This Privacy Policy (this "Policy") describes how the Operator ("we", "us", or "our") collects, uses, retains, and discloses information in connection with Eaves, available at https://eaves.up.railway.app (the "Service"). "You" and "Your" refer to any person who uses the Service. "Content" means messages, files, images, video, audio, drawings, voice notes, and any other material submitted through the Service. A "Space" means a server or channel within the Service; an "Encrypted Space" means a Space in which the optional message encryption described in Section 3 has been enabled. A "Portal" means a white-label client portal operated by a user of the Service, as described in Section 14.
The Service is currently an invite-only beta. There is no public browsing and no user discovery; user search matches exact usernames only.
Data minimization. The Service asks for as little information as possible. An email address is optional. No phone number, no legal or real name, and no government ID or face scan is required to sign up for or use the Service.
We ask for as little as possible. An email is optional, and you never need a phone number, your real name, or a government ID or face scan to sign up or use Eaves.
In spaces with encryption turned on, we can't read your messages. They're encrypted, so unless you report one, they stay between you and your chat. Encryption is opt-in, so the person who runs a space has to turn it on. In spaces without it, message text is stored on our server like regular chat.
Photos and videos work a little differently. Every upload gets scanned automatically for illegal content, so a computer looks at it, but no actual person sees your images unless they get reported or flagged. Either way they're locked to your space, so nobody outside can get to them.
Two honest notes. First, even with encryption we can always see activity around your messages, like who talks to whom and when. Second, if you forget your password and lose your recovery code, your encrypted message history is gone for good. Nobody, including us, can bring it back.
If there's ever a data breach that affects your information, we'll tell you as the law requires.
The remainder of this Policy is the operative text. Where the short version and the numbered Sections differ, the numbered Sections control.
1.1 Account Data. We collect:
1.2 Content. We collect and store:
1.3 Metadata. The following metadata is visible to us at all times, regardless of encryption: who communicates with whom, when, and how often; Space membership; file sizes and types; timestamps; reactions; pins; and edits.
1.4 Security and Technical Data. We collect:
1.5 Payment Data. Payments are handled by Stripe. We store Your Stripe customer, subscription, and invoice identifiers, Your plan, and a ledger of Your credits. We never see or store card numbers.
1.6 Report Evidence. If You report a live camera or screen-share stream, the reporting flow captures approximately three still frames of the reported stream on Your device and uploads them as evidence. That evidence is quarantined, attributed to the reported user, and may be held for up to one year.
1.7 Sensitive Information You Choose to Share. We do not ask You to provide health, religious, sexual-orientation, immigration-status, or similarly sensitive information. You may choose to include this kind of information in Your own messages, files, or profile fields (such as pronouns); if You do, it is stored and handled the same as any other Content or profile data described in this Policy, and we do not use it to profile You or for any purpose beyond operating the Service.
2.1 To operate the Service: delivering messages, connecting calls, storing and serving files, and synchronizing activities.
2.2 To secure accounts: sessions, two-factor authentication, rate limiting, and ban enforcement, including IP-based ban-evasion checks.
2.3 To moderate Content: automated scanning of uploads and review of reported Content (Sections 5 and 7).
2.4 To send notifications You have enabled: push notifications, and email (if You provided an address) for verification, password reset, and email two-factor codes.
2.5 To process payments, subscriptions, and credits through Stripe.
2.6 To monitor errors and maintain the reliability of the Service (Sentry).
2.7 To meter relay costs for calls, using the connection statistics described in Section 1.4.
2.8 We do not sell Your personal information. We share data with the service providers listed in Section 8, with other users as an inherent part of the Service, with the business that runs any Portal You use (Section 14), and with authorities where the law requires or permits it (Section 7).
2.9 Some in-call activities send the text You submit during that activity to a third-party AI service in real time to generate a response for gameplay purposes (Section 8.1). This is not used to train or improve any AI or machine learning model. When You use an activity of this kind, You are interacting with an automated system, not a human.
3.1 Opt-In, Per Space, Text Only. Encryption is opt-in, applies per Space, and covers text only. The owner of a Space may enable encryption in that Space's settings. Encryption is not enabled by default. Messages sent before encryption was enabled remain unencrypted permanently.
3.2 Encrypted Spaces. We do not have access to encrypted message content in the normal course of operation. This Policy states the limitation in those terms, rather than as an impossibility, for two reasons:
3.3 Non-Encrypted Spaces. Message text is stored on our server and is readable by us.
3.4 Files Excluded. Files, images, and videos are never end-to-end encrypted, including in Encrypted Spaces (Section 5).
3.5 Key Loss Is Permanent. If You forget Your password and lose Your recovery code, Your encrypted message history is permanently and unrecoverably lost. There is no Operator-side recovery of any kind. Store Your recovery code securely.
3.6 Verification. Encrypted Spaces use trust-on-first-use key pinning, and You may verify a contact using a 60-digit safety number. Verification is a tripwire for interception; it does not protect against a stolen key, a compromised device, or a contact who shares Your messages.
3.7 Search. Search over encrypted messages runs on Your device, not on our servers.
4.1 End-to-end encryption conceals message content only. We can always see who communicates with whom, when, and how often; Space membership; file sizes and types; IP addresses; push tokens; and, as the feature rolls out, whether call connections are direct or relayed and their byte counts. Nothing in this Policy shall be read as a promise of metadata privacy.
5.1 Uploaded files are not end-to-end encrypted. They are stored in Cloudflare R2 and are readable by the Operator. They are access-controlled to Your Space: private from other users and from the public, but not private from the Operator.
5.2 Every upload is processed by automated systems that check for illegal and policy-violating Content, including industry hash-matching as deployed. By surface:
5.3 No human reviews Your uploads unless they are reported by a user or flagged by the automated scan. A flag quarantines the Content (hides and preserves it); it does not delete it. A platform administrator may then view the flagged Content to release a false positive, remove it, or escalate it (Section 7).
5.4 Live voice, video, and screen-share streams are peer-to-peer and are not scanned by any system. User reporting is the only moderation path for live streams, using the frame-capture evidence described in Section 1.6.
5.5 Our automated scanning classifies image and video content for policy violations (such as nudity or gore). It does not perform facial recognition or voice-identification, and does not create or store biometric identifiers as defined by Illinois's Biometric Information Privacy Act or similar state biometric-privacy statutes.
6.1 Eaves is operated from the United States. The database (PostgreSQL) runs on Railway. Uploaded files are stored in Cloudflare R2.
6.2 Voice, video, and screen sharing run peer-to-peer between participants over WebRTC. Where a direct connection is not possible, media is relayed through TURN servers operated by third parties (Section 8).
7.1 Reporting. Any member may report Content or a live stream. Stream reports are rate-limited and require a reason selected from a fixed list. Reporting a live stream captures evidence frames as described in Section 1.6.
7.2 Review. Automated flags quarantine Content. A platform administrator reviews quarantined Content and may release it (false positive), remove it, or escalate it to a legal hold. Moderation actions are recorded in an audit log.
7.3 Child Sexual Abuse Material ("CSAM"). We comply with US law (18 U.S.C. 2258A). Confirmed CSAM is:
7.4 Reporting Trigger. A report to NCMEC is triggered when we obtain actual knowledge of apparent CSAM, through a user report or an automated flag. US law does not require us to proactively monitor all Content; the upload scanning described in Section 5 is a design choice we disclose. This reporting duty is not limited to images or video; it extends to any apparent violation enumerated in 18 U.S.C. 2258A, including text-based content, when we obtain actual knowledge of it.
7.5 Legal Holds. Content preserved under a legal hold survives account deletion for the duration the law requires. Flagged Content may be reported to law enforcement or other authorities where the law requires or permits it.
7.6 Non-Consensual Intimate Imagery. Content depicting an identifiable, real individual in an intimate or sexually explicit context, shared without that individual's consent, including a realistic image or video generated or altered by AI, may be reported through the process described in this Section 7. On receiving a valid, sufficiently specific report identifying such content, we will remove or disable access to it within 48 hours, consistent with the federal TAKE IT DOWN Act.
7.7 Role as a Service Provider. We provide an interactive computer service within the meaning of 47 U.S.C. 230 and do not treat ourselves as the publisher or speaker of content a user submits. We do not independently verify, endorse, or vouch for the accuracy, legality, or appropriateness of any user's content.
8.1 We use the following service providers:
| Provider | What it does with Your data |
|---|---|
| Railway | Hosting and the PostgreSQL database (account data, messages, metadata) |
| Cloudflare R2 | Stores uploaded files and Portal deliveries |
| Cloudflare | CDN; CSAM hash-scanning as deployed |
| Sightengine | Image moderation API (avatars, banners, server icons, and video-frame tiebreak checks) |
| Firebase / FCM (Google) | Push notifications; we store per-device push tokens |
| Stripe | Payments: checkout, subscriptions, customer portal. Payment methods such as Klarna, Link, Cash App Pay, and Amazon Pay are offered through Stripe and are subject to their own terms |
| Sentry | Error monitoring, configured to minimize personal data |
| Resend | Sends email: verification, password reset, and email two-factor codes |
| NCMEC | Receives CSAM reports, only when a report is filed |
| Cerebras (or a successor AI/LLM provider) | Processes user-submitted text in real time to power the AI-judged in-call activity; not used to train any AI or machine learning model |
8.2 The following third parties are also in the data path:
9.1 We retain data for the following periods:
| Data | Retention period |
|---|---|
| Chat messages | Configurable per Space by its owner: 1, 3, 7, 14, 30, 90, 180, or 365 days. Default 30 days. Pinned messages do not expire while pinned; unpinning restarts a fresh retention window |
| Chat file uploads | Default approximately 30 days; configurable per Space from 1 to 90 days. Pinned files do not expire; removing the last pin restarts the countdown |
| Pinned storage | Plan-tiered: 3 GB free, 20 GB for Supporters. On downgrade while over the cap, over-cap pins freeze read-only for approximately one year (downloadable throughout, with an export offered; resubscribing restores them immediately), then revert to normal file expiry |
| Portal deliveries | Default 60 days per Portal; extendable, or marked keep-forever per delivery |
| Sessions | 30 days; revoked server-side on logout; expired sessions purged hourly |
| Temporary (guest) accounts | 24 hours, then invalid |
| Stream-report evidence | Up to 1 year |
| CSAM / legal-hold Content | 1 year after the NCMEC report, under the terminal hold described in Section 7 |
9.2 IP records and security logs are retained for as long as needed for rate limiting, ban enforcement, and abuse prevention; ban-related IP records persist while the ban does.
10.1 The Service uses a single first-party session cookie, authToken. It is httpOnly, marked secure in production, uses sameSite lax, and lasts 30 days. Sessions are stored server-side in the database and are revoked when You log out; expired sessions are purged hourly. We do not use advertising cookies or cross-site tracking cookies.
10.2 Temporary (guest) accounts are passwordless and email-less, expire after 24 hours, are restricted from certain actions, and may be converted in place to a full account (retaining their identifier and messages). Banned IPs cannot create temporary accounts.
10.3 We do not currently respond differently to a browser "Do Not Track" signal; as stated in Section 10.1, we do not use advertising cookies or cross-site tracking cookies regardless of that setting.
11.1 Deletion. You may delete Your account in the application. Deletion clears Your account data. The following survive deletion: messages that other users have already received; ciphertext backups of encrypted Content; and any Content under quarantine or a legal hold that the law requires us to preserve (Section 7).
11.1.1 Why encrypted messages survive. Ciphertext backups of encrypted messages survive deletion because a Space's message history is shared among its members; deleting Your account does not erase a conversation from the side of members who already received it, the same way leaving any group conversation does not erase Your past messages from other participants' view. This does not change our access: those messages remain governed by Section 3, and we do not have access to their content in the normal course of operation after Your account is deleted, any more than before.
11.2 Email Is Optional. You can use Eaves without providing an email address.
11.3 Access and Correction. You may edit Your profile data in the application at any time. Other requests may be directed to us at eaveshq@gmail.com; because an account may have no email on file, we may ask You to verify Your identity, such as by confirming details only the account holder would know, before acting on a request made this way.
11.4 Export and Portability. You may download an export of Your account data at any time from the application's account settings ("Download My Data"), covering Your profile, server memberships, friends, friend requests, blocked users, messages You authored, files You uploaded, pinned-file records (a full ZIP of the pinned files themselves is available separately), credits ledger, and reports You filed. Content other users authored, reports filed against You, and who has blocked You, are not included, as that is not Your own data. You may also contact us at eaveshq@gmail.com with further data requests. If You delete Your account, Your data is actually removed, subject only to the items listed in Section 11.1 that survive deletion, such as messages other users have already received.
11.5 Removing Your Own Content. You may delete Your own messages and files at any time using the Service's delete features. This is the mechanism by which You, including as a minor, may remove content You posted.
12.1 The Service is offered to persons 13 years of age and older. We do not knowingly collect data from anyone under 13, and we do not offer the Service to them. If we learn that an account belongs to a child under 13, we will delete the account and that child's personal information, subject to the same limited exceptions described in Section 11.1 for content already delivered to other users and content under a legal hold.
12.2 If You are 13 to 17 years of age, You must have the permission of a parent or guardian to use the Service and to make any purchase. Purchases made by minors may be voidable under the laws of some states. If advertising is ever shown to minors, it will be non-personalized only (Section 13).
13.1 The Service currently shows no advertising and performs no cross-site tracking.
13.2 We are considering an optional rewarded-ads feature: US-only, opt-in, browser-only, in which watching one advertisement earns one credit. If the feature ships, the advertising network will perform its own tracking, which we will disclose in this Policy before launch; participation will require Your explicit opt-in, and minors will be shown non-personalized ads only. If that tracking involves sharing information with the ad network for cross-context advertising, we will provide an opt-out consistent with applicable law, such as a "Do Not Sell or Share" mechanism and support for recognized browser opt-out signals, before the feature launches. We will update this Policy before any advertising feature goes live.
14.1 Any user may operate a white-label Portal for that user's business. Each customer of the business receives an isolated booth (files, chat, calendar); clients never see each other. Clients claim full Eaves accounts through the business's branded invite page.
14.2 Controller and Processor. If You are a Portal client, the business that runs the Portal is the controller of the data it collects from You through its Portal, and it is responsible for its relationship with You, its branding, and what it collects. We are the processor and host providing the infrastructure. Direct questions about how the business uses Your data to the business first.
14.3 Portal Specifics.
15.1 Payments are processed by Stripe through Stripe-hosted checkout and the Stripe customer portal. We store the Stripe identifiers, plan status, and credit ledger described in Section 1; we never see or store card numbers. Credits are store credit only: non-refundable, non-withdrawable, and never expiring. Purchase terms are set out in the Terms of Service; this Section describes only the data involved.
16.1 The Service is operated from the United States, and this Policy is written for US law. If You use the Service from the European Union or the United Kingdom, laws there (including the GDPR, the EU Digital Services Act, and the UK Online Safety Act) impose requirements this Policy does not yet address; we do not currently target those markets.
16.2 This Policy and any disputes concerning it are governed by the laws of New Jersey.
16.3 A number of US states have their own comprehensive consumer privacy laws that grant rights such as access, deletion, correction, and opting out of the sale or sharing of personal information, generally once a business meets that state's size or revenue thresholds. We do not believe the Service currently meets those thresholds. If and when it does, we will update this Policy to add the specific rights, request process, and opt-out mechanisms that law requires.
16.4 Export control and sanctions. The Service, including its encryption features, may be subject to United States export control and economic sanctions laws; see Terms of Service Section 19.2 for the representation this requires of You.
16.5 Age-verification and youth-online-safety laws. Some jurisdictions require app marketplaces or developers to verify a user's age or a parent's consent for a minor's account. Where such a law applies to Your use of the Service, we will implement the mechanisms it requires as they become applicable to us.
16.6 AI-system transparency. Some jurisdictions require disclosure when a person is interacting with an AI system. Section 2.9 describes and discloses the Service's AI-assisted activity.
17.1 Legal Process Required. We disclose user information to law enforcement or government agencies only when required by valid legal process, such as a subpoena, court order, or warrant.
17.2 Notice to You. Where legally permitted, we will make reasonable efforts to notify the affected user before disclosing that user's information, unless doing so would endanger someone or is prohibited.
17.3 Transparency Report. We intend to publish a periodic transparency report stating the number of such requests received.
17.4 Relationship to CSAM Reporting. This Section is separate from, and does not affect, the mandatory reporting of child sexual abuse material to NCMEC described in Section 7.
18.1 We use reasonable technical and organizational measures designed to protect the information described in this Policy, including password hashing, encrypted session cookies, and the encryption and access controls described in Sections 3 through 5. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
18.2 If we become aware of a breach of security compromising your personal information in a manner that triggers a notification obligation under applicable law, we will notify affected users without unreasonable delay and in the manner required by that law, describing, to the extent known at the time, the nature of the breach, the categories of information involved, and the steps we are taking and recommend you take in response. Where required, we will also notify the regulators or authorities specified by applicable law.
19.1 We may update this Policy. Upon any update, we will revise the effective date above. For material changes, we will notify You in the application, by email if You provided an address, or both, before the changes take effect where practical. We will keep a dated version history of this Policy so that changes are visible rather than silent.
20.1 Questions, privacy requests, or concerns may be directed to eaveshq@gmail.com.
Reminder: this document is a DRAFT for review by a licensed attorney before publishing. It is not legal advice.
See also the Terms of Service.