Laces.Social
Privacy at Laces
Laces is built around private intentions and mutual relationships. There is no people search or public directory.
Your account
Your account stores your username, display name, language preference and authentication information. Passwords are stored as hashes. Your username cannot be changed in this version.
Verified email addresses and phone numbers
Verifying a contact proves that you control it. It does not publish the contact, enable people search or make it a login credential. Contact values are protected on the server and shown as masks in your account.
Email and SMS are used exclusively for contact-verification security codes. When a channel is available, its delivery provider processes the destination and code. Laces does not send social activity, invitations, recommendations or campaigns by email or SMS.
Private intentions
An intention stores the identifier you enter, including when it is not associated with an account. The acknowledgement does not reveal whether another account exists or has sent an intention. Active intentions do not expire automatically. A verified email or phone is resolved to its current owner; verifying it again may allow existing valid intentions to form a Lace. You can silently withdraw your own intention.
Laces and shared content
Two valid reciprocal intentions form a Lace automatically. Authorized participants can access posts and comments according to the current relationship. Ending a Lace revokes that access immediately and creates a persistent notification inside Laces for the other participant, identifying who ended it. No email, SMS or push notification is sent for the break.
Controls and data lifecycle
In Settings you can manage your display name, language and contacts. Removing a contact removes its recoverable value and mask from the operational database and invalidates its verification codes. It does not end existing Laces or erase another person's intentions.
Verification codes expire and become unusable after consumption or invalidation. Minimal verification-attempt records are retained for 48 hours to prevent abuse, including after a contact is removed, with hourly cleanup. Operational removal does not mean immediate erasure of backups.