Home

Privacy

Updated October 4, 2026

Poof provides voice and text chat without accounts. This page describes how the prototype handles your data.

Conversations

Your voice and messages are sent directly to other people in your room when possible. Cloudflare relays encrypted traffic when a direct connection is unavailable. Poof does not record audio or store chat history on its servers. New arrivals only receive messages sent after they join.

Voice and messages are encrypted between participants' browsers, including when relayed. Direct connections can reveal your public IP address to other participants. Other participants can copy or record what you share.

In your browser

Your nickname, anonymous identity, room access tokens and analytics preference are saved in your browser. This tab keeps the last 100 messages. Leaving clears its local chat history; closing the tab clears its messages. Clear this site's browser data to remove your saved identity and preferences.

Room data

We store room codes, creation and expiry times, capacity, lock status, anonymous participant identifiers used for host controls, and a hash of the host key in Cloudflare D1. This data runs rooms and supports moderation. Each room also uses a Cloudflare Durable Object to keep its connection list, nicknames, admission and removal state, and exchange connection details. Audio and messages do not pass through it.

Rooms expire after 24 hours. Scheduled cleanup removes room metadata and coordination data about an hour after expiry or closure. An hourly batch also removes expired metadata.

Service providers

Cloudflare hosts the website and API, coordinates room connections, and provides the fallback relay. It processes connection information such as IP addresses and device details to operate and protect the service. Provider logs may have different retention periods from room data.

Optional analytics

Analytics is off by default. If enabled and configured, PostHog receives events for creating, joining, and leaving rooms and enabling a microphone, along with basic browser and device information. We exclude messages, assigned names, room codes, and page URLs. Session recording and automatic click tracking are disabled. Do Not Track prevents analytics events.

You can turn this off below to stop future usage events from this browser.

Your choices

Keep your microphone off and share room links only with people you want to join. Hosts can lock rooms, remove participants, or close rooms. Participant removal is tied to a browser session and does not prevent someone from returning in a new session.

Changes

We will update this page and its date when data handling changes.