidence file and the narrative, wraps the key with each unlock method you registered (or splits it via Shamir), and sends only the wrapped envelope to our servers. The plaintext key is wiped from memory. After finalize we do not hold, see, or have any way to recover the key.
  • You can download the encrypted bundle (a .huniwhisp-report file) and carry it to the authority in whatever way you choose — in person, by upload to their intake portal, by courier, or via a one-time share link. The downloaded copy is yours and is not affected by our retention window.
  • The recipient opens the unlock page, presents the QR / biometric / passphrase the way you agreed, and the bundle is reconstructed and decrypted entirely in their browser. Our servers serve the encrypted bytes — they never see the decrypted contents.

What we promise and what we can’t

We promise to keep the Vault server-blind after finalize, to write a tamper-evident audit log of every action taken against your report (creation, evidence added, finalize, download, unlock attempt, hand-over, expiration), and to hold a finalized report for 365 days before it expires. We can’t promise that an authority will read your report, accept it as evidence in court, or act on it — that decision is theirs, and chain-of-custody and admissibility rules vary by jurisdiction. If your report is serious, please also talk to a lawyer.

What we won’t allow

The Vault is for compiling evidence for a relevant authority. It is not for compiling or distributing child sexual abuse material (please report CSAM directly to NCMEC’s CyberTipline at CyberTipline.org or 1-800-843-5678 in the US, or your local INHOPE hotline elsewhere — do not upload such material here), non-consensual intimate imagery, doxxing dossiers, blackmail material, or anything else listed in Terms §28e clause (f). We also can’t recover your report if every unlock token you registered is later lost — that’s the whole point of the design, and it’s why we tell you to keep at least one token (or a Shamir threshold combination of tokens) safe.

The full contract for the Vault lives in Terms §28e, and the proprietary-rights claim over the multi-method-unlock + Shamir-combination + server-blind design is recorded in Terms §28c clause (o).

Vault admin oversight — opt-in only, with five gates and a notification to you every time

Every finalized authority report is also archived in our admin dashboard so super-admins can investigate abuse and respond to lawful emergencies. We want to be honest about what that archive can and can’t do, because it’s a meaningful trade-off and the choice is yours to make.

The opt-in toggle at finalize

At finalize you see a single toggle: “Allow HuniWhisp admins to recover this report’s contents in an emergency.” It is off by default. If you leave it off, our admins can see only metadata about your report — status, recipient category, finalize date, evidence count, and the audit log — and have no technical path to read the contents. If you turn it on, your browser also generates an extra Shamir share of the master key and wraps it to an offline super-admin keypair (the private key is not on any HuniWhisp server or database). That wrapped share is the only door into the contents from the admin side. The toggle is irreversible once you finalize — the only way to revoke admin access after the fact is to delete the report.

The five gates an admin has to clear before reading

  • Super-admin role + 2FA elevation on the account — the standard admin floor.
  • A separate admin-archive passphrase re-entered once per session, distinct from the login password and stored only as a salted PBKDF2-SHA256 hash.
  • WebAuthn biometric step-up immediately before any read — a Touch ID, Face ID, or hardware-key prompt with userVerification: required.
  • A free-text reason for access typed in at open time and recorded verbatim in the access log alongside the admin’s identity, the IP-hash, and the timestamp.
  • A 5-opens-per-24-hour rate cap per admin. Beyond five, the admin has to go through the force-open path, which only executes once a second super-admin with a distinct identity co-signs with their own reason.

Decryption happens in the admin’s browser, not on our servers

Even when an admin clears the five gates, the offline private key never travels to our servers. The admin pastes the offline private key into the browser, the wrapped share is unwrapped client-side, and the master key is reconstructed and the contents decrypted entirely in the admin’s browser. The server’s job is to hand over the encrypted bytes and log the access — nothing more.

You get notified every time, and peer admins see it too

Every contents-open emails you at the address on file. The email includes the date and time, the reason text the admin typed in, the super-admin tier of the accessing admin (not their username), and a link back to your report and its audit trail. In parallel, the access log is exposed to all other super-admins as a real-time peer-oversight feed — so any abuse of admin access is visible to the whole super-admin group as it happens, not just after the fact.

The full rules for the opt-in, the five gates, the force-open co-sign, and the reporter notification live in Terms §28e clauses (j)–(m), and the proprietary-rights claim covers this admin-archive layer too — see Terms §28c clause (o).

Admin-invited accounts — first-login password reset

Sometimes a member can’t self-register because of a bounced email, a regional sign-up issue, or because they need a hand getting onto the platform. A super-admin can manually create the account from the admin tools and email the new member a temporary password. As soon as that member first logs in, we force them through a password reset — they can’t use any other part of the app until they pick a new password of their own. The temporary password becomes unusable after that first reset.

This is also the same path used when an existing member contacts support locked out and needs a temporary password issued. Either way, the temporary password is single-use and the forced-reset flow keeps strangers from holding onto a working credential.

Links and videos in comments — safer to skim

Comments often carry links, and a link from a stranger is the single most common way someone gets hurt on a social platform. HuniWhisp adds a few quiet protections so a comment feed stays easy to skim without handing trust over to whoever posted last.

  • Safety badge on every link. When a URL appears in a comment, we scan it at the moment it’s written and attach a small badge — safe, suspicious, or dangerous — right on the link chip. The verdict is stored with the comment so the badge is there even if you read the conversation days later. You decide whether to tap.
  • Auto-linkified URLs. A bare URL in a comment turns into a tappable chip with the safety badge attached — you don’t have to copy-paste or guess where it leads. Chips carry no tracking parameters and never auto-load remote scripts.
  • YouTube videos start silent. If a link points at a YouTube video, we embed the player inline but show a poster image with the sound off. A small play with sound gate stands between you and any audio — so a stranger’s video can never blast at you while you’re scrolling. There’s also a Don’t play path that keeps the poster visible if you don’t want to load the video at all.
  • Repeat scammers get paused. If a single account writes several dangerous-verdict links in a 24-hour window, we quietly flag the account for our team to review — a soft pause on a small number of repeat offenders so the rest of the community keeps seeing safer comments.

Misinformation — we inform, we don’t censor

An anonymous platform lives or dies on trust, so HuniWhisp ships a full toolkit for weighing what you read — and a firm rule behind all of it: every signal is context placed next to content, never a reason to remove it. Nothing in this toolkit deletes a post, edits an author’s words, or decides what you’re allowed to read. And none of it is HuniWhisp claiming to have fact-checked anything — community signals are labelled as community, curated signals as curated, automated signals as automated.

  • Credibility voting & the consensus bar. Readers vote every eligible post Believable, Plausible, or Made Up. The post page shows the full meter and timeline; feed cards show a compact three-color consensus bar once a post has at least 5 votes, so a couple of early votes or a coordinated pile-on can’t paint a misleading picture. It’s crowd sentiment, not a verdict.
  • Community notes & pinned reader context. Anyone can attach a context note (ideally with a source) and readers rate notes helpful or not. A note that earns the community’s trust is pinned directly under the post so the context travels with it — chosen entirely by reader ratings, never by staff.
  • Source check on shared links. Links to outside sites can carry a small curated chip rating the publication — Reliable, Mixed, Low, Satire, or User-generated — from a hand-maintained list informed by public media-reliability research. Domains we haven’t curated show nothing: no chip means “we don’t know,” never “this is fine.”
  • Proof chips on media. Authors can mark an attached photo, video, or clip as their proof — receipts for the story. The chip means “marked by the poster,” not “verified by HuniWhisp” — weigh it with everything else.
  • A heads-up before sharing. If a post is flagged unverified by our safety system, or the community has voted it heavily Made Up (10+ votes, 60%+), the share sheet pauses for one tap to tell you so before the post leaves the platform. It never blocks the share — the choice is always yours.
  • Unverified posts lose amplification, not their voice. When automated checks flag a fast-spreading, uncorroborated claim, the post gets a visible “unverified” badge and the feed simply stops boosting it while the community catches up. The post stays up, readable, and votable — de-amplification is the ranker’s job; deletion is nobody’s.

What a misinformation report does. You can still report a post as misinformation — the option is right there in the report menu. Under the rule above, that report routes the post for review and feeds the context toolkit (the unverified-badge review and the signals described here); it does not remove the post, because being wrong is never, by itself, a removal reason. The exception is deliberate, coordinated manipulation, which is actioned as abuse.

The full methodology — every signal, who sets it, and what it never does — is published in the Truth & Trust guide. Deliberate, coordinated manipulation of these signals (vote brigading, note spam) violates the Terms and is actioned like any other abuse.

Moderation powers — hard deletes for unambiguous spam

We want to be straight with you about one thing: for content that is clearly spam — scams, ad-spam, mass-posted junk — our moderators can permanently delete the post and everything attached to it (its reactions, comments, bookmarks, tags, and votes) without sending the author a notification. Nothing recoverable, no appeal email.

This is reserved for unambiguous spam, not for ordinary rule-breaking. Removals for harassment, hate, violations of these guidelines, and other normal moderation still come with a notification you can reply to and appeal — that part hasn’t changed. We’re telling you about the silent-delete path so you know it exists; you should never see it used on a genuine post.

Sealed posts (Violation Lock™). Some content removed for a violation doesn’t just vanish — it stays where it was, sealed. Visitors see a plain cover naming only the general class of the violation (harassment, explicit content, sharing personal information); the removed title, text, and media never leave our servers, so there is nothing under the cover to peek at. Content connected to self-harm or crisis is never sealed — that’s a safety matter, not a punishment. The removal behind a seal is appealable in the Appeals Center like any other, and a successful appeal lifts the seal. The full clause is in the Terms, Section 16c.

One more thing, stated generally on purpose: as a safety measure we may limit the reach or visibility of an account’s interactions, without notice, where that’s judged necessary for members’ safety (Terms, Section 16).

Shoutouts — public recognition, same rules apply

A shoutout is a short, public message of positive recognition you can send to a post, another member, a group, or the whole community. They show up in a “Shoutouts” rail and roll off on their own after a while. They’re meant to lift people up — so they follow exactly the same rules as everything else here.

  • Shoutouts are public content and must comply with all of these community guidelines. Using a shoutout to harass, demean, spam, impersonate, or amplify abuse is not allowed and is actioned the same way as any other rule-breaking content — including strikes, suspension, or a ban under the Terms.
  • Member-created shoutouts are limited to email-verified accounts, and each member can only have a few active at a time — a light cap that keeps the rail from being spammed.
  • Auto-shoutouts are platform-generated, not written by a person: when a post or a reply catches fire (earns a strong reaction-based heat tag), the system can mint one automatically to celebrate it. An auto-shoutout is a signal that content is resonating — it does not imply endorsement by HuniWhisp, and like every shoutout it expires on its own.

Huni Habits — gentle by design, never a guilt-trip

Huni Habits lets you name a personal habit and keep a private streak with a one-tap daily check-in. It’s built to encourage, not pressure. Your habits and streaks are private to you; the only thing others ever see is an anonymous count of how many people are working on a similar kind of habit, plus optional one-way “rooting for you” cheers that carry no names and can’t be replied to.

  • A broken streak is a fresh start, not a failure. If you miss a day, Huni Habits resets gently and meets you with compassion — there are no shaming nudges, loss-aversion pressure, or guilt mechanics.
  • It’s a reflective keepsake, not professional care. Huni Habits is for self-encouragement and reflection only. It is not therapy, medical, psychological, or any other professional advice. If a habit touches on something you’re struggling with, please use the support resources below.
  • For members under 18, Huni Habits follows our reduced-messaging, youth-safety posture (see the Terms, Section 12a).

Payments are live — what that means for your wallet

Real-money top-ups and purchases are now enabled — through PayPal on the web, and as one-time Huni Coin packs via Apple In-App Purchase (iOS app) and Google Play Billing (Android app) — so you can fund your wallet and pay for Premium. We’ll never ask for your password or full payment details inside a conversation — payment always happens in the secure checkout flow, and the exact amount is shown before you confirm. Withdrawing a balance back out to a bank account isn’t offered yet. See the Terms (Sections 10 and 10a) for the details.

HuniWhisp will never ask you to pay outside the app’s official checkout. Topping up your wallet only ever happens through the in-app flow — the secure App Store purchase sheet in the iOS app, the Google Play purchase sheet in the Android app, or PayPal on the website. If anyone — in a DM, comment, or email — asks you to send money another way (gift cards, bank transfer, crypto, a link to an outside “payment page”) to get coins, premium, or a reveal, it’s a scam: don’t pay, and use Report.

What isn’t allowed

These are removed when reported (and some are removed automatically):

  • Illegal / imminent danger (removed automatically + escalated): child sexual content or grooming, human trafficking, terrorism, credible imminent threats of violence, selling drugs, selling weapons, and solicitation of commercial sex. Talking about any of these topics in a confession, story, or diary is fine — setting up the deal itself is what’s blocked.
  • Encouraging self-harm: telling, pressuring, or daring anyone to hurt or kill themselves; sharing methods, instructions, or graphic depictions of self-harm or suicide. (Expressing your own pain is always okay — this is about content aimed at harming others.)
  • Violence: threats of violence, or glorifying, celebrating, or encouraging violence against anyone.
  • Harassment, bullying & persecution: targeting, threatening, intimidating, or relentlessly attacking a specific person, or persecuting someone for who they are.
  • Doxxing: posting private identifying information about someone without consent.
  • Intimate images shared without consent (NCII): posting — or threatening to post — someone’s intimate images without their consent. This is removed on sight, ends the account, and is referred to authorities where the law requires. If it happened to you, report it under “Intimate images shared without consent” — it’s treated as P0, every time.
  • Hate: dehumanising or inciting harm against people for who they are.
  • Disrespecting religion: insulting, demoralising, mocking, or hateful content toward any religion, religious text, or believers. (Respectfully discussing or reviewing a religious work is always welcome — this is about content meant to belittle.)
  • Scams, fraud, and spam.
  • Begging or money solicitation: directly asking other members for money, donations, handouts, or gifts — dropping a payment handle (Cash App, Venmo, PayPal, Zelle, a $cashtag), a fundraiser link, or “send me money” / “gift me” messages. (Venting about money troubles or hardship is always welcome — this is only about soliciting funds. If you want to support someone, use the built-in Support button.)

Four things end an account immediately, on the first time. Almost everything here works in steps — a warning, then a removal, then a suspension. These do not: child sexual exploitation, grooming a minor, predatory sexual advances, and sexual content aimed at or shared around underage members. One confirmed incident is a permanent ban, whatever your history. There is no warning step.

And if you are the one it happened to, none of that applies to you. Telling your own story, reporting someone else, or quoting what a predator said so we can act on it is never treated as doing the thing. We detect these categories partly from language — and survivors use the same words to describe what was done to them. So before any account is removed under the rule above, the content is checked for exactly that: a disclosure, a report, someone speaking about a third person. If it looks like one, the removal is stopped and a person reads it instead. You never have to weigh your safety against telling the truth here.

Keeping each space true to itself

A few main categories are special spaces, so they have light guardrails to stay meaningful. The default is conversion, not deletion — posts that don’t fit are converted to a regular post and labelled as such (a diary that converts is closed once its entries become posts). The one exception is Bookworms, below.

  • Huni Diaries are ongoing personal journals. A real diary should keep going — at least 3 entries. If a diary hasn’t reached 3 entries within 14 days, it becomes a regular post.
  • Aspirations & Goals track a real goal over time and should show progress. An aspiration with no progress within 14 days becomes a regular post.
  • Huni Stories should be an actual story with some substance. Very short posts are published as regular posts instead.
  • Huni Bookworms is strictly for books — reviews of or chats about a book or anything book-related, including religious books like the Quran or the Bible. Posts that aren’t about a book may be reclassified by a moderator or, if they fit nowhere, removed with notice — the one lane where removal is possible.

If you’re struggling, you’re not alone

Posts about self-harm or distress are never removed or punished for being a cry for help.They stay in the feed and also appear in Huni Haven — an opt-in support space where people vent and support each other, with these resources pinned:

To make sure these posts are seen with the right tone, our safety scanner now automatically routes posts that show signs of self-harm or deep distress into Huni Haven the moment they’re submitted. Nothing is removed, edited, hidden, or punished — the post stays exactly as written, the author stays the same, and it still lives on your profile. It just appears inside a supportive space rather than mixed into the general feed. Inside Haven, viewers see a Support Post banner with quick-pick supportive comment templates, so a kind, helpful reply is one tap away. When commenting on a post like this, that panel also offers a one-tap button to drop a crisis-support link into your reply — and crisis resources are always available, whether or not you’re signed in. If a post was routed in error, contact us and we’ll review it.

When you share something heavy, we answer with support — and quiet the confetti. If your post is routed to support, what you hear from us next is help: crisis resources, and sometimes a one-way supportive message from Huni Keeper — clearly labeled, expecting nothing back. For a couple of days we also pause the celebratory pings — badge fanfare, promo offers, streak cheers — because a party horn is the wrong sound in a hard moment. Anything you earn during that time still lands quietly on your account; only the celebration ping is skipped — what you earned shows on your profile and account as usual. We never announce any of this, it never appears on your profile, and none of it is visible to anyone else.

If you need someone right now

Two quiet ways to get help fast

Anywhere we show crisis resources — beside a post about distress, and pinned at the top of Huni Haven — you’ll find two one-tap tools. The local hotlines and emergency number shown are chosen from your approximate region only; we never use your location to contact or dispatch anyone.

  • Quick exit — a small “× Quick exit” button instantly sends you to a neutral website and leaves the page out of your back-button history, so you can hide the screen fast if you need to. It’s always there, even when you’re not signed in.
  • A quiet alert to someone you trust — save one trusted person’s email, then send them a calm, one-tap check-in request. It goes only to the person you chose — never the police, and never an automatic dispatch — and you can optionally include your approximate, city-level location so they can reach you. The email is stored encrypted, and you can edit or remove the contact at any time. If you’re in immediate danger, please call your local emergency number — HuniWhisp can’t contact emergency services for you.

Protecting younger members

We ask every member for an age group when they join (it’s private and never shown to anyone). This lets us give younger members a safer experience — some features and personalisation are limited or turned off for under-18s, and we never target them with anything beyond the core, honest product. If you’re under 18, please also have a parent or guardian’s okay to be here.

Younger members & messaging

Direct messaging on HuniWhisp is age-partitioned. Members under 18 can only message other members under 18 — adults can’t message minors, and minors can’t message adults. It’s a hard age boundary enforced on our servers, so a grown-up and a minor simply can’t start a private conversation with each other in the first place.

Because that boundary only works if we know which side someone is on, messaging needs both people to have declared an age group. If yours isn’t set, private messages stay closed until you pick one — one tap in Settings, and only a range, never a birthday or a document. We’d rather pause a conversation than guess someone’s age wrong, because guessing is unsafe in both directions: guess “adult” and a teenager becomes reachable by grown-ups; guess “minor” and an adult slips into spaces meant for teenagers. For the same reason, 18+ posts require at least an age range on your account: with no age set they are withheld entirely on our servers — not just blurred — and under-18 accounts never receive them at all. A recently raised age keeps 18+ areas closed for a short waiting period, so flipping an age never unlocks anything on the spot.

This sits on top of everything else that keeps messages safe: the automated safety scanner (including grooming detection) runs on every message, and you can block or report anyone at any time. It works because ages stay accurate — every member has an age group, and providing an optional exact date of birth (kept private, never shown) keeps that current, so your age group updates on its own the day you turn 18.

The slur filter & platform sweeps

Hate has no home here, and it doesn’t get to hide behind clever spelling. Our slur filter is obfuscation-resistant and multilingual: it sees through symbol swaps (n!…), look-alike letters from other alphabets, accents, stretched-out spelling, and spacing tricks — and it covers slurs written in non-Latin scripts too. It runs where names and words live: usernames, display names, bios, posts, comments, and direct messages. It’s precision-tuned to full slur forms, so ordinary names and words don’t get caught in it.

Alongside report-driven moderation, we also run platform sweeps — scheduled and moderator-initiated passes that re-check existing content and identity fields against the rules. When a sweep finds a violation: the content is actioned, a strike may be recorded, and the member is told why and can appeal. A rule-breaking username gets replaced with a neutral, friendly auto-generated one (you can pick a new compliant name afterwards).

Two honesty mechanics come with this. “Also known as”: your recent former usernames can appear on your profile so no one escapes their reputation by renaming — but a former name that was itself abusive is never displayed publicly (moderators only). And if we get it wrong, we make it right: a mistaken sweep action is reverted — content restored, the strike voided, and an apology sent — and the mistake is added to the filter’s allowlist so it doesn’t happen again.

Momentary Hunis — they really do disappear, and here is the one copy we keep ⏳

A Momentary Huni is a post on a timer you set. When the timer ends it is removed from the platform — it leaves the posts table outright rather than being hidden behind a filter, and no member, including the person who wrote it, can see or recover it again. Its reactions, comments, shares and bookmarks go with it.

We are going to be straight with you about the exception, because you deserve to hear it from us rather than find it out. A format designed to vanish is the most attractive place on any platform to test what moderation will accept — post something, see whether anyone stops it, and let the clock erase the evidence. So an encrypted copy of every Momentary Huni is made when it is published and kept for 30 days, then deleted for good. We take it at publication rather than at expiry on purpose: an account probing our limits deletes the post itself long before the timer runs out.

What that copy is, and what it is not. It is used only to investigate and act on abuse, to handle reports and appeals, to comply with the law, and to put an expired post back up if you ask us to — which returns it under the same anonymity you posted it with. Apart from a restore like that, it is never shown to another member, and it feeds nothing else on this platform — no feed, no search, no profile, no recommendations, no advertising, no analytics, no data export. Only moderators can open one, and every single opening is recorded against that moderator’s name together with the reason they typed, so the power is watched rather than trusted. The deletion date is written onto each copy the moment it is made, which means we cannot quietly extend the window for a post that was already written under it. This is set out in Terms §23 and Privacy §6.

Offline reading — encrypted, temporary, purged on reconnect

If you turn on the optional offline reading setting (off by default, in Dashboard > Settings), HuniWhisp saves a small number of recent public posts on your own device — you pick how many — so a dropped connection still leaves you something to read in a clearly marked, read-only “Saved for offline” section. Anything stored on a device is a risk to be contained, so the cache is deliberately boxed in:

  • Encrypted on your device. Saved posts are encrypted at rest with AES-GCM using your browser’s own WebCrypto — they never sit on the device in readable form.
  • Strictly temporary. Every cached copy hard-expires after 24 hours, even if the device stays offline the whole time. Expired copies become unreadable.
  • Purged the moment you reconnect. When the device comes back online, the entire cache is deleted and replaced with a fresh copy — nothing stale or compromised lingers.
  • Public posts only. Momentary Hunis (self-destructing posts), private-group posts, and direct messages are never cached — nothing sensitive can end up on the device in the first place.

Because the setting is off by default, nothing is ever saved unless you chose it — and switching it off clears the cache.

Your region — optional, self-declared, never your exact location

HuniWhisp never collects your precise location — no GPS, no addresses, no tracking. If you want a region on your profile, you tell us yourself: an optional country (plus a state and city if you choose) you can set at signup or any time in Account › Edit Profile, and clear whenever you like. The defaults are deliberately conservative — only your country can show publicly by default, and state and city stay private until you switch them on in Account › Privacy. What other people see is enforced on our servers, not just hidden in the page.

One thing you might spot: a brief, dismissible 🌍 notice can appear if you’re on a VPN with no saved region — it simply explains that recommendations follow where your connection appears to come from. Informational only; nothing is blocked, limited, or tracked because of it.

If you’re being bullied or targeted

No one should be bullied, harassed, intimidated, or persecuted here. Threats of violence, glorifying or encouraging violence, bullying, harassment, and persecution are not allowed — they’re removed when reported, and the person responsible faces strikes, suspension, or a ban under our strike policy.

If someone is doing this to you, you don’t have to put up with it. Use Report on the post, comment, or profile, and Block them so they can’t reach you — blocking is now enforced both ways in direct messages, so a blocked account can’t message you and the conversation simply can’t continue. First contact from someone who isn’t your friend now arrives as a message request you can accept, decline, or report — strangers can’t open a conversation without your consent. You can also vent and find peer support in Huni Haven. We’re on your side.

Harassment Shield™ — one tap when a pile-on starts 🛡️

When several accounts gang up on you at once, blocking and reporting them one by one is exhausting at exactly the moment you shouldn’t have to be. The Harassment Shield™ turns the work you’ve already done into one protective action: open the shield from your profile page, under Settings → Security, and activate it. Activation gathers the accounts you have already blocked, or already reported for harassment, in the last 30 days (up to a fixed maximum per activation) and handles them together.

  • Blocked in bulk. Every account it gathers is blocked for you in one action — enforced both ways, so none of them can reach you in DMs.
  • Reports file themselves. A moderation report is automatically filed against each of those accounts, so our team reviews the incident without you having to file each one by hand.
  • Your shield list. Those accounts go on your shield list — a record of your own protective action, not a platform verdict on anyone. While the Shield is on, anyone you block afterwards joins the list automatically, so you keep extending it just by blocking. You can remove your own entries at any time.
  • An announcement, on your terms. Activation prepares a short announcement you can release whenever you choose — or never. Releasing needs the Shield switched on, you can have one live announcement at a time (releasing again replaces the previous one), and there’s a short cooldown between releases. The text is checked by our safety scanner when you save it and again when you release it — illegal content is refused — then it’s published as a shoutout, so you get to say your piece when you’re ready.

One honest caveat: the Shield doesn’t work out who is piling on for you. It never adds an account you haven’t blocked or reported yourself — if you haven’t blocked anyone yet, it has nothing to gather. The Shield is for people being piled on — using it to defame or retaliate against someone is itself a violation. The full rules live in the Terms §14d.

Reporting & appeals

We have zero tolerance for objectionable content and abusive users. We review reports of objectionable content and abusive behaviour within 24 hours — removing what breaks the rules and ejecting (suspending or permanently banning) users where the violation warrants it, up to and including permanent bans. Lesser violations move through the strike system in the Terms (Section 16), so the response always fits the violation.

  • See something that breaks these rules? Use the Report option on any post, comment, profile, or message — it’s on every item’s menu.
  • You can block any user from their profile or post menu — blocking removes their content from your view immediately and flags the account to our team.
  • You can delete your own posts at any time from the post’s menu — they’re removed from the feed immediately.
  • Prefer email? Reach our safety team at safety@huniwhisp.com.
  • Reports are reviewed by our team; we act on what genuinely breaks the rules and dismiss the rest.
  • Honest reports never carry consequences, even when we conclude no rule was broken. Repeated knowingly false or harassing reports are different: they can pause a member’s ordinary reporting for a period. And no restriction ever blocks the gravest lanes — child-safety, intimate-image-abuse, doxxing, swatting, stalking, and threat reports are always accepted, from every account.
  • If your post is removed, you’ll get a notification explaining why — and you can answer back. Mistakes happen, and we restore posts we got wrong.
  • Repeated or serious violations can lead to limits on your account, suspension, or a ban (see the Terms, Sections 16–17).

The Appeals Center — /appeals. Four things can be appealed there, and each one carries a status you can check — pending, then granted or denied — so you are not left guessing where it stands:

  • A strike on your account.
  • Something of yours that was removed, blurred, or hidden by moderation — a post, a comment, or a diary entry.
  • A group action taken against you inside a group.
  • A block by another member — see the honest caveat below.

You get one appeal per action. An appeal is a reply, not a channel, so make it count: tell us what we misread. Strike, removal, and group appeals go to our admin queue and come back with a short note — our 24-hour commitment covers them like any other safety work.

Block appeals are deliberately different. Yours goes as one short, quiet message to the person who blocked you. They can unblock you or simply ignore it, and you will never be told which — nor can you send another. A block appeal therefore shows as Sent forever, never granted and never denied. That is not us being unhelpful: telling you whether a block appeal was opened would hand anyone a way to check whether the person who asked them to stop is still reading. The right to be left alone wins.

Every appeal is checked by our safety scanner before it is stored — including as the guard that stops the block-appeal form becoming one more message to someone who blocked you — and then stored encrypted, the same way direct messages are. Appealing an account ban still uses the ban-appeal flow you already know; /appeals links you straight to it.

Huni Amends™ — the open floor, and the way back 🌱

Huni Amends is two things at once, and the first one matters most because it is the one most people are here for: it is the open floor, where any adult member in good standing can bring a hard or controversial subject and have it talked through instead of shouted about — having done nothing wrong at all. It is also the way back, the one door that stays open for a member banned or striked for hate conduct. So being in Huni Amends — or wearing the tag or the 🗯️ marker that comes with a post there — is never a finding against anyone. It says which room the post is in, and nothing else.

On the second half: some lines here are hard ones — hate speech, slurs, hateful conduct. Crossing them earns strikes and bans, and that doesn’t change. But we don’t believe a person’s worst moment has to be the end of their story, so alongside the formal appeal there is a second, slower path back, and it runs through this same room.

  • One door stays open. A member banned or striked for hate conduct can still post and comment in the Huni Amends category — there and only there — to reflect on what happened and show the community who they are now. Everywhere else, the ban is the ban.
  • Posts are never anonymous. Posts in Amends always carry the author’s handle. A vouch is for a person; reflection under a mask isn’t accountability. That includes posts moved into Amends: an anonymous post transferred here — by an admin decision or a community vote reaching its threshold — shows its author’s username from the moment it arrives, with notice to the author (the accountability de-anonymization every member accepts at sign-up — Terms §7c).
  • The community vouches. Members in good standing — zero strikes, no bans — can vouch for someone doing the work. When enough vouches gather, the case goes to our team for reinstatement review with the community’s backing attached.
  • A human always decides. Vouches open the door for review; they never lift a ban or strike by themselves. Reinstatement is a person’s judgement, every time — the same rule every enforcement decision on this platform follows.
  • Honors, both directions. When someone makes it back, they earn a visible honor for the journey — and so does everyone who stood up for them.
  • A door with requirements. A member with a strike, ban, or other violation on their account needs at least an age range selected (the Age page under account settings) before they can post or reply in Amends — only the bracket is stored, and the protections tied to age work honestly inside this space like everywhere else. And since the open floor arrived, the whole space sits behind the age-and-acceptance gate described below — for everyone.

The open floor, in detail. Alongside the way back, Huni Amends hosts civil discussion of controversial topics — racism, hate, the subjects that are usually shouted about instead of talked through. The rule that makes it possible: heavy subjects are discussed, never directed — the moment words target a person or a group, that isn’t discussion any more. Posting on the open floor takes an account in good standing — no live ban and no active strike standing, and a cleared or successfully appealed strike reopens it. The way back is the deliberate exception: that door exists precisely for members who do carry a record. The community can vote to suggest a post belongs in Amends, but a vote never moves anything: a human makes every transfer decision. An anonymous post can be moved there, and moving it reveals the author’s username on that post — posts in Amends are never anonymous, because reflection behind a mask isn’t accountability. (Comments follow the platform’s normal anonymity rules, with one exception: a commenter carrying an active sanction replies under their username.) The author is told plainly when it happens, and it is only ever a person’s decision, never a vote’s (Terms §7c).

Honesty about the door. We used to say everyone can read and reply in Amends. That stopped being true the day the open floor arrived, so here is the gate, stated plainly: a space this rowdy is entered by choice, at a known age, with the rules accepted. You can see Huni Amends only if your account shows you are 16 or older — an adult age bracket, or an under-18 bracket with a birth year showing 16–17 — and you have accepted the space’s terms, which say up front that content inside can be offensive and rowdy. If we can’t be sure you’re 16+, the space stays hidden — the gate fails closed on purpose. Members aged 16–17 are read-only: welcome to read, not yet able to post, comment, or vote.

  • The floor never bends. Harassment, targeting people or groups, threats, violence, or anything that endangers someone is removed and actioned in Amends exactly as it would be anywhere else. The latitude is in the topics, never the conduct.
  • Reports pool at a threshold. Because rowdy spaces generate rowdy reports, a report filed inside Amends surfaces for review once enough members have flagged the same thing — except the grave categories (sexual content involving a minor / child safety, intimate-image abuse, doxxing, threats of violence, swatting), which reach us immediately, every time, with no threshold.
  • Active voices get closer review, not a longer leash. The more you participate in Amends, the more attention your participation gets. That’s deliberate.

If you’re inside, you’re part of what makes both halves real — hold people to honesty, be generous with those doing the work, and keep hard subjects civil. Participation never guarantees reinstatement, and the zero-tolerance rules (Section 4a of the Terms) apply inside Amends too: reflection and honest discussion are welcome; repeating the conduct is not. Can’t see the category? The FAQ walks through every reason and its fix.

If something happens to a loved one 🤍

When a HuniWhisp member dies, becomes incapacitated, or is caught up in legal proceedings, the people who love them are sometimes left with questions — or with a quiet account they need help closing. We’ve built a private, careful path for family, guardians, and authorities to ask for what they need without compromising the privacy of the person behind the account.

Start a request at /legal-requests. Everything you upload is encrypted at rest, and you’ll get a private status token so you can check back on progress.

  • Deceased — access: next of kin requesting the account’s content. Needs a government photo ID, a death certificate, and proof of kinship.
  • Deceased — closure: close and soft-delete the account; an encrypted archive is retained per our privacy policy. Needs a government photo ID and a death certificate.
  • Guardianship: a legal guardian acting on behalf of a member. Needs a government photo ID and the guardianship court order.
  • Court order: a court has ordered access to specific account information. Needs a government photo ID and the court order itself.

We aim to respond within 14 days for routine requests and within 7 days for verified emergencies. Questions can go to privacy@huniwhisp.com.

Lawful requests from authorities

HuniWhisp is built on pseudonymity, and we take that seriously. We do not volunteer user information to law enforcement, governments, or private parties absent a valid legal order or a narrow imminent-harm exception — that’s a written commitment in our Terms §7. When we do receive lawful process, we review it carefully, comply with what is legally compelled, and push back on overbroad demands.

Authorities can submit court orders, subpoenas, search warrants, and law-enforcement investigation requests through /legal-requests. Each submission requires a government photo ID and the underlying legal instrument (subpoena, warrant, court order, or credentials + agency letterhead for investigations), plus a declaration under penalty of perjury. Documents are encrypted at rest (AES-256-GCM), as is requester PII.

Standard turnaround is 14 days, up to 30 days for complex matters. Verified emergency requests involving imminent threat to life are triaged within 7 days. Direct questions to privacy@huniwhisp.com.

Games — playful, safe, and skill-based 🎲

The Huni Games Room (at /games) — Six-Word Whisps, Two Truths, One Lie, Riddle at Dusk, and The Caption Circle — is built to be fun and safe. Here’s how we keep it that way:

  • Skill and social, never gambling. These are games of skill and participation — writing, guessing, voting, captioning. You never bet, stake, or risk money, and there is no game of chance.
  • Free to play. Playing always costs nothing. Wins and streaks earn badges and achievements.
  • Coin prizes are 18+. Some wins grant a small, daily-capped coin prize to your wallet. Any coin payout is limited to members 18 and over. Coins are a virtual balance with no cash value.
  • Everything you submit is safety-scanned. Your six words, captions, statements, and guesses pass through the same automated safety screening and moderation as posts — nothing skips the line.
  • Under-18 protections. Younger members can still play and enjoy the games; the youth-safety posture that applies elsewhere on HuniWhisp applies here too, and coin payouts are off the table for under-18s.
  • Anti-farm. Coin rewards are rate-limited, daily-capped, and one-per-game-per-day, and automated, banned, and staff accounts are excluded from prizes and leaderboards. Trying to farm rewards (multi-accounting, automation, collusion) can cost you those rewards.

Advertising safety 📣

Ads on HuniWhisp come through Huni Ads, our self-serve platform at /advertise. Every campaign and its creative is reviewed by our team before it can run, and ads must follow the same content rules as the rest of the platform. We never target or knowingly show ads to members under 18. If you see an ad that breaks the rules — misleading, harmful, or inappropriate — you can report it the same way you’d report any content, and we’ll review it.

Our safety system is still being tuned to better serve everyone here. If something feels wrong, tell us — it helps us get it right. In an emergency, call your local emergency number (911, 999, 112, 000) or go to your nearest emergency room. These guidelines are written in English; translations are best-effort and the English version prevails (Terms §26).