Privacy Policy

We collect the bare minimum to prevent abuse. Conversations are end-to-end encrypted. Room data auto-deletes. Your email hash is kept for 30 days, then deleted.

Last updated: 3 March 2026

What we collect

Room creators: Your email address is required to create rooms. This prevents abuse and spam. The email is used once to send a verification code, then immediately discarded. We store only a one-way hash (SHA-256) of your email, and we cannot recover your actual address from it.

Participants: No email, no account, no identification. Participants only provide a display name which is stored in memory during the session.

Communication content: All messages are end-to-end encrypted. The server only sees encrypted blobs. We do not store chat messages, voice, or video. The encryption key exists only in the room link (URL fragment) and never reaches our server.

No IP logging: We do not log IP addresses, user agents, or any personally identifiable information in our application logs.

Legal basis for processing (GDPR Art. 6)

Every data point we process has a specific legal basis under GDPR Article 6. We process the minimum necessary for each purpose.

DataLegal basisPurpose
Email hash (SHA-256)Legitimate interest (Art. 6(1)(f))Abuse prevention, rate limiting, ban enforcement
Subscription dataContract performance (Art. 6(1)(b))Providing paid tier access; billing via Stripe
Abuse reportsLegal obligation / Legitimate interest (Art. 6(1)(c)/(f))Responding to law enforcement; platform safety
Communication contentNot processedEnd-to-end encrypted, server never receives plaintext (GDPR Art. 25 privacy by design)

Data retention

DataRetention
Room dataAutomatically deleted when the room expires (max 4 hours). Stored only in memory (Redis), never written to disk.
Email hashStored for 30 days after your last room creation, then automatically deleted.
Verification codeDeleted after 10 minutes or immediately upon use.
Abuse reportsIf someone reports a room, the report (room ID and report type, no message content) is stored for 90 days.
FeedbackVoluntarily submitted feedback is stored for 180 days.
Ban listIf an account is banned for abuse, the email hash is stored permanently to enforce the ban. No other data is retained.

Law enforcement requests

We respond to lawful requests from law enforcement. Our zero-knowledge architecture means we cannot provide what we do not have.

We CAN provide

  • Room creation timestamp and configured duration
  • Number of participants (no identities)
  • SHA-256 hash of creator email (if within 30-day retention window)
  • Subscription tier and billing status
  • Abuse report records (room ID, report type, 90-day TTL)

We CANNOT provide

  • Message content (end-to-end encrypted, we never see plaintext)
  • Voice or video recordings (E2EE, never stored)
  • Participant identities (no account required to join)
  • Plaintext email address (discarded immediately after OTP)
  • Historical room content (RAM-only, deleted on expiry)

Legal requests: legal@hushroom.io. We notify affected users unless prohibited by law.

Your rights

Under GDPR, EU users have rights to request information, deletion, object to processing, and lodge complaints. Due to our privacy-by-design architecture, most data is automatically deleted before you could request it.

For ban appeals or data requests, contact us below.