Blog · privacy

Privacy by design — what gets deleted, what stays

By M2B Editorial · 5 min read · June 8, 2026

"We take your privacy seriously" is the most devalued sentence on the internet. So instead of saying it, here is the actual inventory: what M2B stores, what it deletes, and what it never collects in the first place.

What gets deleted

Verification documents. Your bank statement or brokerage letter exists in our systems only long enough to score your application. On approval, it is deleted. We keep the decision and the reasoning, not the artifact.

Chat history with Mitobi, client-side. Conversations with the concierge in your browser clear when your session ends. Each visit starts fresh.

What stays

Your pseudonym and profile. The fixed pseudonym you chose, plus whatever profile fields you decided to fill — city, what you contribute, what annoys you. You control every optional field.

Your threads and replies. The conversation is the product. What you write in the room stays in the room, attributed to your pseudonym.

Moderation and verification metadata. Scores, decisions, agent reasoning, timestamps. This is the audit trail that keeps the agents accountable to the founder, and the founder accountable to members.

Your email. We need one channel to reach you — application decisions, security notices. It is never shown to other members.

What we never collect

Real-name social graphs. We do not import your contacts, scrape your connections, or map who you know.

Behavioral advertising data. There are no ads, so there is no ad targeting, so there is no tracking pixel economy on the site. Essential cookies only: session authentication and security.

Engagement telemetry for ranking. We do not track scroll depth to feed an algorithm. There is no algorithm to feed. Threads rank by recency and substance.

Pseudonymity, precisely

Members write under fixed pseudonyms like quiet.compounder or Phantom.III. Fixed matters: a stable identity accrues reputation, and reputation disciplines behavior. This is not 4chan-style anonymity — it is accountability without exposure.

Your real name exists in exactly one place: the verification flow, where an AI agent and possibly the founder see it once. Display preferences let you reveal more — or not — at your discretion. The default is private and stays private. As the landing page puts it: your name can stay private; your thinking does not have to.

The structural argument

Privacy that depends on a policy can be changed by a policy. Privacy that depends on architecture cannot.

We chose the architecture version everywhere we could: documents deleted so they cannot leak, pseudonyms so there is nothing to dox, no ad model so there is no buyer for your data, no staff so there is no insider to bribe. The anonymous founder is the same principle applied at the top.

No system is breach-proof. But the honest measure of a platform's privacy is what an attacker would find after full compromise. Here, they would find pseudonyms, conversations, and scores. Not statements, not balances, not names attached to either.