NyChat
Secure • Ephemeral • Private
LEGAL // DATA PRACTICES

Privacy Policy.

Transparent, factual information on how temporary rooms, session tokens, and communication data are handled in NyChat.

DOCUMENTPrivacy Policy
STATUSActive / Current
PRODUCTNyChat v2
AUTHORNyxen Studio
AT A GLANCE / EXECUTIVE SUMMARYDATA BOUNDARIES
01 / WHAT WE HANDLE

Temporary display names, reconnect tokens, encrypted message text, capability-gated media, and operational routing events.

02 / ON YOUR DEVICE

AES-256-GCM encryption/decryption keys (held in URL fragment #) and temporary session storage tokens.

03 / AT THE SERVER

Ephemeral room relay state, temporary capability tokens, WebRTC signaling, and pseudo-anonymous daily aggregate metrics.

04 / NOT CLAIMED

No 100% untraceability claims. Media is not E2EE. Operating metadata exists to keep the service stable.

[01]Privacy Overview
[01]

Privacy Overview

NyChat is an ephemeral, web-based communication tool designed for temporary conversations. Our architecture is guided by a simple principle: avoid collecting or storing personal information that is not required to operate real-time rooms.

We do not require users to create accounts, provide phone numbers, submit email addresses, or maintain persistent profiles. This Privacy Policy describes transparently what information is processed when you use NyChat, how temporary rooms operate, and our data retention standards.

[02]

Information Processed During Active Sessions

To deliver real-time chat functionality over WebSocket connections, NyChat processes the following session-scoped data:

  • Temporary Display Name: The name you enter when joining a room. This identifier exists within that room session and is never linked to an account.
  • Session Reconnect Tokens: A random cryptographic string generated in your browser and stored in local/session storage to allow seamless reconnection if your network briefly drops.
  • Encrypted Message Payloads: Text messages are encrypted in your browser before they are sent; the service relays the encrypted payloads, replies, and reactions to other participants in the same room.
  • Temporary Media & Files: Images (up to 10 MB) and documents (up to 20 MB) uploaded by participants to share within the room session.
  • Voice Notes: Short audio recordings (up to 3 minutes) captured in-browser and uploaded through NyChat's protected media pipeline. They are stored temporarily with session media, accessible only to authenticated room participants, and permanently purged when the room ends.
  • WebRTC Calling Media: Voice and video streams flow directly peer-to-peer between participant browsers where network conditions permit (encrypted with DTLS-SRTP in transit). The server relays signaling packets (offers, answers, ICE candidates) and coordinates call state, but does not record or store audio or video content.
  • Operational Metadata: Connection events, room membership, timestamps, and similar technical data required to route messages and keep rooms working.
[03]

Information Not Intentionally Collected

NyChat deliberately avoids harvesting data common to traditional social platforms:

No user registration or passwords
No email or phone number capture
No address book or contact synchronisation
No persistent user profiles or social graphs
No advertising networks or ad tracking
No permanent archive of room message content

NyChat does use privacy-friendly, cookieless analytics (see the Analytics section) to understand aggregate site usage.

[04]

How Temporary Rooms and Secure Invites Work

When a room is created, a room code is allocated and a complete secure invite link is generated. The room code identifies the room; the complete invite link additionally contains a client-side encryption key fragment (kept in the URL fragment, which browsers do not send to the server). Opening a room with only the code cannot establish the same encrypted session — joining a secure room requires the complete invite.

TIER 01 / CLIENT BROWSER

Your Device & Local State

  • Client-side AES-256-GCM encryption & decryption
  • Room decryption key stored only in URL fragment (#)
  • Ephemeral session reconnect tokens in sessionStorage / localStorage
  • Instant removal when browser data is cleared or session closed
Boundary: The server never receives client-side encryption keys
TIER 02 / NYCHAT RELAY & SERVICE

Required Operational Data

  • Relays encrypted ciphertext and WebRTC signaling packets
  • Temporary room store (presence, message history during active room)
  • Access-controlled media storage with short-lived capability tokens
  • Pseudo-anonymous metrics using a daily-rotating salt
  • Bounded 90-day evidence retention only if content is formally reported
Boundary: Room store is removed when participants leave
TIER 03 / THIRD-PARTY INFRASTRUCTURE

Strictly Bounded Sub-processors

  • Cloud edge & CDN for DDoS defense and asset delivery
  • Umami cookieless, privacy-friendly aggregate analytics
  • No advertising trackers, no ad networks, no data brokers
Boundary: Zero tracking across third-party websites

When all participants leave and active connections terminate, the temporary room store — including its message history — is removed. Losing a complete secure invite means losing access to that room's encrypted session; there is no key recovery.

[05]

Messages, Media, and Voice Calls

Text messages are encrypted in your browser using AES-256-GCM via the native Web Cryptography API, then relayed in real time to connected participants over secure WebSocket channels (WSS/TLS). Because encryption and decryption happen on your device, the NyChat service cannot read the plaintext of encrypted room messages.

Uploaded media (images and files) is stored temporarily by the service so room participants can view and download it. Access is gated by short-lived, session-scoped capability tokens rather than end-to-end encryption. Media has no public index, and unused or orphaned uploads are cleaned up automatically.

Voice and video calls use WebRTC peer connections between participants' browsers where the browser and network support direct P2P; a TURN relay may be used on restrictive networks when configured. Voice calls support up to 8 participants and video calls up to 4 per call. Call state events (such as a call starting or ending) are visible to room participants as lightweight room activity. NyChat does not record call audio or video.

[06]

Storage and Data Retention

NyChat does not build a permanent archive of room message content. Active room state and message history live in a temporary room store that exists while the room is populated and is removed when the room ends.

Data Retention Schedule
AUDITED INTERVALS
Active Room Messages & StateSession duration

Removed when all participants leave or disconnect

Purpose: Real-time chat delivery and synchronization
Temporary Media & Voice NotesSession duration

Images, documents, and voice notes purged automatically when the room closes or expires

Purpose: In-room viewing and playback via capability tokens
WebRTC Voice & Video StreamsLive transit only

Exchanged peer-to-peer between browsers via DTLS-SRTP; never recorded or stored on servers

Purpose: Real-time voice and video communication
Reported Content EvidenceUp to 90 days

Bounded context around the reported item; automatically purged after 90 days

Purpose: Safety & moderation review for Terms of Service violations
Local Browser TokensUser controlled

Stored in localStorage / sessionStorage; cleared on browser cache wipe

Purpose: Seamless reconnects during transient network drops
Daily Aggregate MetricsNon-persistent identifier

Generated using a daily-rotating salt; cannot be reversed to IP addresses

Purpose: Capacity planning and aggregate traffic estimations

Exceptions to temporary storage: when content is reported, a bounded evidence snapshot may be retained for a limited moderation review period (see Reporting & Moderation), and the service retains operational records (such as security and audit logs) needed to run and protect the platform.

Browser client data — such as locally saved reconnect tokens — is stored directly in your browser's localStorage or sessionStorage and can be cleared at any time via your browser settings.

[07]

Reporting and Moderation

Any participant can report a message, media item, file, poll, or participant from its action menu. A report instructs the service to preserve a bounded, time-limited snapshot of room activity around the reported item so it can be reviewed by moderators.

Evidence is retained for a limited period — currently 90 days, after which expired reports are automatically purged — and includes bounded context around the reported item (a limited number of surrounding messages, when still available). Reported message content remains encrypted: the service retains the evidence snapshot it needs for moderation without being able to read encrypted message text as plaintext. Network references in moderation records are cryptographically hashed, and raw network data is never exposed in normal moderation views.

Moderators can apply restrictions (such as blocking room entry, uploads, or calls) for users who violate the Terms of Service. Moderation actions are recorded in audit logs.

[08]

Analytics and Measurement

The NyChat website uses Umami, a privacy-focused, cookieless analytics service, to measure aggregate site usage such as page views and visitor counts. Umami does not use cookies for tracking and does not build advertising profiles.

Separately, the NyChat service keeps first-party, aggregate event metrics used for its own operations (for example total page views and unique visitor estimates shown in administration dashboards). These metrics are deliberately pseudo-anonymous: visitors are counted using an identifier derived by hashing network and browser information with a daily-rotating salt, so the identifier cannot be reversed into an IP address and does not persist across days. Approximate country information may be derived from edge-network headers when available. This data is aggregate and estimate-based; it is separate from the authoritative realtime presence counts shown inside live rooms. NyChat does not sell or share analytics data with advertising brokers.

[09]

Transport Security

All network communication between your browser and NyChat servers occurs over HTTPS and secure WebSockets (WSS) using TLS encryption in transit.

Transport security protects data against third-party interception on the network. Content protection for encrypted messages comes from client-side encryption; users should also share room invite links only with intended participants and keep their devices secure.

[10]

Infrastructure and Sub-processors

To serve web assets and host the application, NyChat relies on cloud hosting and CDN infrastructure. These providers may process standard HTTP network connection logs (such as IP addresses and request timestamps) strictly for traffic routing, DDoS defense, and operational stability.

One additional third-party service is used, strictly for aggregate measurement: Umami (privacy-friendly, cookieless site analytics). QR codes for room invites are generated entirely on your device — the room invite URL (including its encryption key fragment) is never transmitted to any QR service or to NyChat servers.

NyChat does not sell, rent, or trade user data to third-party advertising brokers.

[11]

What NyChat Does Not Promise

To keep this policy honest, here is what NyChat does not claim:

  • NyChat does not promise perfect or unbreakable anonymity. Limited operational metadata is processed to run the service.
  • Encryption protects message content where implemented (room text). It does not make all service activity invisible.
  • A room code alone does not contain enough information to decrypt a secure room. Losing the complete secure invite can mean losing access to the room's encrypted session.
  • Uploaded media is access-controlled and temporary, not end-to-end encrypted.
  • Your browser and device security still matter. NyChat cannot protect a compromised device.
[12]

Support and Feedback Submissions

If you voluntarily contact us via our support form or email, we receive the information you provide (such as your name, email address, and message content).

This information is used exclusively to respond to your inquiry or resolve reported issues, and is never correlated with room sessions.

[13]

User Choices and Rights

Because NyChat does not maintain persistent accounts, personal profiles, or message archives linked to identities, most data footprints are naturally short-lived. Leaving a room and clearing your browser storage removes local traces of your chat sessions.

For questions about retained data (for example moderation records), contact us using the details below.

[14]

Contacting Us

If you have questions regarding this Privacy Policy or NyChat's data practices, you can contact our team at:

support@nyxen.inEmail Support →
Have specific privacy questions?Reach out to our security & privacy team.
support@nyxen.in →