Privacy Policy
Last Updated: 18 September 2026
1. Overview
whodis.chat is built around anonymity: no accounts, no profiles, no chat history visible to other users. But running a safe, moderated chat service means we do process some data — and this policy tells you exactly what, why, and for how long, in plain language. If anything here surprises you, email us at [email protected].
2. Information We Collect
We collect and process the following:
- Text and GIF messages: Messages you send are stored on our servers, together with your IP address and browser fingerprint, so that moderators can act on reports and abuse. They are automatically deleted after 30 days. They are delivered to the other participant. Access to retained copies is restricted to authorised moderation staff, apart from configured processing services described below.
- Connection data: IP addresses and basic connection metadata, used for security, abuse prevention, and ban enforcement.
- Browser fingerprint and a persistent identifier: We compute a device fingerprint (using techniques such as canvas, WebGL, and audio characteristics) and store a persistent identifier in your browser. Security fingerprints help enforce bans and detect ban evasion. Guest identifiers also support mutual connections and allow authorised staff to recognise returning visitors; they are not used for advertising.
- Moderation snapshots: While your camera preview or video chat is running, periodic face thumbnails are captured from your camera feed and retained for up to 90 days, for moderation and ban enforcement.
- Interest tags: Stored locally in your browser and sent to our server during matching. We do not keep a permanent record of your interests.
- Usage data: Anonymous, aggregated statistics about platform usage (such as the number of active users).
3. What We Do Not Collect or Do
- We do not require user accounts, names, email addresses, or phone numbers
- We do not record or store video or audio conversations
- We do not build advertising profiles or sell your data
- We do not show your chat history to other users — other participants cannot browse your retained conversations; authorised staff can access moderation records as described below
4. Video, Audio & Moderation Monitoring
Video and audio use encrypted WebRTC connections through Cloudflare TURN relays. Relay-only connections prevent your chat partner from learning your network IP address through the call. Our service and the relay provider still process connection IP addresses. If a relay connection cannot be established, the call fails rather than falling back to a direct connection. We never record or store these streams.
However, you should know: to enforce our Community Rules, our moderation team may view live video sessions, including audio, while they are in progress — for example when a session is flagged by our automated systems or reported by a user. In addition, periodic face thumbnails are captured from video sessions and retained for up to 90 days to support moderation decisions and ban enforcement. By using video chat, you acknowledge this monitoring.
5. Advertising & Consent
We show Google ads to keep the service free. The Google advertising tag only loads after you accept the consent banner shown on your first visit. If you decline, no advertising scripts are loaded and the banner won't reappear. You can clear your browser's site data to change your choice.
6. Plus Passes
whodis Plus is an optional one-off time pass. Payments are processed by Stripe, who act as an independent controller for the payment itself — card details never reach our servers. We store a pass record (the pass code, the amount and currency, the expiry, and the IP address and device fingerprint the pass was bought from) for 12 months, so that you can restore your pass on another device and so we can detect fraudulent purchases. Passes are non-refundable once you have started using them. Buying a pass does not create an account and does not change what we collect about your chats.
7. Data Retention
How long we keep things:
| Data | Retention |
|---|---|
| Text & GIF messages (with IP and fingerprint) | Deleted after 30 days |
| Moderation face thumbnails | Up to 90 days |
| Ban records & linked device identifiers | Duration of the ban, plus a limited period (up to 180 days) to prevent ban evasion |
| Connection logs (IP, timestamps) | Up to 90 days, or longer where linked to an active ban |
| Video & audio streams | Never recorded or stored |
| Plus pass records (code, expiry, IP, fingerprint) | 12 months |
8. Lawful Bases (UK & EU users)
Where UK/EU data protection law applies, we rely on:
- Legitimate interests — keeping the platform safe: message retention for moderation, moderation monitoring, fingerprinting and persistent identifiers for ban enforcement, and abuse prevention
- Consent — loading Google advertising, which happens only after you accept the consent banner
- Performance of a contract — the processing strictly necessary to connect you with a chat partner and deliver the service, and to sell, restore and honour a whodis Plus pass
9. Your Rights
You have the right to:
- Request access to any personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict the processing of your data
- Complain to your data protection authority (in the UK, the ICO)
To exercise any of these rights, email us at [email protected]. Because we don't have accounts, we may need details such as the approximate time you used the service and your IP address to locate data relating to you.
10. Data Security
We implement reasonable technical and organizational measures to protect the data we process. Video and audio streams are encrypted in transit using WebRTC, and stored moderation data is access-restricted to our moderation team. However, no method of transmission over the internet is completely secure.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date. Your continued use of whodis.chat after changes are posted constitutes acceptance of the revised policy.
12. Contact
For questions or requests regarding this Privacy Policy, please contact us at [email protected].
Guest identity, connections and product measurement
A first-party, HTTP-only cookie identifies this browser with a random token. We store a hash of that token. Optional mutual connections use this identity, not a public profile. Clearing browser data removes your access to those connections. Inactive guest identities and associated connections are removed after 180 days; one-sided contact choices expire after one day.
Conversation references used by these features are kept for 30 days. Case records and internal decisions are retained for up to 90 days after their last update. First-party product milestones and feedback are retained for 90 days; daily visit markers for return-rate measurement are retained for 180 days. Metrics do not contain message contents. Existing moderation and ban-enforcement records have the retention described above.
Optional translation
When a translation provider is configured, choosing Translate displays the provider name and asks you to confirm before sending the selected message. The original message remains visible. The translation service receives the selected text and target language; our product metrics record that translation was used, without copying its text. The provider’s own processing and retention terms also apply.
Configured content screening
Operators may enable Sightengine to analyse selected in-session video thumbnails and text messages in its supported languages. When enabled, this provider receives those samples to identify potential rule violations. It does not receive your guest cookie. Automated scores can create moderator cases and, in enforcement mode, hold messages or end flagged conversations. Human review remains necessary; this is sampled content screening, not continuous video analysis or age verification. Provider outages and unsupported languages are reported as unavailable, not as successful checks.