Child Safety Policy
Effective: May 7, 2026
Hypastack has zero tolerance for child sexual abuse material (CSAM). This is not negotiable.
My Position
Any content that sexually exploits or endangers children will be removed immediately upon discovery or report. The associated account will be terminated. All available information will be reported to NCMEC (National Center for Missing & Exploited Children) and relevant law enforcement.
What I Can Provide to Authorities
For files uploaded through the website, my zero-knowledge architecture limits the data I can provide to:
- The hashed nickname associated with the account
- The encrypted nickname blob
- Account creation timestamp
- Last activity timestamp
- File metadata (encrypted filename, size, upload time)
- The file content itself (before deletion)
CDN assets and files uploaded through the developer API are not encrypted. For those, I can provide the content itself in readable form, and I will do so when lawfully required.
In no case do I have email addresses, IP addresses, or real identities. I am transparent about this limitation. It is a consequence of the account model and the zero-knowledge pipeline, not an attempt to shield abusers.
Prevention Measures
- Dangerous file types (executables, scripts) are strictly blocked for CDN uploads
- File type verification checks magic bytes, not just extensions
- Rate limits prevent mass-upload abuse
- CAPTCHA verification on uploads (Cloudflare Turnstile)
- Temporary files auto-expire within 1–7 days
- Inactive accounts are purged after 7 days
For encrypted file shares, I cannot proactively scan contents — I rely on reports and the technical barriers above. CDN asset uploads are not encrypted and will be subject to client-side content scanning in a future update.
Age Requirements
Minimum age to use Hypastack: 18. I cannot verify age because I do not collect identity information. If I learn a user is underage, I delete the account.
Reporting
If you encounter CSAM or any content that endangers children, send the file URL (without any #... fragment) via https://t.me/t_usekiko. I will act within 24 hours.
Do not send me the decryption key. I will not ask for it. Receiving and decrypting content to verify a CSAM report creates direct legal liability for me. I do not and will not do this.
Do not screenshot or preserve CSAM. Simply send me the URL so I can delete the file immediately, and report it directly to the NCMEC CyberTipline. That is all I need from you.
