01 What Information We Collect
A. For Anonymous Message Senders
- Zero Identification: We do NOT collect or store your real name, phone number, address, or social profile credentials.
- Message Content: The text you submit is stored securely in encrypted storage solely so the recipient can read it.
- Spam Defense (Cloudflare Turnstile): Non-invasive browser validation verifies human interaction without storing tracking cookies.
- Transient Edge Telemetry: Cloudflare edge nodes process request headers transiently for anti-DDoS rate-limiting; your IP is never saved with the message text.
B. For Registered Recipients (Account Holders)
- Email Address: Used solely to authenticate your login via passwordless One-Time Passcodes (OTP).
- Unique Username / Handle: The public slug used to generate your public TBH card link (e.g.,
secretmsg.net/janasco). - Inbox Contents: Received anonymous messages, archived notes, and responses.
02 What We Will NEVER Do
🚫 We never sell, rent, license, or trade your personal email address or message logs to third-party data brokers or marketing conglomerates.
🚫 We never disclose the sender's identity or IP address to the message recipient.
🚫 We never run retargeting pixels, advertising trackers, or invasive analytics scripts.
03 Third-Party Service Providers
SecretMsg relies only on minimal, enterprise-grade privacy infrastructure:
04 GDPR & CCPA Rights: Instant Complete Deletion
Under the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and our fundamental engineering principles, you retain the unmitigated right to erasure:
lock_reset Self-Service Account Wipeout
Open Settings → Delete Account at any time. When confirmed, a cascaded SQL transaction permanently purges your account row, email address, custom handle, and all inbox messages forever. This process is instant and cannot be undone.
05 Inquiries & Data Protection Contact
If you have questions regarding this Privacy Policy or wish to request data verification, contact the project maintainer: