Privacy Policy
Email verification (commenting, editing a review, feedback, and optionally reviews)
Commenting, editing a review, and sending feedback all require verifying a one-time code sent to your email -- this stops one person from posting many times under different names, not to build a mailing list. Writing a review is the one exception: verifying is optional there, offered as a way to earn a Verified badge and enter our Starbucks gift card draw, not a requirement to submit at all (see the next section for what happens if you skip it). Whenever email verification does happen, your address is used only to send and check that code. What actually gets attached to whatever you submitted afterward is only a one-way SHA-256 hash of it, so we can enforce “one submission per building per person” without your submitted content ever being traceable back to your address -- that hash can't be reversed back into an email. To be fully upfront: the underlying verification record (created just to send and check the code) doesn't yet have an automatic deletion process, so it isn't purged within minutes the way an earlier version of this page said -- that's something we're actively working on tightening. It's never linked to, or published alongside, anything you submit.
Reviews submitted without email verification
If you submit a review without verifying your email, we hash your IP address (one-way, the same SHA-256 pattern as above -- the raw IP is never stored) and attach that hash instead. It's used for exactly one thing: stopping a second unverified review for the same building from the same device. It's never linked to anything you submit, never shown anywhere, and never shared with any third party.
“I manage this building” claims and reports
These are different: a building-management claim asks for your name, phone, and email directly (not hashed), and a report can optionally include a contact email -- because a moderator may need to actually reach you to verify or follow up. This information is only used for that review process and is never published on the site or shared with anyone else.
Content you submit
Reviews, comments, and building suggestions are held for manual approval before they ever appear publicly -- see About & Methodology for how that works. Anything you submit that gets published is shown alongside your declared reviewer type (e.g. “Tenant, Family”) and, for reviews, the year range you lived there -- never your name or email.
Analytics, and no ads
Xposay uses Vercel Analytics for basic, cookieless page-view tracking (which pages get visited, roughly how much traffic the site gets) -- it doesn't use advertising or marketing scripts, doesn't set tracking cookies, and we don't sell or share any data with advertisers. Aggregated review content and photos shown on building pages come from Google's Places API, fetched server-side and displayed per Google's attribution requirements -- your browser never calls Google directly or shares anything with it.
Saved buildings
Tapping the bookmark icon on a building saves it to a list stored in your browser's local storage -- there's no account, and this list is never stored on our servers. Opening the Saved page briefly sends that list of building IDs to our server just to look up each building's current info; we don't log or retain that list ourselves. Clearing your browser's site data, or switching browsers or devices, will lose it.
Flatmate listings and expressing interest
Posting a Flatmates listing requires the same email-OTP verification as elsewhere, but this feature handles your email differently from everywhere else on the site: every other verified flow only ever keeps a one-way hash of your email, since nothing needs to contact you again afterward. A Flatmates listing is the one exception -- we keep your actual email address (not just a hash of it) for as long as the listing stays open, because expressing interest in your room, potentially weeks later, requires being able to reach you. A hash of it is kept alongside purely to enforce the cap on how many listings you can have open at once and to power “manage my listing.”
Posting a listing, and expressing interest in someone else's, both require your age, profession, and LinkedIn profile URL -- these are mandatory fields on both sides, not optional. All three are self-reported and are never verified by Xposay (your LinkedIn URL is only checked for looking like a real profile link, e.g. rejecting a company page or an unrelated URL by mistake -- that is not the same as confirming the profile is real or belongs to you). Use your own judgment before making plans to meet anyone through this board. None of these three -- nor your email -- is ever shown publicly on a listing; a listing's public card only shows post type, rent band, your stated gender, and who you're looking for, which is shown publicly and filterable by design, since the whole point of this board is to be browsed and filtered.
Expressing interest is a two-way exchange, both sides verified email-OTP first: the poster receives the interested person's verified email, age, profession, and LinkedIn URL, and the interested person receives the poster's same four details back in a confirmation email. Nothing here is broadcast publicly or shared with anyone besides the one specific matched counterparty. There's no in-app messaging -- once those emails are sent, the two of you take it from there directly.
