Privacy Policy
A plain-language notice describing what VeilPair processes, why it is processed, how long current records remain, and the limits of deletion and confidentiality.
Operator, Scope & Contact
This notice covers the VeilPair service at veilpair.com. The service is operated by the VeilPair service team on Hostinger infrastructure. A separate legal-entity name and postal address are not published in this MVP.
Privacy questions, access/deletion requests, security disclosures, and complaints can be submitted through the feedback and safety form. Do not include passwords, bearer tokens, private-room URLs, or unnecessary message content.
Data Processed to Provide the Service
- Guest use: a random guest identifier and account-creation timestamp.
- Optional pseudonymous account: username, bcrypt password hash, account identifier, and timestamp. Real name, email, and phone number are not required for account creation.
- Handoff records: endpoint slug, title, optional source context, owner identifier, expiry, request limits, and status.
- Pairing requests: requester/owner identifiers, human-readable code, timestamps, status, and resulting conversation identifier when accepted.
- Conversations: participant identifiers, messages, contact cards voluntarily shared by participants, labels, timestamps, save state, close state, and expiration.
Feedback, Analytics, IP & Request Metadata
- Feedback and safety reports: category, message, optional reply email, optional public session reference, timestamp, status, and a truncated salted IP-derived hash are persisted.
- First-party analytics: daily aggregate page views, unique-visitor counts, paths, languages, referrer hostnames, endpoint/pairing/message/contact counts, and contact types are persisted. A truncated daily IP-derived value is held in memory to count unique visitors but is not written to the application datastore.
- Rate limiting: IP-based keys are processed in memory to control abuse and expire with their rate-limit windows.
- Infrastructure: Hostinger, reverse proxies, TLS termination, operating-system services, and security systems may process IP addresses, timestamps, user agents, and request metadata. Their exact log retention has not been independently verified by this notice.
Purposes and Processing Basis
Data is processed to create guest or optional pseudonymous accounts, operate handoff links and pairing requests, relay and store conversations, share participant-selected contact cards, prevent abuse, maintain security, provide support, measure aggregate service usage, and comply with applicable legal obligations.
Depending on applicable law and the specific activity, processing may be necessary to provide the service requested by the user, protect the service and its users, respond to consent-based optional submissions, or meet legal obligations. VeilPair does not claim a jurisdiction-specific legal basis beyond what can be supported for the relevant user and operator.
Current Retention and Expiration
| Record | Current application behavior |
|---|---|
| Temporary endpoint | Configured lifetime, normally 24 hours; expiry marks it inactive |
| Pending pairing request/code | 15-minute pending window; expired/resolved records are removed by cleanup or related destruction |
| Unsaved conversation/messages/contact cards | 24-hour sliding expiration after the latest message |
| Saved conversation | No automatic general retention limit currently enforced |
| Guest/pseudonymous account | No automatic account-deletion schedule currently enforced |
| Feedback, safety reports, and persisted IP-derived feedback hash | No automatic retention limit currently enforced |
| Aggregate analytics | No automatic retention limit currently enforced |
Close, Destroy, Deletion & Backups
- Close: stops further conversation activity but is not an immediate deletion promise.
- Destroy Room: removes the active conversation and associated pairing records from the application datastore for both participants.
- Automatic expiration: removes unsaved conversations after the sliding 24-hour window.
- Backups: deleted records may remain in restricted infrastructure or project backups until those backups rotate or are securely removed. Backup copies are not part of ordinary application access.
Because saved conversations, accounts, feedback, and analytics do not yet have general automatic retention enforcement, users may submit a deletion request through the feedback form. Verification may be required before acting on a request.
Cookies, Local Storage & Authentication
The product stores its bearer authentication token and guest/user state in browser storage so sessions can resume. Product bearer tokens currently expire after 7 days for guests and 30 days for registered accounts. They are not HttpOnly cookies and do not have per-session server-side revocation.
The separate Admin application uses a Secure, HttpOnly, SameSite cookie. Admin traffic is excluded from product analytics.
Advertising and Tracking
VeilPair does not currently embed Meta Pixel, Google Analytics, third-party advertising pixels, or cross-site advertising fingerprinting in private rooms. It does operate the first-party aggregate analytics described above. Private conversation content is not used for targeted advertising.
Security and Confidentiality Limits
Production transport uses HTTPS/WSS and the application applies origin controls, security headers, validation, authorization, and rate limits. VeilPair is not end-to-end encrypted: the server processes and can access messages and contact cards. No service can guarantee anonymity, absolute security, participant trustworthiness, or protection from a compromised device, compromised server, screenshots, or voluntary copying.
Privacy Requests, Jurisdictional Rights & Minimum Age
Depending on applicable law, users may have rights to request access, correction, deletion, restriction, portability, objection, or review of certain processing. Submit a request through the feedback form and include only the minimum information needed to identify the relevant record. VeilPair may need to verify control of an account or record before responding.
VeilPair's Terms set a minimum age of 18. The service is not intentionally directed to children.
Changes to This Notice
Material changes should be reflected by updating this page's date and, where appropriate, by a notice in the service. This notice describes the implementation as reviewed on 27 August 2026 and should be revised whenever storage, analytics, authentication, providers, or retention behavior changes.