Privacy Policy
Effective Date: October 4, 2026 • Version 1.0 • Syphr Protocol
1. Information We Do Not Collect
Because of our strict peer-to-peer (P2P) architecture, Syphr is engineered deliberately to minimize any point of centralized data ingestion. We explicitly do not collect, retain, sell, or monitor:
- Chat Messages & Transcripts: Text messages are transmitted directly between browsers via WebRTC DataChannels. They are never written to any database.
- Transferred Media & Files: Images, documents, and code snippets transmitted between participants are sent as binary chunks directly over P2P channels and never uploaded to cloud buckets.
- Voice Notes: Microphone audio recorded via the in-app tool is captured directly into local browser memory, packaged for transmission, and discarded immediately after playback or session close.
- Personal Identifiers: We do not require accounts, passwords, telephone numbers, emails, or personal identification to initiate or join chat rooms.
2. How Peer-to-Peer Transmission Operates
Syphr establishes direct communication between clients using the WebRTC (Web Real-Time Communication) standard:
- Signaling & Handshake: To establish a direct P2P link, prospective peers exchange cryptographic session descriptions (SDP offers and answers). This handshake is completed via client-generated invite URLs, QR codes, or transient signaling relays.
- DTLS Encryption: Data channels between peers are protected using Datagram Transport Layer Security (DTLS), ensuring that intermediate networks or eavesdroppers cannot inspect transmitted message packets.
- IP Address Exchange: WebRTC requires peers to exchange network route candidates (ICE candidates) so your browser can discover the direct IP path to your peer. As with all P2P protocols (such as BitTorrent or direct VoIP), your public IP address becomes visible to the peer you connect with. If this is a concern, we recommend using a Virtual Private Network (VPN) or Tor proxy.
3. Local Device Storage & Preferences
Syphr explicitly separates ephemeral conversation data from user interface preferences:
- No Chat Logging in Storage: Chat transcripts, photos, and voice notes are never stored in your browser's persistent storage (
localStorage,IndexedDB, or cookies). - Client-Side UI Preferences: The application may save benign client-side display preferences in your local browser storage, such as your chosen theme preset (e.g., Dark, Light, Neon Pulse), audio haptic mute preference, or chosen display nickname. This data never leaves your device and can be cleared at any time through your browser settings.
4. Device Permissions
Syphr requests only the minimal browser permissions necessary to provide optional features:
- Microphone Access (getUserMedia): If you choose to record an audio note, your browser will prompt you for microphone permission. Audio input is captured strictly while the recording is active. As soon as the recording stops, audio capture hardware is released and all tracks are immediately closed. Audio is never stored on servers or transcribed by third-party speech engines.
- Camera Access (Optional QR Scanning): If you use an in-app QR scanner to join a peer room, video stream access is used solely on-device to decode the room connection token and is never recorded or broadcast.
5. Instant Data Vaporization (The NUKE Protocol)
Syphr includes an emergency session incineration protocol (the "NUKE" button). When triggered, or when you close the browser tab:
- All active WebRTC peer connections and data channels are forcefully severed.
- In-memory message lists, audio blob buffers, and image object URLs are nullified and released to the browser's garbage collection cycle.
- DOM elements containing chat history are wiped clean.
- Because no backup or server copy exists, wiped data is permanently unrecoverable.
6. Third-Party Dependencies
The Syphr web client loads required open-source user interface assets from established, reputable Content Delivery Networks (CDNs) including Google Fonts, Lucide Icons, and unpkg. These CDNs receive standard HTTP request headers (such as IP address and User-Agent) solely for the technical delivery of static scripts and fonts in accordance with their respective privacy policies.
7. Contact & Questions
If you have any questions regarding this Privacy Policy or the cryptographic design of the Syphr protocol, you can review the open-source code repository or contact the project maintainers through our official project documentation.