
Those keys were in a different table of the database, which contained no PII, and which we are therefore not disclosing. Note, as we have stated, an entire database was taken, and that database included access keys to social media sites. Rather than simply assure you, we are taking the transparent step of simply posting publicly the entirety of the schema of the table that contained personally identifiable information, so you can see for yourself what was taken.


How do we know there won’t be more PII? People have asked us whether more personally identifiable information will come out, and if we say no, how they can know. Most accounts contained gender, country codes and date of birth information. In addition to our communications with local and federal law enforcement, we are also in contact with all our social media providers, and will update users as needed, but again: there are no credible reports, and there has been no evidence of, any unauthorized use of these access tokens.

All the compromised tokens have been deauthorized, and are no longer valid. However, it is important that we tell you that there was a short time window during which it was theoretically possible for unauthorized users to access those posts - again, we have no evidence that this actually happened. In general, Timehop only has access to social media posts you post yourself to your profile.

Second, we want to be clear that these tokens do not give anyone (including Timehop) access to Facebook Messenger, or Direct Messages on Twitter or Instagram, or things that your friends post to your Facebook wall. While we continue to investigate, we want to stress two things: First: to date, there has been no evidence of, and no confirmed reports of, any unauthorized access of user data through the use of these access tokens.
