VeilPair

Operator, Scope & Contact

This notice covers the VeilPair service at veilpair.com. The service is operated by the VeilPair service team on Hostinger infrastructure. A separate legal-entity name and postal address are not published in this MVP.

Privacy questions, access/deletion requests, security disclosures, and complaints can be submitted through the feedback and safety form. Do not include passwords, bearer tokens, private-room URLs, or unnecessary message content.

Data Processed to Provide the Service

  • Guest use: a random guest identifier and account-creation timestamp.
  • Optional pseudonymous account: username, bcrypt password hash, account identifier, and timestamp. Real name, email, and phone number are not required for account creation.
  • Handoff records: endpoint slug, title, optional source context, owner identifier, expiry, request limits, and status.
  • Pairing requests: requester/owner identifiers, human-readable code, timestamps, status, and resulting conversation identifier when accepted.
  • Conversations: participant identifiers, messages, contact cards voluntarily shared by participants, labels, timestamps, save state, close state, and expiration.

Feedback, Analytics, IP & Request Metadata

  • Feedback and safety reports: category, message, optional reply email, optional public session reference, timestamp, status, and a truncated salted IP-derived hash are persisted.
  • First-party analytics: daily aggregate page views, unique-visitor counts, paths, languages, referrer hostnames, endpoint/pairing/message/contact counts, and contact types are persisted. A truncated daily IP-derived value is held in memory to count unique visitors but is not written to the application datastore.
  • Rate limiting: IP-based keys are processed in memory to control abuse and expire with their rate-limit windows.
  • Infrastructure: Hostinger, reverse proxies, TLS termination, operating-system services, and security systems may process IP addresses, timestamps, user agents, and request metadata. Their exact log retention has not been independently verified by this notice.

Purposes and Processing Basis

Data is processed to create guest or optional pseudonymous accounts, operate handoff links and pairing requests, relay and store conversations, share participant-selected contact cards, prevent abuse, maintain security, provide support, measure aggregate service usage, and comply with applicable legal obligations.

Depending on applicable law and the specific activity, processing may be necessary to provide the service requested by the user, protect the service and its users, respond to consent-based optional submissions, or meet legal obligations. VeilPair does not claim a jurisdiction-specific legal basis beyond what can be supported for the relevant user and operator.

Current Retention and Expiration

RecordCurrent application behavior
Temporary endpointConfigured lifetime, normally 24 hours; expiry marks it inactive
Pending pairing request/code15-minute pending window; expired/resolved records are removed by cleanup or related destruction
Unsaved conversation/messages/contact cards24-hour sliding expiration after the latest message
Saved conversationNo automatic general retention limit currently enforced
Guest/pseudonymous accountNo automatic account-deletion schedule currently enforced
Feedback, safety reports, and persisted IP-derived feedback hashNo automatic retention limit currently enforced
Aggregate analyticsNo automatic retention limit currently enforced

Close, Destroy, Deletion & Backups

  • Close: stops further conversation activity but is not an immediate deletion promise.
  • Destroy Room: removes the active conversation and associated pairing records from the application datastore for both participants.
  • Automatic expiration: removes unsaved conversations after the sliding 24-hour window.
  • Backups: deleted records may remain in restricted infrastructure or project backups until those backups rotate or are securely removed. Backup copies are not part of ordinary application access.

Because saved conversations, accounts, feedback, and analytics do not yet have general automatic retention enforcement, users may submit a deletion request through the feedback form. Verification may be required before acting on a request.

Cookies, Local Storage & Authentication

The product stores its bearer authentication token and guest/user state in browser storage so sessions can resume. Product bearer tokens currently expire after 7 days for guests and 30 days for registered accounts. They are not HttpOnly cookies and do not have per-session server-side revocation.

The separate Admin application uses a Secure, HttpOnly, SameSite cookie. Admin traffic is excluded from product analytics.

Service Providers, Sharing & International Processing

Hostinger supplies the VPS, network, backup, and related infrastructure used to operate VeilPair. Data may therefore be processed in infrastructure locations outside a user's country. VeilPair does not sell or rent private conversation content or contact cards.

Data may be disclosed when required by applicable law, to protect users or the service, to investigate abuse, or to infrastructure providers acting as necessary service processors. Contact details voluntarily shared with another participant leave VeilPair's control once that participant copies, exports, or screenshots them.

Advertising and Tracking

VeilPair does not currently embed Meta Pixel, Google Analytics, third-party advertising pixels, or cross-site advertising fingerprinting in private rooms. It does operate the first-party aggregate analytics described above. Private conversation content is not used for targeted advertising.

Security and Confidentiality Limits

Production transport uses HTTPS/WSS and the application applies origin controls, security headers, validation, authorization, and rate limits. VeilPair is not end-to-end encrypted: the server processes and can access messages and contact cards. No service can guarantee anonymity, absolute security, participant trustworthiness, or protection from a compromised device, compromised server, screenshots, or voluntary copying.

Privacy Requests, Jurisdictional Rights & Minimum Age

Depending on applicable law, users may have rights to request access, correction, deletion, restriction, portability, objection, or review of certain processing. Submit a request through the feedback form and include only the minimum information needed to identify the relevant record. VeilPair may need to verify control of an account or record before responding.

VeilPair's Terms set a minimum age of 18. The service is not intentionally directed to children.

Changes to This Notice

Material changes should be reflected by updating this page's date and, where appropriate, by a notice in the service. This notice describes the implementation as reviewed on 27 August 2026 and should be revised whenever storage, analytics, authentication, providers, or retention behavior changes.

Need to move an anonymous conversation to private?

Create a temporary handoff link as a guest, or sign in to manage saved conversations.

Launch VeilPair →