We collect the bare minimum to prevent abuse. Conversations are end-to-end encrypted. Room data auto-deletes. Your email hash is kept for 30 days, then deleted.
Last updated: 3 March 2026
Room creators: Your email address is required to create rooms. This prevents abuse and spam. The email is used once to send a verification code, then immediately discarded. We store only a one-way hash (SHA-256) of your email, and we cannot recover your actual address from it.
Participants: No email, no account, no identification. Participants only provide a display name which is stored in memory during the session.
Communication content: All messages are end-to-end encrypted. The server only sees encrypted blobs. We do not store chat messages, voice, or video. The encryption key exists only in the room link (URL fragment) and never reaches our server.
No IP logging: We do not log IP addresses, user agents, or any personally identifiable information in our application logs.
Every data point we process has a specific legal basis under GDPR Article 6. We process the minimum necessary for each purpose.
| Data | Legal basis | Purpose |
|---|---|---|
| Email hash (SHA-256) | Legitimate interest (Art. 6(1)(f)) | Abuse prevention, rate limiting, ban enforcement |
| Subscription data | Contract performance (Art. 6(1)(b)) | Providing paid tier access; billing via Stripe |
| Abuse reports | Legal obligation / Legitimate interest (Art. 6(1)(c)/(f)) | Responding to law enforcement; platform safety |
| Communication content | Not processed | End-to-end encrypted, server never receives plaintext (GDPR Art. 25 privacy by design) |
| Data | Retention |
|---|---|
| Room data | Automatically deleted when the room expires (max 4 hours). Stored only in memory (Redis), never written to disk. |
| Email hash | Stored for 30 days after your last room creation, then automatically deleted. |
| Verification code | Deleted after 10 minutes or immediately upon use. |
| Abuse reports | If someone reports a room, the report (room ID and report type, no message content) is stored for 90 days. |
| Feedback | Voluntarily submitted feedback is stored for 180 days. |
| Ban list | If an account is banned for abuse, the email hash is stored permanently to enforce the ban. No other data is retained. |
We respond to lawful requests from law enforcement. Our zero-knowledge architecture means we cannot provide what we do not have.
We CAN provide
We CANNOT provide
Legal requests: legal@hushroom.io. We notify affected users unless prohibited by law.
Under GDPR, EU users have rights to request information, deletion, object to processing, and lodge complaints. Due to our privacy-by-design architecture, most data is automatically deleted before you could request it.
For ban appeals or data requests, contact us below.