Back

What this records

This is an anonymous inbox. You write to Azraf Al Monzim without giving a name, and they can write back. This page is the full account of what is kept when you do — not a summary of it.

Anonymous to other people, not to the owner
Nobody else can see who sent a message. Azraf Al Monzim can see everything on this page, attached to your message, from the moment it arrives. If that is not what you expected, the time to stop is now, before you send.

Who can read what

Your message goes to one person. It is not published, listed, or shown to other senders.

Your thread link is the exception. It is a long random reference and it is not guessable, but there is no password on it — anyone you send it to can read the thread and the reply. Treat it the way you would treat a password, and be careful where you paste it.

Your recovery key is shown to you exactly once and is stored only as a one-way hash. If you lose it, nobody can recover it for you, including Azraf Al Monzim. That is deliberate: a key someone else can recover is a key someone else can use.

What you can send

Up to 2,000 characters of text, and up to 5 images of 10 MB each.

Photographs from a phone usually carry the camera model and the exact place they were taken inside the file. Every image you attach is decoded and written back out in a different format before it is stored, which removes all of it. The file you upload is never kept.

No image is visible to anyone — not to Azraf Al Monzim, not on the thread page, not to you — until it has been reviewed one at a time. Your own upload showing as “held for review” is the system working, not a fault.

You are asked to confirm you are 18 or older before a message will send.

Everything that is stored

Grouped by where it comes from. If a field exists in the database, it is in this table — that is enforced by a test, not by anyone remembering to update this page.

What you wrote

The message itself, and what happened to it.

Your message
It is the thing you came here to send.
Who wrote it
Separates what you sent from what was written back to you.
When you sent it
Orders the conversation and starts the retention clock below.
The reference in your link
It is the link. Anyone holding it can read the thread, which is why it is 26 random characters and not your name.
When the thread began
Distinguishes a first message from a follow-up on an older one.
Whether it reached the inbox
Messages can be stopped by a filter or a block. You are not told which, and a stopped message still gets a thread and a link.
Which filter caught it, if one did
Lets the owner see why something was marked without re-running the rules.
Whether it has been read
Drives the unread count in the owner's console. It is never shown to you.
Whether the owner starred it
The owner's own bookmark.
Whether the owner archived it
Moves it out of the inbox without deleting it.
Whether the owner deleted it
Deletion is recorded rather than silent, so a thread that is gone can say it is gone instead of looking broken.
Whether the whole thread was deleted
Deleting a thread takes its messages and images out of reach with it.

Images you attach

Every image is decoded and written back out as WebP before it is stored. That is what removes the camera and location data that phones put inside photo files — the original file is never kept.

The image itself
Re-encoded, resized to at most 1600 pixels on its longest edge, and stored.
A smaller copy of it
So a thumbnail does not cost a full-size download.
What you called the file
So the owner sees something recognisable next to the image.
How large the stored copy is
The size after re-encoding, not the size of what you sent.
The stored format
Always WebP. Recorded so nothing has to guess what the bytes are.
When you uploaded it
Uploads that are never sent are cleared out on their own.
A one-way hash of your device token
So only the browser that uploaded an image can attach it to a message. The token itself is not stored.
Whether it has been reviewed
Every image is held until the owner approves it — including from your own view of it.
When that decision was made
Records that a person made it, and when.
The result of the automatic check
Confirms the stored file is still a readable image. It cannot approve anything; only a person can.
What that check saw
The format and pixel dimensions of the stored copy.
When it ran
So an image that was never checked is visible as such.

The network you are on

Cloudflare works this out from the connection itself. None of it needs your permission and none of it can be turned off from this page — the only way to change it is to change the network you are using.

Your IP address
The one identifier here that usually points at a single household or phone. It is removed when the record is coarsened — the section below gives the figure, read from the policy that does it.
Country
The coarsest location, and the one kept longest.
Region or state
Narrows the country down, usually to something the size of a county.
City
Usually accurate to the city, not the street.
Postal code
Sometimes present, sometimes wrong. Kept because it is part of what was reported.
Approximate latitude
A guess from your address, typically the middle of a city.
Approximate longitude
The other half of that guess.
Network number
Identifies the operator carrying your traffic.
Network operator
The name behind that number — a phone network, an ISP, a data centre.
Kind of network
Mobile, home broadband, or a hosting provider. Worked out from the operator's name.
Which Cloudflare location served you
A rough sanity check on the rest.
Whether you look like you are using a VPN
A judgement, not a fact. Traffic from a data centre reads as likely.
Cloudflare's bot score
How much the request looks automated.

Your location, only if you share it

This group is empty unless you press the button and your browser asks you first. Nothing here is collected silently.

Precise latitude
What your device reported. On a phone this can be accurate to a few metres.
Precise longitude
The other half of that reading.
How accurate it claims to be
A reading with 2 km of error means something different from one with 8 m.
What happened when you were asked
Whether you were never asked, shared, gave an approximate answer, or your device could not tell.

Your device

What your browser tells every site it visits, and a little that this page asks it for.

Browser identification string
Sent by your browser on every request, to every site.
Device class
Phone, tablet, or desktop. Read out of the line above.
Operating system
Also read out of that line, so it is a guess rather than a reading.
Browser
Which browser, and roughly which version, from that same line.
Screen size
Read from the page. Distinguishes one device from another more than you would expect.
Language
The language your browser asks for pages in.
Time zone
Your device's own setting, which does not always agree with your network.

What is worked out from all of that

Nothing new is collected here. These are conclusions drawn from what is above.

Whether your two locations disagree
Set when the network guess and the shared reading are further apart than the accuracy allows.
How much of the above is trusted
A word, not a score: high, medium, low, or unknown.
When this was recorded
It is what the retention period below is counted from.
When the raw identifiers were removed
Empty until the retention run has been through this record.

How you are recognised when you come back

You have no account here and there is nothing to sign in to. These exist so that /my can show you your own threads, and so the owner can tell one anonymous sender from another.

A label like “Sender 4F92”
What the owner sees instead of a name.
A one-way hash of a cookie in your browser
The cookie is a random value with no meaning. Only its hash is stored, so the stored value cannot be put back into a browser.
A one-way hash of your browser identification
Notices when the same cookie appears from a visibly different browser.
When that browser was first seen
Distinguishes a new device from a long-standing one.
When it was last seen
Used to age out devices that stop being used.
A one-way hash of your recovery key
The key is shown once and never stored. If you lose it, nobody — including the owner — can recover it.
When it was issued
Each send issues a fresh one.
Whether it has been used
A recovery key works once.
When you first wrote
Tells a first-time sender from a returning one.
When you last wrote
Orders the sender list, so the most recent is at the top.
How many messages you have sent
Shown next to your label.
When this record was made
The first time a message of yours was accepted.
The owner's private notes about you
Written by the owner, never shown to you, and free text.
Whether you were linked to another sender
The owner can decide two senders are the same person. The decision is recorded and can be undone.
Whether you have been blocked
Recorded here, and never shown to you.
Why
The owner's reason, written for the owner and never shown to you.
When you were linked to another sender
Nothing is ever linked automatically. A person decided, and this is when.
What that link moved
Which of your threads and devices changed hands, and your message count before it. Kept so the link can be undone exactly.
Whether that link was taken back
A link that was made and withdrawn stays on the record as both.
Two senders the owner decided are not the same
The opposite decision to the one above, recorded for the same reason: so nothing keeps asking, and so it can be reversed.
The other sender in that pair
The decision is about a pair, so both sides of it are stored.
When that decision was made
So a judgement made once is visible as having been made once.

If you report a thread

Only what the report form asks for.

The reason you chose
Sorts what arrives, so the serious reports are not buried.
Anything you added
Optional, and only what you typed.
Your email, if you gave one
Optional. Leaving it blank does not make the report count for less; it only means nobody can reply.
Whether it has been dealt with
Waiting, escalated, resolved, or dismissed.
What was decided
The owner's note on the outcome. You are not shown it — see below.
When it was decided
How long your report waited. Kept so it is possible to tell a queue that gets worked through from one that does not.
When you sent it
Orders the queue, oldest complaint first.

If a rate limit refuses you

A limit that stops a script has to remember who it stopped, or the owner cannot let a person back in.

What was counted
Your address, or the sender identity your browser is bound to, depending on which rule refused you. It is the same value already recorded above; this row is a note that it hit a limit.
What you were doing
Sending, uploading or reporting. Which limit it was.
How many times
Counted since the last time somebody let you through, not for ever. It is what tells a person in a hurry apart from a script.
When it started
The first refusal in this run of them.
The most recent one
Also decides when this row stops being shown at all — a day after the last refusal, it drops off the list.
When you were let back in
Set when the owner releases a limit by hand. Blank means the limit ran its course on its own.

What the owner's own actions leave behind

Running the inbox creates records too, and some of them are about you.

What a block applies to
A sender, an address, a range of addresses, or a whole network operator.
The value blocked
Which may be your IP address or the network you are on, kept for as long as the block stands.
Why
The owner's reason for adding it, in the owner's own words.
Any notes
Anything else the owner wrote alongside it.
When it was added
Orders the block list by age, so old blocks can be reviewed.
Whether a reply to you was rewritten
The owner can change a reply after sending it. Your page says so, and this is the stamp it says it from — a reply that changed silently under someone who already read it is a record nobody can rely on.
What the owner did
Deleting, blocking, approving, changing a setting.
Who did it
The owner, or the system acting on a schedule.
What kind of thing it was done to
A message, a sender, an attachment, a setting.
Which one
So the record points at something specific.
The address the owner acted from
The owner's own address, not yours.
What it looked like before
Which can include a copy of your message, kept so a deletion can be shown to have happened.
What it looked like after
The other half of that record.
When it happened
This log is only ever added to. Nothing in the application can change or remove a line of it.
A word the owner may put on your message
The owner's own filing, in their own words. It is never shown to you and never leaves this system, but it is a label attached to something you wrote, so it is named here.
When one was put on
Orders the owner's own filing. Nothing about it reaches you.
The line in a held notification
When the owner has quiet hours or a digest switched on, the fact that you wrote is written down until it can be sent. It carries your sender label and never a word of what you wrote.
When the thing it is about happened
So a summary arriving in the morning can say when each thing actually happened rather than when it was sent.

How long it is kept: 90 days, then less of it

Everything above is kept in full for 90 days. After that, a scheduled job removes your IP address and any precise coordinates you shared, and stamps the record to say it has done so.

What survives is the coarse version: country, region, city, network operator, and the kind of device. That is kept indefinitely.

Messages themselves are not deleted on a timer. They stay until Azraf Al Monzim deletes them, which means a message can outlive the raw details of how it was sent.

These figures are the ones the scheduled job uses. They are read from the same setting it reads, so this paragraph cannot fall behind a change to the policy.

Who else your browser talks to

Opening this page fetches the page, its styling and its fonts from this site and nowhere else. The fonts used to come from Google, which meant that simply reading this sentence told them your IP address and which page you were on. They are served from here now.

One other connection is made, and this is it. A test holds this list against the code, so a new one cannot appear here without appearing on this page too.

challenges.cloudflare.com

Cloudflare, who also host this site

When
The send page and thread pages, where there is a form to submit.
What they learn
Your IP address, your browser, and signals about how the page is being used — enough to tell a person from a script.
Why it is here
It is the check that stops this inbox being filled by automated submissions. It runs without asking you to identify anything, and it is the only remaining request off this site.

Asking for something to be deleted

Write to abuse@fisfis.cc and include the reference from your thread link — the characters after /t/. Without it there is no way to find your message, because there is nothing else connecting it to you.

Your open threads are listed at /my on the browser you sent from, and each one carries its own reference.

Deletion removes the message, its images and any reply. A line stays in the owner's own record saying that a deletion happened and when — that log is only ever added to, and nothing in this application can rewrite it.

Reporting something

Every thread page has a report control. Use it if a reply is threatening, or if something here is being used against you.

For anything urgent, or anything you would rather not put through this site, write to abuse@fisfis.cc.