Privacy & your data
Last updated: 22 September 2026. UrduPal uses Cloudflare Workers and Durable Objects to deliver rooms and store limited recent conversation history.
What is stored
An essential HttpOnly cookie holds a random browser identity for 30 days. Your nickname is saved in this browser. Room history holds up to 80 messages and a direct conversation up to 120 messages from the previous 24 hours. Expired messages stop appearing after 24 hours; scheduled cleanup removes expired stored history within approximately 48 hours.
Reports preserve the selected message, your report reason and pseudonymous participant identifiers for up to seven days, plus up to one day for scheduled cleanup. Room blocks and direct-message preferences expire after 30 days. Temporary abuse restrictions last 24 hours. While you are connected, the owner can view your IP address and approximate city/region/country for moderation. Location may reflect a VPN or carrier rather than your physical location. These connection details are not included in public user lists or chat history and are discarded when the connection ends. Hashed network addresses support connection and abuse limits; Cloudflare also processes request information to operate its service.
Voice and camera privacy
Turn camera on requests camera permission and shares video with connected voice participants. Turn camera off stops video capture. Leave voice stops both camera and microphone capture. We do not record or store video. Other participants may record their screens.
Room staff
The owner can assign a room admin or moderator role to a browser identity or verified account for 30 days. Roles are limited to the assigned room and can be revoked. Up to 100 recent staff actions are retained for up to 30 days, plus scheduled cleanup time, with a pseudonymous actor identifier and action type. Staff controls do not expose participant IP addresses or location.
Email accounts
Guest access does not require email. When email sign-in is enabled, the delivery provider processes your email to send a one-time code. We store a hash of the normalized email, a nickname and a random account identifier. Codes expire in 10 minutes after at most five attempts; session cookies expire in 30 days. Expired authentication records are cleaned up hourly. Account records persist until deleted by the operator. Email verification confirms email access, not a person’s real identity. Email sign-in is not currently available. Guest access remains open.
Voice privacy
Voice starts only when you choose Join voice; this joins as a listener without microphone capture. Raise your hand to enter the mic queue. Only the current speaker can choose Unmute mic, which requests permission to capture audio. Turns are timed; passing or expiry disables outgoing microphone audio. Voice is sent using WebRTC to connected voice participants. Direct connections may expose network addresses to peers. If a relay is configured, Cloudflare processes relayed media traffic. We do not record or store voice audio. Other participants can still record it using their own devices. Mute pauses outgoing audio; Leave voice stops capture and disconnects voice. Blocking a participant closes their voice connection. Voice reports contain a participant identifier, reason and timestamp, not an audio recording; reports are allegations for operator review.
Who can read messages
Room messages are public to people in that room. Direct messages are delivered only to the participating browser identities, but are not end-to-end encrypted. The service operator controls storage and can read submitted report evidence. Do not send sensitive information. Clearing cookies loses your access to direct history; nicknames do not restore it.
Your controls
Direct messages are off until you opt in for that room. Block and report controls are available in the room. “Erase my room data” removes your sent messages, direct conversations involving your identity, and your room preferences. Reports and temporary abuse restrictions are retained for their stated period. Repeat in any other room you used. Clearing browser data separately removes your local nickname and identity cookie.
No advertising trackers
This version has no advertising, analytics cookies or file uploads. Microphone access is requested only when you choose Unmute mic. Essential storage is required for chat to work. No claim of complete anonymity is made.
Questions
Use the report form in the room with the reason “Privacy or other concern” to send a concern attached to a relevant message. Review is asynchronous. If you no longer have the browser identity, automated deletion cannot verify which guest history belongs to you.