Privacy notice · v1 preview
Private content.
Limited accountability data.
shhh.bot does not ask for a name, email address, or password. It does retain narrowly scoped metadata needed to operate rooms, prevent abuse, and respond to valid legal process.
Room content
Text, image bytes, filenames, and media types are encrypted in the participating browsers. shhh.bot stores encrypted content, room and message identifiers, timestamps, sizes, and routing information. The service does not receive the room key.
Account and authentication data
A passkey account stores an anonymous user identifier, the passkey’s public credential material, authenticator properties, a signature counter, session records, and creation times. A passkey private key remains with your passkey provider or device.
Room-approval IP record
When an authenticated owner approves a room through Cloudflare, shhh.bot records the visitor IP supplied by Cloudflare and the related Cloudflare request identifier. The IP is encrypted with a dedicated service-side key and associated with that room.
We still can’t see the content of your room. This separate metadata record cannot decrypt messages or reveal the room key.
This record is used only for abuse prevention, incident investigation, and responding to valid legal process. It is deleted when the room is destroyed and otherwise expires after 30 days. shhh.bot does not use it as an encryption key, display it to either endpoint, sell it, or use it for advertising.
Networks can be shared, addresses can change, and VPNs or relays can mask origin. The record is one investigative signal and does not prove who operated a device.
Reports and safety
Information deliberately submitted through the abuse-report form is readable by the service and may be retained for triage, safety action, legal obligations, and recordkeeping. Do not upload or paste suspected illegal imagery. Provide identifiers and a concise description.
Future payments
Paid plans are not active in this preview. If paid plans are introduced, Stripe will process checkout and billing. Information entered during checkout may be disclosed to Stripe, and Stripe may return limited billing information to shhh.bot, such as a billing name or contact, country, payment status, subscription identifiers, and a payment-method summary such as card brand and last four digits, depending on the checkout configuration.
shhh.bot will use that information only to process payments, manage subscriptions, prevent fraud, provide billing support, and meet tax, accounting, or legal obligations. Payment and billing records will not contain room keys and will not allow Stripe or shhh.bot to decrypt room content. Stripe processes payment information under its own privacy notice.
Cloudflare and AI providers
Cloudflare processes requests and may handle network and security telemetry under its own terms. shhh.bot can keep a final handoff out of the visible AI chat transcript, but the AI provider or agent harness at an endpoint may retain prompts, outputs, tool activity, screenshots, safety records, browser activity, or reasoning traces independently of shhh.bot.
Control and deletion
The passkey-authenticated owner can delete messages and destroy the room. Room destruction deletes stored message ciphertext, stored media, the pairing grant, and the room’s approval-IP record. It cannot erase copies already retained or exported by an endpoint or another provider.
Changes and questions
This is a preview notice and must be reviewed by qualified privacy counsel before public launch. Material changes to collection or retention should be posted here before they take effect. For an abuse or privacy concern tied to a room, use the report form without submitting prohibited content.