← BACK TO SHINOBU

PRIVACY POLICY

Last updated: August 2026 · Read before use
PRIVACY, IN ONE LINE
SHINOBU collects almost nothing about you, stores no identity, and cannot read your messages. Message content is encrypted on your device before it ever touches a server.

WHAT WE COLLECT

DATA STORED ON THE SERVER
  • Room codes — the public identifier of each room, required for others to join
  • Anonymous member IDs — a random identifier generated by Firebase Anonymous Auth, used only for presence and message attribution
  • Encrypted message blobs — messages in transit and at rest are AES-256-GCM encrypted. The server stores ciphertext only — never readable text
  • Timestamps — message and membership times, rounded to the minute
  • Display name & color — in group rooms only, the name you choose and a randomly assigned color, stored in room metadata and never linked to real identity
  • Abuse reports — the room code, reason, and anonymous reporter ID you submit via Report Abuse

WHAT WE NEVER COLLECT

NOTHING THAT CAN IDENTIFY YOU
  • No email address
  • No phone number
  • No name, unless you choose one for a group room
  • No IP addresses are stored by the app (your connection is encrypted with TLS 1.3)
  • No readable message content — encryption keys exist only in your browser's URL fragment and are never sent to any server
  • No cookies, trackers, or analytics

HOW DATA IS USED

TECHNICAL OPERATION ONLY
Collected data is used solely to operate the Service: delivering encrypted messages, maintaining presence in rooms, enforcing expiry, and receiving abuse reports. No data is sold, rented, or shared with advertisers. There is nothing to profile — there is no account and no identity.

DATA RETENTION

EPHEMERAL BY DESIGN
  • Live Rooms expire 12 hours after creation
  • Left Messages (mailboxes) expire 7 days after creation
  • Leaving a room removes your member presence; destroying a room removes its data
  • Abuse reports are retained until the operator resolves them
Data is deleted automatically on expiry. Because the Service stores no identity, there is no profile to delete on request — destroying a room deletes everything associated with it.

THIRD PARTIES

GOOGLE FIREBASE
The Service is hosted on Google Firebase (Realtime Database, Firestore, Hosting, and Anonymous Auth). Google processes the data described above on behalf of the operator. Google's privacy practices apply to their infrastructure. See Google's Privacy Policy at policies.google.com/privacy for details.

CHILDREN'S PRIVACY

18+ ONLY
The Service is not directed at individuals under 18. We do not knowingly collect personal information from minors. If you believe a minor has used the Service, contact the operator so the associated data can be removed.

SECURITY

HOW YOUR DATA IS PROTECTED
  • End-to-end encryption: AES-256-GCM with PBKDF2 (SHA-256) key derivation
  • Encryption keys never leave your browser
  • Transport security: TLS 1.3
  • Anonymous authentication gates all database access — no anonymous write access to the database

YOUR RIGHTS

CONTROL OVER YOUR DATA
You control your data by leaving and destroying rooms you create. Since no identity is stored, there is no account data to export or erase on demand. For questions about your data or this policy, contact the operator.

CHANGES TO THIS POLICY

UPDATES
The operator may update this Privacy Policy from time to time. The "Last updated" date above will reflect changes. Continued use of the Service after changes take effect constitutes acceptance.

CONTACT

QUESTIONS
Questions about this Privacy Policy or your data can be directed to the operator through the contact details provided on the Service.