Privacy
A good community starts with trust.
What is stored
Supabase handles your email, password authentication and persistent account. The community stores your profile, room memberships, topics, messages, reports and moderation records. Direct messages are accessible to conversation participants through access controls; they are not end-to-end encrypted.
Live media and providers
Cloudflare relays audio and video only when you join media. This application does not implement media recording. Transport encryption is not an end-to-end encryption promise. Your device requests microphone or camera permission before capture. Server-side limits and moderation can stop a stream.
Profile photos and optional notifications
Selected profile photos are resized, stripped of source metadata and stored privately in Cloudflare R2. Authorized community members can view them. Removing a photo immediately removes access; physical cleanup can be delayed by provider failures. Optional mobile push uses Expo, Apple or Google delivery. Device tokens are stored on the backend, and lock-screen notifications contain no message text, sender or room name. You can disable or revoke devices in your profile. Already in-flight notifications cannot be recalled.
Before public launch
Retention periods, data controller details, rights requests, deletion/export processes and international data transfer disclosures require operator decisions and legal review. Do not use this preview for sensitive data.
Preview policy version: 2026-10-01-preview