dumpbox.ai
Back to home
Safety first

Every precaution we take,one by one.

This isn't a statement of intent: it's the list of what is already in the software, how it's built and why we built it that way. At the bottom is the part nobody usually writes — what we still don't do.

You don't have a password, so we can't lose it

There is no password field on Dumpbox. You get in with Google, with Apple, or with a code sent to your email: three routes that all end in a signed session, and none of the three ever puts a secret word of yours in our hands.

This isn't a shortcut. A password store is the most valuable thing a small site can hold and also the thing it holds worst: if we don't have one, there is nothing to steal, nothing you may have reused elsewhere, nothing to change in a hurry on the day of bad news.

The only password in the product is the optional one you can put on a shared link. What stays on the server is not the text but a fingerprint with salt in front of it, and the comparison happens on the server: the value never reaches the browser of whoever is trying to get in.

  • No sign-in password: not stored, not transmitted, nothing to recover.
  • The session lives in a fourteen-day httpOnly cookie: no script can read it, not even ours.
  • The whole site over HTTPS only, declared to the browser as mandatory for a year.

The data we don't have

What we collect is written out in full in the privacy notice, and it fits in a few lines: email, name, username, the photos you upload. But the list that really matters is the opposite one.

We don't ask for your phone number to sign up. We don't read your contacts. We don't know where you are while you use the site. We don't buy data about you from anyone, and we don't sell yours to anyone.

We can't even ask for your camera and microphone: we switch them off at browser level with a header that goes out on every single response from the site. It isn't a promise we ask you to believe, it's a line you can read yourself in your browser's developer tools.

  • Permissions-Policy: camera=(), microphone=(), payment=() — on every page.
  • No other site can frame Dumpbox inside itself: the pages refuse to sit in a frame.
  • Links that are themselves a key go out with no-referrer: that address reaches nobody, not even as the origin of a font request.

A photo's location is never an address

Photos taken with a phone often carry a GPS position accurate to a few metres. On public content that number is not «a place»: it's somebody's home.

When we read the date a photo was taken, the GPS block is switched off on purpose. The one function that does read it rounds it to two decimals — about a kilometre — before it even returns it: the exact point exists nowhere in the software, not for an instant and not in memory. Then we show it to you as a suggestion, and it only ends up in the gallery if you confirm it.

The same rounding is applied again on the server, to the value that arrives. On precision we don't trust the browser — not even our own.

  • Two decimals: about 1.1 km. Enough to spread pins across a map, not enough to find a front door.

What a guest uploads stays invisible until you approve it

Whoever scans the QR uploads without an account, from the browser, with nothing to install. The file lands in a waiting area that can be written to but not read: not by that guest, not by another guest, not by someone who guessed the exact address of the file. The photos appear when the gallery's owner approves them.

On the way in we look at the file's actual bytes, not its name and not what the browser claims. The accepted formats are a closed list, and image types that can carry executable code are not on it.

A contribution link isn't forever: you can protect it with a password, give it an expiry, or stop accepting uploads. And when you delete your account, every link and QR of yours stops working in the same moment.

  • Guest contributions are write-only: the person uploading can't even read back their own file.
  • The rules deciding who reads what live on the server, not in the page: changing browser doesn't change permissions.

If you say no, we stay on counting

Before your choice not one request goes out: it isn't «less data», it's zero — and we're not saying it from memory, it was verified on the real site, with a clean browser, watching the network traffic. What changes is what happens next, and the two paths really are different.

If you say yes, there are four tools and the cookie policy lists them one by one. If you say no, counting is all that is left: no cookie written or read, no identifier, ads are not personalised, and every event has everything stripped from it except its name. What goes out is «somebody signed up», never who — and that subtraction is not a matter of principle: without it your username, and even other people's, would go out with it.

We will not tell you it is «completely anonymous», because one honest line is worth more than a reassuring one: to count, a request to Google does go out, and like every request on the web it carries your IP address and the browser you use. That we cannot make disappear. What we can do, and do, is attach nothing else to it.

The banner doesn't greet you in the face: it waits until you've seen what Dumpbox is, so people who pass through and leave never see it at all. The two buttons are exactly the same width, because refusing can't cost more than accepting, and «Ignore» is final: it doesn't come back to ask next time.

You can change your choice whenever you like from the cookie policy, and a withdrawal takes effect the instant you make it — not from the next page load.

  • Before your choice: zero requests to third parties, neither measurement nor advertising.
  • If you refuse: no cookie, no identifier, and only the bare name of each event goes out.
  • Consent is withdrawn on the same page where you read what each tool does.

When there's AI, we say so

There are generated images on the site, and they are one thing only: the covers of some of the galleries published by our own official account, the ones that fill the public pages until there are enough real photos. They are not photographs of an evening out: they are illustrations. The rule governing them isn't «no faces», it's no resemblance to a real person — an invented face laughing is fine, a close-up of whoever is on stage is not.

Your photos, on the other hand, never pass through a model. We don't use them to train anything and we don't use them for our own advertising: the licence you give us in the Terms covers hosting them and showing them to whoever you choose, and it stops there.

The story image isn't generated either. It's your photo recomposed with text on a canvas drawn inside your browser, on your device: nothing leaves for any third party to make it.

  • Generated images exist only on our official account's galleries, never on yours.
  • No content uploaded by people is used to train models, ours or anyone else's.

If something goes wrong, there's a queue and there's a deadline

Every photo, comment, gallery or profile can be reported from inside the page in two taps, choosing among nine reasons. Whoever published it never sees who reported it — and whoever reports doesn't have to write to any address to do it.

The written promise is that a person looks within twenty-four hours. It isn't a slogan on a wall: it's a single number inside the code, and it does two jobs at once — it draws the time you see and it orders the queue, with overdue reports at the top. That way a late one can't hide at the bottom of the list.

And leaving is as quick as arriving: you delete your account yourself from Settings, immediately, and it takes galleries, photos, videos, comments and links with it. There is no cooling-off period, and we say so beforehand instead of letting you find out after.

  • Nine reporting reasons, from copyright to self-harm, with no email to write.
  • Twenty-four hours is the commitment window, and it's the same number that orders the moderation queue.

What we still don't do

We don't put a label next to each generated image. The declaration is this page and the Terms, not a caption under the picture — and that's a choice, not an oversight: those images live only on our own account's galleries, they depict no real person, and they are never passed off as the photograph of an evening that actually happened. The day AI reached the place where people's own photos live, that caption would become mandatory — and this line would change before it did.

We don't look at photos before they're uploaded. There is no automatic filter deciding in your place, and that cuts both ways: nobody reads your content for sport, but wrong content is taken down after a report, not before.

There is no security review yet by anyone who isn't us. Dumpbox is a sole proprietorship, in beta: the infrastructure is Google's and Cloudflare's, the code is ours and for now we review it ourselves. The day that changes, this line changes too.

If you find a problem, write to privacy@dumpbox.ai. A person answers, not a form.

The same things, in a lawyer's words