The short version
SemaBuzz does not collect, store, or sell your personal data. We can't read your conversations. Sessions are ephemeral — when you leave, everything is gone. Your messages are encrypted on your device before they leave it; our relay server forwards ciphertext it cannot read.
What we collect
Nothing you type. Messages are encrypted on your device using ECDH P‑256 key exchange and AES‑256‑GCM before they leave your app. Encryption keys are generated locally and never transmitted to our servers. The relay server only ever sees ciphertext it cannot decrypt.
IP addresses. When you connect to a SemaBuzz session, your IP address is visible to our relay server infrastructure (hosted on Railway, behind Cloudflare). We do not log or store IP addresses persistently, but Cloudflare and Railway may record them as part of standard network operations — see their respective privacy policies below.
Connection metadata. Our relay holds session tokens and connection state only for the duration of an active session. Nothing is written to persistent storage. When both participants disconnect, all session data is discarded.
No accounts. SemaBuzz does not require registration, email, or any identifying information.
Cookies & tracking
SemaBuzz does not use cookies, analytics trackers, or any third-party tracking scripts.
Encryption
SemaBuzz uses ECDH P‑256 for key exchange and AES‑256‑GCM for message encryption, derived via HKDF‑SHA256. Keys are generated fresh for every session and exist only in memory on your device. Neither our relay server nor any third party receives your keys or can decrypt your messages.
Note: The key exchange is unauthenticated — SemaBuzz does not verify the identity of the person you're chatting with. Anyone who knows your session code can join. Share your invite link only with people you trust.
Third-party services
The SemaBuzz relay server is hosted on Railway. Railway handles the infrastructure and may process IP addresses and connection data per their privacy policy.
The promotional website is served via Cloudflare Pages. Cloudflare may collect standard web server logs (IP address, browser type, page requested) per their privacy policy.
The Windows app is distributed via Microsoft Store. Microsoft's own privacy policy governs that experience.
Data retention
We retain no user data. Session tokens are transient and expire when all participants disconnect.
Contact
Questions? Reach us at privacy@semabuzz.me.