Privacy Policy
Last updated: October 1, 2026
gobrooms is built to know as little about you as possible. There are no accounts, messages are end-to-end encrypted, and everything on our server is temporary. This policy explains exactly what that means, including what we can and can’t see.
End-to-end encryption
Messages, images, direct messages, reply previews, and pinned messages are end-to-end encrypted. They are encrypted in your browser before they are sent and can only be decrypted on the devices of the people in the conversation. Our server only relays and temporarily stores the encrypted data. We do not have the keys and cannot read your messages.
- Each browser creates its own encryption identity the first time you visit. Its private part never leaves your device.
- Each room has its own key, created on a member’s device. When you join, another member’s device sends it to you encrypted so that only your device can open it. The server passes it along but can’t read it.
- Direct messages use a separate key shared only by the two people talking, so other members of the room can’t read them.
- If a message can’t be encrypted, it isn’t sent. gobrooms never falls back to sending your messages unencrypted.
Player ids
Everyone online gets a short random id, shown as # and four characters in their profile, so you can tell apart people with similar names. It is assigned by our server, is not linked to your identity, and changes when you start a new session.
What our server can see
Encryption protects what you say, but some information has to be visible for the Service to work:
- The username and any nickname you choose, and the names of the rooms you join.
- Who is in a room, when people join and leave, and when messages are sent and roughly how large they are.
- Room settings, including room passwords, and commands that start with “!” (such as !nick or !pass), which are sent unencrypted so the server can run them.
- Game moves and game state (Wordle, Connect 4, and Wavelength).
- Your browser’s public encryption key, which is shared with other members so they can send you keys. It cannot be used to read your messages.
- Technical data needed to deliver the Service and prevent abuse, such as your IP address and browser type.
Retention
Everything on our server is held in memory only. We do not keep it in a database. Each room keeps a limited number of recent messages, and images expire after 30 minutes. When everyone leaves a room, or the server restarts, the room and all of its encrypted history are deleted. We do not sell your data, show ads, or use tracking or analytics tools.
Stored on your device
Some data is kept in your browser so the app works smoothly. It is never sent to us unless listed above:
- Your encryption identity and the keys for rooms you’ve joined, kept in your browser’s IndexedDB.
- A short-lived cache of images from your chats, deleted after 30 minutes.
- For the current tab only: a random session id, your username, your open rooms, room passwords you’ve entered, and muted rooms. These are cleared when the tab closes.
- Your desktop notification setting.
- One cookie, set only if you use an admin key.
You can remove all of this by clearing this site’s data in your browser. If you do, a new encryption identity is created and earlier encrypted messages can no longer be read on that device.
Third parties
- Link previews are fetched through our server, which sees the links that are previewed.
- GIF search is provided by Klipy through our server. Klipy receives your search terms but not who you are.
- The Service is hosted by a third-party infrastructure provider, which may keep standard connection logs.
- The public changelog is loaded from GitHub. No information about you is sent to GitHub.
Limits of protection
No system is perfect, and we want you to know the limits:
- gobrooms runs in your browser, so you rely on the app code our server delivers being genuine.
- Anyone in a room can read, copy, or screenshot what is posted there.
- Encryption can’t protect you if your device itself is compromised.
- Someone removed from a room may still be able to read messages until the room’s encryption key changes.
- If our server briefly can’t handle the key exchange, for example during an update, messages are still encrypted but with a key based on the room’s name. Our server could work out that key, so this fallback is weaker than full end-to-end encryption.
Children
The Service is not directed to children under 13, and we do not knowingly collect their personal information.
Your choices
You can leave a room or close the page at any time, and clear this site’s data to remove everything stored on your device. Because we hold no accounts and keep nothing permanently, there is usually nothing tied to you for us to delete. To ask about data associated with you, contact the operator of this site.
Changes
We may update this policy. When we do, we’ll change the date at the top of this page.