hiyaTermsSign in

Privacy Policy

Last updated 26 September 2026 · Applies to hiya and every page published on it

The short version. Signing in with Discord tells us your Discord ID, username and avatar — not your email address, not your servers, not your messages. We store the page you build, the images you upload, and a small amount of technical data used to stop abuse.

There are no analytics scripts, no advertising and no trackers on hiya or on the pages it publishes. We don't sell anything to anyone. You can delete all of it yourself, whenever you like.

Contents
  1. Who's responsible
  2. What we collect
  3. Cookies
  4. Why we use it
  5. What's public
  6. How long we keep things
  7. Who else is involved
  8. When we share information
  9. Your rights and choices
  10. Security
  11. Children
  12. Where your data is
  13. Changes to this policy
  14. Contact and complaints

1. Who's responsible

hiya operates hiya from South Africa and is the party responsible for the personal information described here — the “responsible party” under South Africa's POPIA, and the “controller” if the UK or EU GDPR applies to you.

Reach us at support@hiya.page for anything in this policy.

2. What we collect

From Discord, when you sign in

We ask Discord for the identify scope only. That gives us four things:

  • your Discord user ID (a number, which is how we recognise you);
  • your Discord username;
  • your Discord display name, used as a starting suggestion;
  • the web address of your Discord avatar image.

We do not receive your email address, your password, your phone number, the servers you're in, your friends or any of your messages. We never post anything as you. We keep the short-lived Discord access token only for the few seconds it takes to read those four fields, and never store it.

What you give us

  • the username you choose, and any previous ones you've released;
  • everything on your page: headings, text, links, colours, emoji, section layout — both the published version and your unpublished draft;
  • images you upload (banner, project images, icons, tab icon), with their file size, type and dimensions;
  • the content of any report you send us about someone else's page.

Your page is a free-text space, so what ends up in it is up to you. Please don't put anything sensitive in there — health information, ID or card numbers, your home address — that you wouldn't want on a public web page, because that's exactly what a published page is.

Collected automatically

  • Your IP address, used two ways: as part of a short-lived counter that stops someone brute-forcing invite codes or flooding uploads, and recorded against certain administrative actions in our internal audit log.
  • Server logs. Our web server records requests in the ordinary way — address, time, path, status, user agent — which is what lets us diagnose faults and spot attacks.
  • Page view counts. When someone opens a published page we add one to a daily total for that page. We store a number per page per day and nothing about the visitor — no IP, no cookie, no fingerprint, no idea who they were. We don't count the page owner viewing their own page.
  • Timestamps — when your account was created, last signed in, and last changed.
  • Who invited you, and which code you used.

3. Cookies

We use three cookies, all strictly necessary, all first-party. There is no advertising or analytics cookie, so there's no consent banner to click through.

CookieWhat it's forHow long
hiya_sessionKeeps you signed in. Contains your account ID and a session number, signed so it can't be edited, and marked HttpOnly so page scripts can't read it.30 days
hiya_pendingHolds your Discord identity between signing in and redeeming an invite, so the signup step doesn't send you back through Discord.30 minutes
hiya_oauth_stateA one-time random value that proves the sign-in coming back from Discord is the one you started. Deleted as soon as it's checked.Seconds

Published pages set no cookies of their own. Clearing your cookies signs you out and nothing else.

4. Why we use it

What forUsingLawful basis (GDPR)
Signing you in and knowing who you areDiscord ID, session cookiePerformance of our agreement with you
Storing and publishing your pagePage content, drafts, uploads, usernamePerformance of our agreement with you
Showing you how many people visitedDaily view totalsPerformance of our agreement with you
Stopping abuse, spam and brute-force attemptsIP address, rate-limit counters, server logsOur legitimate interest in a service that works
Handling reports and moderating contentReport details, page content, account recordsOur legitimate interest in keeping people safe; legal obligation where one applies
Keeping staff accountable for admin actionsAudit log, including staff username and IPOur legitimate interest in accountability and security
Responding to a lawful request or defending a claimWhatever is relevant and necessaryLegal obligation, or our legitimate interest

We don't use your information to build a profile of you, to make automated decisions with legal effects, or to advertise anything.

5. What's public

Assume these are visible to anyone on the internet:

  • your username, because it's the address of your page;
  • everything on your page once you publish it, including any image you upload to it;
  • the display name and avatar you choose to show on it.

These are not public:

  • your Discord ID;
  • your unpublished drafts and version history;
  • your view counts;
  • who invited you, and how many invites you have left;
  • anything in our server logs or audit log.

Search engines can index a published page, and anyone can archive or screenshot it. Unpublishing removes it from us but can't remove copies other people or services already made.

6. How long we keep things

WhatKept for
Your account and its settingsUntil you delete the account
Your page, your draft and your uploaded imagesUntil you remove them, or until you delete the account — files are erased from the server's disk, not just hidden
Version historyThe most recent ~20 published versions; older ones are pruned automatically
Released usernamesAbout 30 days, so nobody can take your old handle and impersonate you
Daily view countsIndefinitely — they're a number per page per day and contain nothing about visitors
Rate-limit counters (which include an IP address)Minutes to an hour, then deleted automatically by the database
Server request logsRotated by the server, typically a couple of weeks
Moderation reports and decisionsKept after they're resolved, as the record of what was decided and why
Audit log of administrative actionsKept long-term for security and accountability. Entries can include a username, a Discord ID and an IP address, and survive the deletion of the account they refer to
Record that an invite code was redeemedKept after account deletion, so the chain of who invited whom stays intact

Backups of the database may hold copies for a short period after deletion before they're overwritten in the normal cycle.

7. Who else is involved

Running the service means a few other companies necessarily see some data. We don't give any of them your information to use for their own purposes.

  • Discord — handles signing in. Discord knows you authorised hiya, and your use of Discord is governed by their own privacy policy. Avatar images are loaded straight from Discord's CDN, so your browser contacts Discord when one is displayed.
  • Google Fonts — the site's typeface (Inter) is loaded from Google's servers, which means your browser reveals your IP address to Google when a page loads. We don't receive anything back from them.
  • Our hosting provider — the server that stores the database and your uploaded images is rented from a hosting company, whose staff could technically access the machine.
  • Cloudflare — manages DNS for hiya.page, and may sit in front of traffic to it.

There is no analytics provider, no advertising network, no email marketing platform and no data broker in that list, and we have no plans to add one.

8. When we share information

We don't sell your personal information, ever. We disclose it only when:

  • you published it yourself, in which case it's already public;
  • we're required to by a valid legal process, or by law in South Africa;
  • we believe in good faith that someone is at risk of serious harm, or a serious crime is involved — child sexual abuse material is always reported;
  • it's needed to investigate abuse of the platform, or to establish or defend a legal claim;
  • you've asked us to. When someone complains about copyright, we tell the page owner what was removed and who complained, because they need that to respond.

If hiya were ever transferred to someone else, we'd tell you before your information moved, and this policy would keep applying until you were given a new one.

9. Your rights and choices

Wherever you live, you can ask us to do the following, and most of it you can do yourself right now:

  • See what we hold. Most of it is in your dashboard already. Email us for the rest and we'll send you a copy.
  • Correct it. Your page, display name and username are all editable by you.
  • Delete it. Account settings → delete account. That erases your account, page, drafts, version history and image files. The exceptions are in section 6: audit entries, resolved moderation records and the fact that an invite code was used.
  • Take it offline without deleting. Unpublish from the editor and only you can see your page.
  • Object to a use we've justified by legitimate interest, or ask us to restrict it while we look at your objection.
  • Get it in a portable form — ask and we'll send your page content as a data file.
  • Withdraw Discord's authorisation at any time from your Discord settings, under authorised apps. Note that this stops you signing in, but doesn't itself delete your hiya account.

Email support@hiya.page. We'll reply within 30 days. We may need to confirm you control the Discord account in question before acting, so that nobody can delete someone else's page by asking nicely.

10. Security

  • We never handle your password. Discord does the authenticating, so there is no password of yours for us to lose.
  • Everything is served over HTTPS. Session cookies are signed, HttpOnly and Secure, so page scripts can't read them and a tampered cookie is rejected.
  • Suspending an account invalidates its existing sign-ins immediately rather than waiting for the cookie to expire.
  • Uploads are checked by inspecting the file's actual contents, not by trusting its name, and SVGs containing scripts are refused.
  • The database listens only on the server itself and requires authentication; it isn't reachable from the internet.
  • Page content is escaped when rendered, so one member can't inject code into another's browser.

None of that makes any system perfectly secure. If something does go wrong in a way that puts you at risk, we'll tell you and the Information Regulator (South Africa) as the law requires.

11. Children

hiya isn't for anyone under 13, and we don't knowingly collect information from children. If you believe a child under that age has an account, email us and we'll remove it. Where a child's local law sets a higher age for consenting to online services, that age applies instead.

12. Where your data is

The database and your uploaded images live on a single rented server. Because Discord, Google and Cloudflare operate globally, some processing necessarily happens outside South Africa — including in the United States. Where the GDPR applies to you, those transfers rely on the mechanisms those providers put in place, such as the European Commission's standard contractual clauses.

13. Changes to this policy

If we change what we collect or what we do with it, we'll update this page and the date at the top. For a change that materially affects you we'll give notice on the site before it takes effect.

14. Contact and complaints

Email support@hiya.page with any question or request about your information, and please say what you'd like us to do.

If you're not happy with how we've handled it, you can complain to the Information Regulator (South Africa), or to the data-protection authority where you live.

The rules for using the service are in our Terms of Service.

hiya© 2026
TermsPrivacyDiscord