Privacy
Control without unnecessary exposure
MitraSetu follows a privacy-by-design approach: collect and expose only what is needed for platform functionality, account security, and responsible safety.
Who can see your profile
Profile visibility can be PRIVATE, CONNECTIONS, or PLATFORM. PLATFORM means authenticated MitraSetu users—not the unrestricted public internet. Blocking applies in both directions to social visibility.
Discovery and connections
Username discovery is optional and off by default. Discovery respects profile visibility, active-account status, and blocks. Connection-request policy is separately controlled and defaults to the most restrictive option.
Sessions and devices
Security records use privacy-minimized device and session information needed to recognize sessions and revoke access. The interface does not display raw authentication tokens, IP addresses, internal session IDs, device IDs, or fingerprints.
Notifications and safety records
Notifications contain narrow relationship events and redact or suppress actors when current privacy rules require it. Security events and tamper-evident audit records support platform integrity but are not publicly exposed; audit hashes and internal security details are never shown in member interfaces.
The current implementation does not add analytics, advertising trackers, behavioral fingerprinting, contact scraping, or location collection.