This page is about what happens under a photograph: who hears what you say, who is named on it, and what is taken back when somebody is removed or blocked. The rule for comments is the thing in people you know most likely to catch out somebody who has used any other app, so it comes first.

All of it lives on one screen. A row in the feed carries no comments, no count and no field to write in; tapping the row opens the post, and the post is where the conversation is.

Who hears a comment

Call somebody’s circle that person plus everybody they are connected to. You hear a comment if its author is in both circles: yours, and the circle of whoever’s photograph it is.

Two things follow at once, and they are not exceptions to the rule—they are the “themselves” half of each circle. You always hear what you wrote. You always hear the person whose post it is.

Worked through. Ana posts a photograph to thirty of her mutuals. Bruno and Carla are both in that audience and have never met.

  • Carla writes a comment. Ana hears it, because it is her photograph. Carla hears herself.
  • Bruno does not hear it. Carla is in Ana’s circle but not in Bruno’s, and the rule needs both.
  • Dan is in the audience too and knows Carla. Dan hears her: she is in his circle and in Ana’s.
  • Months later Bruno and Carla connect. The next time Bruno opens the post, Carla’s comment is there, including the one she wrote back then. The rule is asked afresh every time comments are fetched, and never frozen at the moment they were written.

None of this is announced. There is no line under the comment field telling you who will hear you, and nobody is told that a comment was hidden from them. On an ordinary post the surprise runs in the safe direction: fewer people read what you wrote than you assumed, never more. An album works the other way round, and the section after next says how. This page is where the sentence goes instead, because reading it is something you chose to do, and being told about it while you are trying to say something to a friend is not.

Why it works that way

The audience of a post belongs to whoever made it, not to whoever is reading it. Everybody in Ana’s audience is a stranger to somebody else in it. A comment list with no rule over it hands Bruno the handle of a person he could not have searched for and whose profile he cannot open—and a handle is how somebody is found here, which is why search is exact-match and rationed.

It is one of the two things that took out the viewer list. Nobody is told who looked at a post, and a comment list was that hole sitting one screen away, defended by nothing except that nobody had said it out loud. The fix available here was better than removal: comments stay, and what goes is the part of them that crosses an edge nobody has.

Inside an album, everybody hears everybody

For a photograph contributed to an album, both halves of the rule ask a different question: not “is this person your mutual” but “is this person in the album”. So a co-member you have never met hears you, and you hear them.

An album is one room. Its membership is its audience, its members can read each other’s names off the album’s own screen, and whoever contributes a photograph wraps its key for every member with no edge in sight. Asking about mutuals there would hide most of a shared album’s conversation from most of the people sharing it, which is the opposite of what an album is for.

One visible consequence. On an ordinary post everybody you hear is you, the poster, or one of your own mutuals, so your phone holds the name you have for them: their display name if they have set one, their handle if not. In an album, a co-member you have no connection to is shown under their handle, because that is all your phone has.

Removing somebody reaches backwards

Both halves of the rule are checked on every read, and the half that looks redundant is the half with teeth. Somebody had to be in the audience to write anything at all, so “connected to the poster” is true at the moment the words are typed. It only starts doing work later.

When Ana removes Carla, Carla goes quiet under Ana’s ordinary posts. For everybody: for readers who still know Carla perfectly well, and for Ana too. It applies to what Carla wrote a year ago exactly as it applies to this morning. It is the answer to “I removed him ages ago, why is he still talking under my photographs”. A contribution of Ana’s to an album somebody else made is the exception, because there the rule asks about membership, and removing somebody does not take them out of a third person’s room.

Nothing is deleted by that, and if Ana adds Carla back her comments are audible again. Removing somebody does destroy the keys between the two of you, so an ordinary post of Ana’s stops opening for Carla altogether.

Blocking deletes the words

A block is not a stronger filter. It is a deletion, and it runs both ways at once: every reaction either of you left on the other’s posts is deleted, and every comment either of you left on the other’s posts is taken down. Unblocking brings none of it back.

The reasoning is that after a block neither person can reach the other’s posts again, so a comment left on one is a comment its own author can never delete—and words you cannot take back are words you did not agree to keep. A removal is undone by adding somebody back; a block is a door closing.

A block also takes every delivery between the two of you, album photographs included, so it reaches into a room a third person made. A removal does not.

Two other things end a conversation. Deleting your account takes your comments down and removes your reactions, in the one transaction that destroys your keys. Deleting a post for everyone destroys every copy of that post’s key, so its comments stop opening at the same instant the photographs do.

The one revocation that is a filter

This is worth saying plainly, because everywhere else in this app taking something back means destroying a key rather than setting a flag. A comment is sealed under the post’s own key, and everybody the post reached already holds that key. So what the rule above changes is who the server is willing to show the words to, never who could open them.

The alternative is worse. Sealing each comment to the intersection would mean telling the writer’s phone which of their friends also know the poster: disclosing a graph in order to hide one, and up to 128 wrappings for one sentence. The leak being closed was never a cryptographic one. It was a handle in a list.

Answering a comment

reply sits beside a comment, and what you write goes under it, one step in. The box at the bottom of the post is the same box; while you are answering it says who you are answering, and cancel puts it back to the photograph without throwing away what you have typed.

A reply cannot be answered. One level, and that is the whole of it: there is no thread here, only a conversation under a sentence. You will not find a message saying so—reply simply is not there on a reply.

You can only answer something you can hear, which follows from the rule at the top of this page and costs nothing: the people whose comments reach you are exactly the people you could already have named with @.

And a reply is heard only where the comment it answers is. If Bruno cannot hear Carla, he does not hear Ana’s answer to her either—even though he hears Ana perfectly well everywhere else on that photograph. An answer with nothing in front of it is not what anybody wrote. The failure runs the way the rest of this page runs: fewer people read it than you assumed, never more.

Deleting a comment takes the answers to it. That is the one place in the app where taking back your own words takes somebody else’s, and it is worth being plain about. Nothing else here leaves a mark when it goes, so the alternative—a deleted placeholder with the conversation reading on under it—would have turned taking something back into an announcement that you had. The app asks first when there is anything to lose, and says how many replies go with it.

Whoever wrote the comment is told you answered it, as a row in their activity tab. A notification for it is the same switch as a comment’s: settings → when somebody comments on my post, off until you turn it on. It is deliberately not the let mutuals tag me switch, which is about whether somebody may put your name on something—a reply puts your name nowhere.

Naming somebody in a comment

Type @ and the names you may use appear above the box: the person whose photograph it is, plus the people you and they both know. Tap one, or type it out. A name you were not offered does nothing at all.

The names you are offered are not the same set as the people who will hear you—the audience of a post belongs to whoever made it, and listing the part of it you happen to know would be the viewer list wearing a picker. So a name may quietly reach nobody, and nothing tells you which: a reply that said would be a way of asking, one name at a time, who is in somebody else’s audience. At most eight names in one comment; past that, a sentence is a mailing list.

Whoever you name is told, once, in their activity tab, and by a notification if their let mutuals tag me switch is on—the same switch that lets somebody put your name on a photograph, because a caption and a word in a sentence are the same act at two sizes. Your name in a comment is inside the sealed text, so there is nothing for us to take down later: turning the switch off stops the next one.

What a comment is

  • In the order written, with each answer under the comment it answers.
  • Sealed on your phone under the post’s key, and bound to the post, to you, to that one comment—and, for a reply, to the comment it answers—so nobody can move your words under somebody else’s name, or under a different sentence.
  • Yours to edit, and yours to delete. The person whose post it is may delete it as well: editing changes what somebody said and only they may do that; deleting removes it, and the person whose photograph is being talked under may do that too.
  • An edited comment does not say it was edited, although an edited caption does. There is no column for it, and adding one would mean showing you a mark we could set on a comment nobody touched, about a body we cannot read.
  • A deleted comment leaves nothing behind. There is no “this was deleted” placeholder—and the answers to it go at the same moment, for the same reason.
  • A comment that will not decrypt is shown as This could not be opened on this phone. rather than dropped quietly. A comment that simply vanishes is the failure nobody reports, and it is also what a forged one would look like.
  • The person whose post it is is told, as a row in their activity tab; so is whoever you answered, and so is anybody you named. Never more than once about one comment: being named says the most, being answered says more than “somebody commented”, and each replaces the one below it. A notification is off until you turn it on, at settings → when somebody comments on my post. Nobody else in the conversation is told anything, ever.
  • There is no comment count anywhere, and no reply count either. Nothing computes one, so nothing can draw one: the comments are the list, and their number is however many are on the screen. The one number about replies is in the question the app asks before you delete a comment that has some, and it counts what that tap is about to take.
  • A comment has no report of its own. Report the post it sits under, from more, or the person who wrote it, from more on their profile. A comment under your own post you can simply delete. What we receive is a pointer and what you type; see the moderation policy.

Reactions

react under a photograph, or the plus at the end of the row once there are some. A double-tap on the photograph on the post screen is a heart, and a second double-tap takes it back—on a post drawn as a carousel, which is anything up to eight photographs. Beyond that a post is a grid of tiles, and there is nothing there to double-tap.

Any emoji. There is no shortlist. The picker is Unicode’s emoji table under nine lowercase headings with a recent row on top, and it has no search box, because a keyboard between somebody and a reaction is the opposite of what a reaction is for. Anything your phone’s font cannot draw is left out of the picker rather than offered: sending a hollow box to everybody in the audience would be worse than not offering the emoji at all.

Only what you choose from the picker becomes recent. Tapping somebody else’s pill is agreeing with a reaction they picked, and the double-tap is a gesture of its own, so neither fills your recent row with things you never went looking for. That row is kept on your phone and is nobody else’s business.

The pills are in the order each emoji first arrived, never in order of popularity. A row that ranks itself moves under your thumb: you reach for the third pill and it swaps with the second because somebody reacted while you were reaching. And ranking what people send is the one thing this app does not do. A pill that gains a person keeps its place.

The count on a pill is the only number about other people allowed anywhere near a photograph. It says which emoji six people chose, it is bounded by an audience that is itself bounded, and only people already in that audience can see it. There is no total: no summed reaction figure, no comment count, no view count.

Who is named on a pill

Press and hold a pill and it names the people who chose it. The comment rule does not apply here. That list is everybody in the audience who reacted, so it can name somebody you have no connection to, shown under their handle. Nothing in that list is a link: it is a line of names, and there is nothing in it to tap.

Whether the comment rule should cover reactions as well is a question we have not settled, and the difficulty is the count: filtered per reader, the one number this app allows would disagree from screen to screen, naming four people under a six. A reaction is also a smaller disclosure than a sentence. An emoji beside a handle says somebody was there; a comment says what they think.

Reactions never notify anybody

A reaction writes a row in the activity tab of whoever’s post it is, and can never send a notification. There is no setting for that, because there is nothing to switch on: no notification type, no column, no route. The settings screen says so under the comments switch, in as many words: Reactions never notify anybody, and cannot be made to. Looking is allowed; interrupting is not, and you can already see who reacted by opening your own post.

All of one post’s reactions are a single row in that tab, naming whoever reacted most recently and moving as more arrive. Comments get a row each, because three comments are three things somebody wrote. “Ana and three others reacted” was refused outright: a figure other people make bigger is exactly what this app has none of.

Reactions are not encrypted, and we say so

A reaction is one emoji, stored in the clear. Sealing it would be theatre: a single emoji from a set anybody can enumerate is guessable however it is wrapped, and we hold the row saying who reacted to what regardless. Your photographs, captions and comments are sealed; reactions are on the list of what we can see in the privacy policy, which is where they belong.

Nobody is told who looked

There is no seen-by list, no viewer list and no read receipt. One was built, and taken out again in the pass after it shipped.

A per-person read receipt was the last thing in the app that turned looking into an act that gets reported. Somebody who opens a photograph their mother sent has done something that is now on a list she can read, and “you saw it and didn’t say anything” becomes available to everyone in the audience. That obligation is the thing this app is meant to be a rest from, and leaving the number off does not fix it.

The app does record that you saw a post, and when you first did. That is how your feed empties, and it is listed in the privacy policy as something we hold. What is gone is any way to ask for it.

Being named on a photograph

Whoever posts may name up to 32 people on it. Only their own mutuals, only people the post is already going to, and only people who have left the switch below turned on. The names appear under the poster’s name as with ana, bruno, and every viewer of the post sees them.

You can only be named on a photograph you can see, and that is structural rather than a rule somebody remembered to write: the name rests on the delivery of the post to you, so when the delivery goes—a removal, a block, the post deleted, an album membership taken away—the name goes with it, with nothing anywhere having to remember to take it down.

What a name discloses is your handle, always, and your display name and profile picture if the poster passes them on, which they can because they hold them as your mutual. Tapping a name you are connected to opens that person’s profile. Tapping one you are not opens their card: their face, their name, who you both know, and add. It is one of two places in this app where a row names a stranger you can tap—the other is the original poster of a reshare, further down this page—and both have the same two consents behind them: the named person’s, in the switch, and the poster’s, in the act of naming them. It is “who is that in your picture?”, and the person in the middle is on the hook for the introduction.

The switch is yours. settings → let mutuals tag me, and it is on to begin with—only one other switch on that screen starts on. Its line reads: They may show your name and picture to whoever sees the post. Turning this off removes every tag of you and takes back anything you reshared. That is exact. Turning it off deletes every existing name of yours, every copy of your profile key handed out on those posts, and every reshare you made, in one go. Turning it back on restores none of it.

It starts on because nobody can name you who is not already your mutual, and only on a photograph you were sent, so what the switch withholds is narrower than it sounds.

You take one name off at more → remove my tag, which asks nothing first, because it narrows. The poster cannot add or remove names after posting; only the person named can take their own off.

You are told you were named by a row in your activity tab.

Passing a photograph on

Somebody you named can pass the post on to their own mutuals, but only if you allowed it for that particular post. tagged people may reshare this is a checkbox in the composer, off by default, and it only appears once you have named somebody. Afterwards it is a switch on the post itself, under the names it is about, so you can give the permission later or take it back: Turning this off takes back anything they reshared.

A reshare is a post of the resharer’s, with its own audience, chosen once. It carries no caption of its own, and it is drawn under the original poster’s name and face with one small line above them reading bruno reshared, because the photograph is still theirs. The date is the reshare’s own, because that is when it reached you. Each person may reshare a given post once.

Three kinds of person never receive it: the original poster, anybody who already holds the post, and anybody blocked with the original poster. What a reshare adds is the resharer’s own people who did not have it, bounded by their own limit of 128 mutuals, and it counts nothing and ranks nothing. Nowhere in the app is there a number of how many times something was reshared.

A reshare is a different room. Its comments and its reactions are its own, and who hears a comment under it is the intersection with the resharer’s circle, the ordinary rule with the resharer as the poster. The original poster is not in the reshare’s audience at all, so they cannot open it and cannot read what is said there. They are told once, by a row in their activity tab, and never by a notification.

A reshare lives exactly as long as the name it rests on. Take your name off, turn your switch off, have the poster untick the permission, remove you, block you or delete the post, and the reshare and every key that opened it are destroyed together. Nothing is hidden; there is nothing left to open.

Nobody can reshare a reshare, and nothing in an album can be reshared at all. A chain would put a hop behind somebody the original poster never named and never allowed, and an album is a room whose whole promise is that only the people in it see what is in it.

Where else to look

The rest of the guide is at how it works. What we hold and what we cannot see is in the privacy policy; what we can do about somebody, and what you can do yourself without waiting for us, is in the moderation policy.