← Eaves

Eaves Privacy Policy

DRAFT for review by a licensed attorney before publishing. Not legal advice.

Effective date: July 4, 2026

Operator: Currently operated as a sole proprietorship, pending formal LLC formation, based in the United States; referred to throughout as "we," "us," "our," or "the Operator." This section will be updated with the formal entity name once formed.

Contact: eaveshq@gmail.com

Service: Eaves, at https://eaves.up.railway.app

This Privacy Policy (this "Policy") describes how the Operator ("we", "us", or "our") collects, uses, retains, and discloses information in connection with Eaves, available at https://eaves.up.railway.app (the "Service"). "You" and "Your" refer to any person who uses the Service. "Content" means messages, files, images, video, audio, drawings, voice notes, and any other material submitted through the Service. A "Space" means a server or channel within the Service; an "Encrypted Space" means a Space in which the optional message encryption described in Section 3 has been enabled. A "Portal" means a white-label client portal operated by a user of the Service, as described in Section 14.

The Service is currently an invite-only beta. There is no public browsing and no user discovery; user search matches exact usernames only.

Data minimization. The Service asks for as little information as possible. An email address is optional. No phone number, no legal or real name, and no government ID or face scan is required to sign up for or use the Service.

The short version

We ask for as little as possible. An email is optional, and you never need a phone number, your real name, or a government ID or face scan to sign up or use Eaves.

In spaces with encryption turned on, we can't read your messages. They're encrypted, so unless you report one, they stay between you and your chat. Encryption is opt-in, so the person who runs a space has to turn it on. In spaces without it, message text is stored on our server like regular chat.

Photos and videos work a little differently. Every upload gets scanned automatically for illegal content, so a computer looks at it, but no actual person sees your images unless they get reported or flagged. Either way they're locked to your space, so nobody outside can get to them.

Two honest notes. First, even with encryption we can always see activity around your messages, like who talks to whom and when. Second, if you forget your password and lose your recovery code, your encrypted message history is gone for good. Nobody, including us, can bring it back.

If there's ever a data breach that affects your information, we'll tell you as the law requires.

The remainder of this Policy is the operative text. Where the short version and the numbered Sections differ, the numbered Sections control.

1. Information We Collect

1.1 Account Data. We collect:

  1. Your username and display name;
  2. Your email address, which is optional; the Service may be used without one. Email addresses are stored in lowercased form;
  3. a salted hash of Your password (salted scrypt). We never store Your password itself. Password hashes created under an older scheme are upgraded to the current scheme upon Your next successful login; and
  4. profile data You provide: avatar, banner, biography, and pronouns.

1.2 Content. We collect and store:

  1. messages, stored as plaintext in non-encrypted Spaces and as ciphertext in Encrypted Spaces;
  2. files You upload, including images, video, audio, and documents; and
  3. drawings, Portal deliveries, and voice notes (Opus recordings in Portal booths).

1.3 Metadata. The following metadata is visible to us at all times, regardless of encryption: who communicates with whom, when, and how often; Space membership; file sizes and types; timestamps; reactions; pins; and edits.

1.4 Security and Technical Data. We collect:

  1. IP addresses, recorded when You register, log in, or create a temporary account, used for rate limiting and to enforce bans (including IP bans for ban evasion);
  2. push notification tokens (Firebase Cloud Messaging, per device);
  3. two-factor authentication data. If You use an authenticator app, we store the TOTP secret encrypted at rest; the server must be able to read the secret to verify Your codes, so it is encrypted rather than hashed. Email two-factor codes are stored hashed;
  4. session tokens (Section 10);
  5. error and diagnostic data via Sentry, under a privacy-minimizing configuration; and
  6. per-connection call statistics (in rollout): whether a call connection is direct or relayed, and byte counts, used to meter relay costs. These statistics do not include call content.

1.5 Payment Data. Payments are handled by Stripe. We store Your Stripe customer, subscription, and invoice identifiers, Your plan, and a ledger of Your credits. We never see or store card numbers.

1.6 Report Evidence. If You report a live camera or screen-share stream, the reporting flow captures approximately three still frames of the reported stream on Your device and uploads them as evidence. That evidence is quarantined, attributed to the reported user, and may be held for up to one year.

1.7 Sensitive Information You Choose to Share. We do not ask You to provide health, religious, sexual-orientation, immigration-status, or similarly sensitive information. You may choose to include this kind of information in Your own messages, files, or profile fields (such as pronouns); if You do, it is stored and handled the same as any other Content or profile data described in this Policy, and we do not use it to profile You or for any purpose beyond operating the Service.

2. How We Use Information

2.1 To operate the Service: delivering messages, connecting calls, storing and serving files, and synchronizing activities.

2.2 To secure accounts: sessions, two-factor authentication, rate limiting, and ban enforcement, including IP-based ban-evasion checks.

2.3 To moderate Content: automated scanning of uploads and review of reported Content (Sections 5 and 7).

2.4 To send notifications You have enabled: push notifications, and email (if You provided an address) for verification, password reset, and email two-factor codes.

2.5 To process payments, subscriptions, and credits through Stripe.

2.6 To monitor errors and maintain the reliability of the Service (Sentry).

2.7 To meter relay costs for calls, using the connection statistics described in Section 1.4.

2.8 We do not sell Your personal information. We share data with the service providers listed in Section 8, with other users as an inherent part of the Service, with the business that runs any Portal You use (Section 14), and with authorities where the law requires or permits it (Section 7).

2.9 Some in-call activities send the text You submit during that activity to a third-party AI service in real time to generate a response for gameplay purposes (Section 8.1). This is not used to train or improve any AI or machine learning model. When You use an activity of this kind, You are interacting with an automated system, not a human.

3. Encryption: Scope and Limits

3.1 Opt-In, Per Space, Text Only. Encryption is opt-in, applies per Space, and covers text only. The owner of a Space may enable encryption in that Space's settings. Encryption is not enabled by default. Messages sent before encryption was enabled remain unencrypted permanently.

3.2 Encrypted Spaces. We do not have access to encrypted message content in the normal course of operation. This Policy states the limitation in those terms, rather than as an impossibility, for two reasons:

  1. Reporting. Reporting a message discloses that message and a span of surrounding context (not only the reported message) to reviewers, so reviewers have enough context to evaluate the report. By accepting the Terms of Service, which incorporates this Policy, You agree that this process applies to any message You send. If You submit the report, You additionally consent to that specific disclosure by choosing to report. If another participant reports a message from a conversation You are part of, the same span may include messages You sent; that disclosure is authorized by Your acceptance of the Terms of Service rather than by any separate act of consent on Your part for that instance, and reviewers see only the reported span, not Your full message history.
  2. Web-delivered code. The web client executes JavaScript served by the Operator. Code capable of reading message text on Your device could technically be served. We do not do this, but the design cannot make it impossible.

3.3 Non-Encrypted Spaces. Message text is stored on our server and is readable by us.

3.4 Files Excluded. Files, images, and videos are never end-to-end encrypted, including in Encrypted Spaces (Section 5).

3.5 Key Loss Is Permanent. If You forget Your password and lose Your recovery code, Your encrypted message history is permanently and unrecoverably lost. There is no Operator-side recovery of any kind. Store Your recovery code securely.

3.6 Verification. Encrypted Spaces use trust-on-first-use key pinning, and You may verify a contact using a 60-digit safety number. Verification is a tripwire for interception; it does not protect against a stolen key, a compromised device, or a contact who shares Your messages.

3.7 Search. Search over encrypted messages runs on Your device, not on our servers.

4. Metadata Visibility

4.1 End-to-end encryption conceals message content only. We can always see who communicates with whom, when, and how often; Space membership; file sizes and types; IP addresses; push tokens; and, as the feature rolls out, whether call connections are direct or relayed and their byte counts. Nothing in this Policy shall be read as a promise of metadata privacy.

5. Uploads and Automated Scanning

5.1 Uploaded files are not end-to-end encrypted. They are stored in Cloudflare R2 and are readable by the Operator. They are access-controlled to Your Space: private from other users and from the public, but not private from the Operator.

5.2 Every upload is processed by automated systems that check for illegal and policy-violating Content, including industry hash-matching as deployed. By surface:

  1. avatars, profile banners, and server icons are scanned server-side using the Sightengine moderation API;
  2. chat images are scanned on Your device by a classifier, both before sending and on receipt;
  3. chat videos are frame-sampled and scanned on-device, with a server-side check as a tiebreaker; and
  4. drawings and link-preview images are scanned on-device.

5.3 No human reviews Your uploads unless they are reported by a user or flagged by the automated scan. A flag quarantines the Content (hides and preserves it); it does not delete it. A platform administrator may then view the flagged Content to release a false positive, remove it, or escalate it (Section 7).

5.4 Live voice, video, and screen-share streams are peer-to-peer and are not scanned by any system. User reporting is the only moderation path for live streams, using the frame-capture evidence described in Section 1.6.

5.5 Our automated scanning classifies image and video content for policy violations (such as nudity or gore). It does not perform facial recognition or voice-identification, and does not create or store biometric identifiers as defined by Illinois's Biometric Information Privacy Act or similar state biometric-privacy statutes.

6. Where Your Data Is Stored

6.1 Eaves is operated from the United States. The database (PostgreSQL) runs on Railway. Uploaded files are stored in Cloudflare R2.

6.2 Voice, video, and screen sharing run peer-to-peer between participants over WebRTC. Where a direct connection is not possible, media is relayed through TURN servers operated by third parties (Section 8).

7. Moderation, Reporting, and CSAM Handling

7.1 Reporting. Any member may report Content or a live stream. Stream reports are rate-limited and require a reason selected from a fixed list. Reporting a live stream captures evidence frames as described in Section 1.6.

7.2 Review. Automated flags quarantine Content. A platform administrator reviews quarantined Content and may release it (false positive), remove it, or escalate it to a legal hold. Moderation actions are recorded in an audit log.

7.3 Child Sexual Abuse Material ("CSAM"). We comply with US law (18 U.S.C. 2258A). Confirmed CSAM is:

  1. placed under a terminal legal hold: it is never re-served, never deletable, and not re-viewable, even by administrators;
  2. reported to the National Center for Missing and Exploited Children ("NCMEC") through the CyberTipline; and
  3. preserved in access-minimized storage for one year after the NCMEC report, as required by 18 U.S.C. 2258A(h).

7.4 Reporting Trigger. A report to NCMEC is triggered when we obtain actual knowledge of apparent CSAM, through a user report or an automated flag. US law does not require us to proactively monitor all Content; the upload scanning described in Section 5 is a design choice we disclose. This reporting duty is not limited to images or video; it extends to any apparent violation enumerated in 18 U.S.C. 2258A, including text-based content, when we obtain actual knowledge of it.

7.5 Legal Holds. Content preserved under a legal hold survives account deletion for the duration the law requires. Flagged Content may be reported to law enforcement or other authorities where the law requires or permits it.

7.6 Non-Consensual Intimate Imagery. Content depicting an identifiable, real individual in an intimate or sexually explicit context, shared without that individual's consent, including a realistic image or video generated or altered by AI, may be reported through the process described in this Section 7. On receiving a valid, sufficiently specific report identifying such content, we will remove or disable access to it within 48 hours, consistent with the federal TAKE IT DOWN Act.

7.7 Role as a Service Provider. We provide an interactive computer service within the meaning of 47 U.S.C. 230 and do not treat ourselves as the publisher or speaker of content a user submits. We do not independently verify, endorse, or vouch for the accuracy, legality, or appropriateness of any user's content.

8. Third-Party Service Providers

8.1 We use the following service providers:

ProviderWhat it does with Your data
RailwayHosting and the PostgreSQL database (account data, messages, metadata)
Cloudflare R2Stores uploaded files and Portal deliveries
CloudflareCDN; CSAM hash-scanning as deployed
SightengineImage moderation API (avatars, banners, server icons, and video-frame tiebreak checks)
Firebase / FCM (Google)Push notifications; we store per-device push tokens
StripePayments: checkout, subscriptions, customer portal. Payment methods such as Klarna, Link, Cash App Pay, and Amazon Pay are offered through Stripe and are subject to their own terms
SentryError monitoring, configured to minimize personal data
ResendSends email: verification, password reset, and email two-factor codes
NCMECReceives CSAM reports, only when a report is filed
Cerebras (or a successor AI/LLM provider)Processes user-submitted text in real time to power the AI-judged in-call activity; not used to train any AI or machine learning model

8.2 The following third parties are also in the data path:

  1. STUN and TURN servers (Google STUN; Open Relay Project / Metered TURN) assist in establishing call connections. When a call cannot connect directly, media packets transiting these relay servers carry standard WebRTC transport encryption; this is separate from, and not the same as, the opt-in message encryption described in Section 3.
  2. YouTube (Google) powers the watch-together feature via the embedded player and search API. Using it loads YouTube content in Your browser under Google's policies.
  3. CDN-served libraries (jsDelivr, and the Hugging Face CDN for the on-device moderation model) are fetched by Your browser, which exposes Your IP address to those CDNs in the same manner as any web resource.

9. Data Retention

9.1 We retain data for the following periods:

DataRetention period
Chat messagesConfigurable per Space by its owner: 1, 3, 7, 14, 30, 90, 180, or 365 days. Default 30 days. Pinned messages do not expire while pinned; unpinning restarts a fresh retention window
Chat file uploadsDefault approximately 30 days; configurable per Space from 1 to 90 days. Pinned files do not expire; removing the last pin restarts the countdown
Pinned storagePlan-tiered: 3 GB free, 20 GB for Supporters. On downgrade while over the cap, over-cap pins freeze read-only for approximately one year (downloadable throughout, with an export offered; resubscribing restores them immediately), then revert to normal file expiry
Portal deliveriesDefault 60 days per Portal; extendable, or marked keep-forever per delivery
Sessions30 days; revoked server-side on logout; expired sessions purged hourly
Temporary (guest) accounts24 hours, then invalid
Stream-report evidenceUp to 1 year
CSAM / legal-hold Content1 year after the NCMEC report, under the terminal hold described in Section 7

9.2 IP records and security logs are retained for as long as needed for rate limiting, ban enforcement, and abuse prevention; ban-related IP records persist while the ban does.

10. Cookies and Sessions

10.1 The Service uses a single first-party session cookie, authToken. It is httpOnly, marked secure in production, uses sameSite lax, and lasts 30 days. Sessions are stored server-side in the database and are revoked when You log out; expired sessions are purged hourly. We do not use advertising cookies or cross-site tracking cookies.

10.2 Temporary (guest) accounts are passwordless and email-less, expire after 24 hours, are restricted from certain actions, and may be converted in place to a full account (retaining their identifier and messages). Banned IPs cannot create temporary accounts.

10.3 We do not currently respond differently to a browser "Do Not Track" signal; as stated in Section 10.1, we do not use advertising cookies or cross-site tracking cookies regardless of that setting.

11. Your Rights and Account Deletion

11.1 Deletion. You may delete Your account in the application. Deletion clears Your account data. The following survive deletion: messages that other users have already received; ciphertext backups of encrypted Content; and any Content under quarantine or a legal hold that the law requires us to preserve (Section 7).

11.1.1 Why encrypted messages survive. Ciphertext backups of encrypted messages survive deletion because a Space's message history is shared among its members; deleting Your account does not erase a conversation from the side of members who already received it, the same way leaving any group conversation does not erase Your past messages from other participants' view. This does not change our access: those messages remain governed by Section 3, and we do not have access to their content in the normal course of operation after Your account is deleted, any more than before.

11.2 Email Is Optional. You can use Eaves without providing an email address.

11.3 Access and Correction. You may edit Your profile data in the application at any time. Other requests may be directed to us at eaveshq@gmail.com; because an account may have no email on file, we may ask You to verify Your identity, such as by confirming details only the account holder would know, before acting on a request made this way.

11.4 Export and Portability. You may download an export of Your account data at any time from the application's account settings ("Download My Data"), covering Your profile, server memberships, friends, friend requests, blocked users, messages You authored, files You uploaded, pinned-file records (a full ZIP of the pinned files themselves is available separately), credits ledger, and reports You filed. Content other users authored, reports filed against You, and who has blocked You, are not included, as that is not Your own data. You may also contact us at eaveshq@gmail.com with further data requests. If You delete Your account, Your data is actually removed, subject only to the items listed in Section 11.1 that survive deletion, such as messages other users have already received.

11.5 Removing Your Own Content. You may delete Your own messages and files at any time using the Service's delete features. This is the mechanism by which You, including as a minor, may remove content You posted.

12. Age Policy and Minors

12.1 The Service is offered to persons 13 years of age and older. We do not knowingly collect data from anyone under 13, and we do not offer the Service to them. If we learn that an account belongs to a child under 13, we will delete the account and that child's personal information, subject to the same limited exceptions described in Section 11.1 for content already delivered to other users and content under a legal hold.

12.2 If You are 13 to 17 years of age, You must have the permission of a parent or guardian to use the Service and to make any purchase. Purchases made by minors may be voidable under the laws of some states. If advertising is ever shown to minors, it will be non-personalized only (Section 13).

13. Advertising and Tracking

13.1 The Service currently shows no advertising and performs no cross-site tracking.

13.2 We are considering an optional rewarded-ads feature: US-only, opt-in, browser-only, in which watching one advertisement earns one credit. If the feature ships, the advertising network will perform its own tracking, which we will disclose in this Policy before launch; participation will require Your explicit opt-in, and minors will be shown non-personalized ads only. If that tracking involves sharing information with the ad network for cross-context advertising, we will provide an opt-out consistent with applicable law, such as a "Do Not Sell or Share" mechanism and support for recognized browser opt-out signals, before the feature launches. We will update this Policy before any advertising feature goes live.

14. Client Portals (Businesses and Their Clients)

14.1 Any user may operate a white-label Portal for that user's business. Each customer of the business receives an isolated booth (files, chat, calendar); clients never see each other. Clients claim full Eaves accounts through the business's branded invite page.

14.2 Controller and Processor. If You are a Portal client, the business that runs the Portal is the controller of the data it collects from You through its Portal, and it is responsible for its relationship with You, its branding, and what it collects. We are the processor and host providing the infrastructure. Direct questions about how the business uses Your data to the business first.

14.3 Portal Specifics.

  1. Portal Content is not end-to-end encrypted. This is a deliberate design decision; do not expect encrypted-text-level protection in Portals.
  2. Portal media passes through the same moderation pipeline as other uploads (Section 5).
  3. Deliveries are stored in Cloudflare R2 and expire per Section 9 unless extended or marked keep-forever.
  4. The business can see when You download deliveries (download receipts and an activity feed).
  5. Booth chat supports push notifications and voice notes, which are stored as recordings.

15. Payments

15.1 Payments are processed by Stripe through Stripe-hosted checkout and the Stripe customer portal. We store the Stripe identifiers, plan status, and credit ledger described in Section 1; we never see or store card numbers. Credits are store credit only: non-refundable, non-withdrawable, and never expiring. Purchase terms are set out in the Terms of Service; this Section describes only the data involved.

16. US State Privacy Laws; International Users; Governing Law

16.1 The Service is operated from the United States, and this Policy is written for US law. If You use the Service from the European Union or the United Kingdom, laws there (including the GDPR, the EU Digital Services Act, and the UK Online Safety Act) impose requirements this Policy does not yet address; we do not currently target those markets.

16.2 This Policy and any disputes concerning it are governed by the laws of New Jersey.

16.3 A number of US states have their own comprehensive consumer privacy laws that grant rights such as access, deletion, correction, and opting out of the sale or sharing of personal information, generally once a business meets that state's size or revenue thresholds. We do not believe the Service currently meets those thresholds. If and when it does, we will update this Policy to add the specific rights, request process, and opt-out mechanisms that law requires.

16.4 Export control and sanctions. The Service, including its encryption features, may be subject to United States export control and economic sanctions laws; see Terms of Service Section 19.2 for the representation this requires of You.

16.5 Age-verification and youth-online-safety laws. Some jurisdictions require app marketplaces or developers to verify a user's age or a parent's consent for a minor's account. Where such a law applies to Your use of the Service, we will implement the mechanisms it requires as they become applicable to us.

16.6 AI-system transparency. Some jurisdictions require disclosure when a person is interacting with an AI system. Section 2.9 describes and discloses the Service's AI-assisted activity.

17. Law Enforcement and Government Requests

17.1 Legal Process Required. We disclose user information to law enforcement or government agencies only when required by valid legal process, such as a subpoena, court order, or warrant.

17.2 Notice to You. Where legally permitted, we will make reasonable efforts to notify the affected user before disclosing that user's information, unless doing so would endanger someone or is prohibited.

17.3 Transparency Report. We intend to publish a periodic transparency report stating the number of such requests received.

17.4 Relationship to CSAM Reporting. This Section is separate from, and does not affect, the mandatory reporting of child sexual abuse material to NCMEC described in Section 7.

18. Data Security and Breach Notification

18.1 We use reasonable technical and organizational measures designed to protect the information described in this Policy, including password hashing, encrypted session cookies, and the encryption and access controls described in Sections 3 through 5. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.

18.2 If we become aware of a breach of security compromising your personal information in a manner that triggers a notification obligation under applicable law, we will notify affected users without unreasonable delay and in the manner required by that law, describing, to the extent known at the time, the nature of the breach, the categories of information involved, and the steps we are taking and recommend you take in response. Where required, we will also notify the regulators or authorities specified by applicable law.

19. Changes to This Policy

19.1 We may update this Policy. Upon any update, we will revise the effective date above. For material changes, we will notify You in the application, by email if You provided an address, or both, before the changes take effect where practical. We will keep a dated version history of this Policy so that changes are visible rather than silent.

20. Contact

20.1 Questions, privacy requests, or concerns may be directed to eaveshq@gmail.com.


Reminder: this document is a DRAFT for review by a licensed attorney before publishing. It is not legal advice.
See also the Terms of Service.