Privacy Policy — product draft for legal review
Privacy and encryption, explained plainly.
NOW-2-CHAT is designed to minimize application-level data. This policy describes the intended behavior of the current text-chat version. It should be reviewed and adapted by qualified counsel before public launch.
1. Who is responsible for the service
The operator of NOW-2-CHAT is responsible for the application-level processing described in this policy. Cloudflare provides hosting, network security, bot protection, real-time infrastructure and, when configured, email delivery. Questions or privacy requests may be sent through the Contact page or to the email address above.
2. Adults-only service
NOW-2-CHAT is intended exclusively for people aged 18 and over. The service is not designed for children or minors. Anyone under 18 must not use it.
3. What the chat service does not request
Chat rooms do not require an account, email address, telephone number, legal name, password or persistent profile. The service does not intentionally use advertising trackers, session-replay tools or browser fingerprinting for chat participation.
4. Data required to operate a room
The application processes the room locator, selected duration, participant limit, room status, timestamps, connection count, random participant identifiers, creator or guest role, mute state, temporary authorization tokens and encrypted packets. Cloudflare and other network providers may process IP addresses, device and browser information, timing and traffic characteristics to deliver and protect the service. The application derives a short-lived salted hash from the connecting IP for rate limiting rather than storing the raw address in the room record.
5. Message content and nicknames
Messages, temporary nicknames and transient typing indicators are encrypted in each participant's browser before transmission. The Worker and Durable Object do not receive the room key and are not designed to read plaintext chat content. Encrypted traffic can still reveal operational metadata such as approximate packet size, timing and the number of connections. Any participant who has the access code can read the conversation and may copy or record it.
6. How the encryption works
The creator's browser generates a random access code. HKDF-SHA-256 derives an independent AES-GCM 256-bit room key, a one-way key proof and a room locator from that code. Secure links place the access code after the URL fragment marker #; the application reads it locally, derives the credentials and removes it from the visible address bar.
AES-GCM provides encryption and integrity protection. Every encrypted packet uses a fresh 96-bit initialization vector. Protocol metadata is authenticated, so altered packets fail verification rather than displaying modified text.
7. Retention and deletion
The current version does not store chat history. Encrypted message, profile and typing packets are relayed in real time and are not written to D1, KV, R2 or a message archive. Typing indicators expire in the interface after a few seconds and are never persisted by the room. Active-room metadata exists only as required to coordinate and expire the room. After closure, a minimal invalidation marker may remain inside the Durable Object to prevent reuse of the same room object. A participant's browser may retain ordinary device-level artifacts outside the application's control, including screenshots, clipboard content or browser diagnostics.
8. Contact form data
The Contact page requests a name, reply email, subject and message. That information is used only to review and respond to the request, protect the form against abuse and maintain necessary correspondence. In production, the form is designed to deliver messages to contact@now2chat.com through Cloudflare Email Service. Email providers may retain the correspondence according to their own policies and the operator's legitimate recordkeeping needs.
9. Turnstile, fonts, security and service providers
Room creation uses Cloudflare Turnstile and rate limiting to reduce automated abuse. Cloudflare may process technical information under its own terms and privacy documentation. The service may also use Cloudflare security controls to limit attacks, automated traffic, repeated failed access attempts and misuse.
The interface loads the Inter typeface from Google Fonts. When a page is opened, the browser may connect to Google infrastructure to obtain the stylesheet and font files, which can expose ordinary connection data such as the IP address and browser request information to that provider.
10. Cookies and temporary tab storage
While a room is active, the application uses temporary storage limited to that browser tab so a refresh can restore the room identity and rederive the encryption key. The recovery record contains the access information, temporary nickname, short-lived authorization data and room expiry, but no messages, ciphertext, analytics identifier, IP address or fingerprint. It is not used for tracking or sent to Analytics Engine, expires with the room and is removed when you leave, close or lose access to the room. The application does not use localStorage or IndexedDB for chat sessions and does not intend to preserve identity between separate browser tabs or later sessions. Essential Cloudflare security mechanisms may set or process technical cookies when required to provide bot and abuse protection.
11. Abuse prevention and blocking
Misuse may result in throttling, rejection of requests, room termination or temporary or permanent access restrictions. Because chat content is end-to-end encrypted, enforcement is primarily based on technical signals, user reports, contact submissions and lawfully available information. Attempts to evade restrictions may lead to additional blocking.
12. Legal disclosures
The operator may disclose information actually available when required by valid legal process, applicable law or a good-faith need to prevent serious and imminent harm. Because the application is designed not to possess plaintext messages, it ordinarily cannot provide a readable chat history. This does not prevent disclosure of operational, hosting or contact-form information that is lawfully available.
13. Your rights
Depending on your jurisdiction, including under Brazil's LGPD, you may have rights to confirmation of processing, access, correction, deletion, information about sharing and objection where applicable. Requests should identify the relevant contact correspondence or other data sufficiently for the operator to locate it. Anonymous room content generally cannot be searched or recovered after a room closes.
14. Security limitations
No system guarantees absolute anonymity or security. Encryption does not verify identity, prevent screenshots, protect a compromised device or provide Signal-style forward secrecy. Do not use NOW-2-CHAT for emergency communication, legally required records or situations where loss of a message could create serious harm.
15. Changes to this policy
This policy may be updated as the service changes. The revised date will appear at the top. Continued use after publication of an updated policy constitutes acceptance to the extent permitted by applicable law.