← Back

Faceless Talk

Privacy Policy

Effective date: July 23, 2026

Operator: Hidden Orbit LLC, Florida, United States

Faceless Talk is a privacy-focused, temporary, room-based communication service. This Privacy Policy explains what information we process, why we process it, how long it may remain, when it may be shared, and the rights and choices available to users.

1. Privacy-focused architecture

Faceless Talk is designed to operate without public profiles, phone-number registration, or traditional social-account linking. It is not completely anonymous or confidential. Limited technical, session, room, and security information must be processed to operate, protect, moderate, and enforce the service.

2. Information we process

  • Room and identifier data, including room phrases, PIN hashes, ephemeral room IDs, room type, creation time, participation records, and expiration metadata.
  • Encrypted user-generated content, including message ciphertext, encrypted cards and images, plus readable copies that a participant intentionally submits through the reporting process.
  • Technical and session identifiers, such as temporary session tokens, client identifiers, room-scoped sender keys, and device or browser storage used to maintain room continuity, enforce limits, and prevent abuse.
  • Limited non-content safety signals, such as message frequency, room-creation frequency, failed access attempts when available, upload volume, independent blocks, report counts, and room status. These signals do not reveal the text or image content of an unreported encrypted message.
  • Diagnostic and infrastructure information, such as IP addresses, browser and device type, user-agent strings, request timestamps, error logs, and security or rate-limit events.
  • Communications you send to us, including support, privacy, legal, copyright, or abuse reports.

3. Browser storage and cookies

We use essential localStorage, sessionStorage, and functional cookies or similar technologies to maintain room access, preserve user preferences, enforce limits, and support security. Clearing browser or app storage may end room access or reset preferences. The “Hide room shortcuts” option only hides the shortcut list and retains the saved room records on that device; turning it off shows them again. The separate “Forget saved rooms” action deletes the saved shortcuts and local room-access records from that device.

We do not currently use third-party advertising cookies or sell personal information for targeted advertising. If this changes, this Policy and any required consent controls will be updated before such use begins.

4. How we use information

  • • We may use information to operate temporary rooms, route messages, display cards and images, process links, and maintain room access;
  • • We may use information to enforce room, upload, message, link, and creation limits;
  • • We may use information to detect, investigate, prevent, and respond to spam, harassment, threats, scams, doxxing, exploitation, malware, unlawful content, coordinated misuse, and automated abuse using reports, client-side checks, rate limits, and limited non-content safety signals;
  • • We may use information to review reports, hide or remove content, block access, preserve evidence, and protect users, the service, and Hidden Orbit LLC;
  • • We may use information to debug errors, improve reliability, maintain security, comply with law, respond to valid legal process, and defend legal claims.

5. Content encryption, reports, and moderation

Normal room messages, replies, card text, captions, and uploaded pictures are encrypted on the participant’s device before being transmitted for temporary storage and delivery. The room phrase and participant-selected 4-to-6-digit PIN are used on the device to derive the room content key. Under normal operation, room content keys are not transmitted to or stored by Hidden Orbit LLC, and ordinary unreported room content is stored as ciphertext that Hidden Orbit LLC cannot routinely read.

A longer, less predictable PIN and a generated room phrase generally provide stronger resistance to guessing than a short PIN or familiar phrase. Encryption does not prevent a participant from sharing access credentials, taking screenshots, copying, recording, or otherwise disclosing content. Anyone with the correct phrase and PIN may be able to enter and decrypt the room.

Faceless Talk does not routinely monitor or review ordinary encrypted conversations. As a result, we may not know that prohibited or unlawful activity is occurring unless a participant reports it, a client-side safety check blocks it before encryption, or limited non-content abuse signals indicate possible misuse. Consent among participants does not make prohibited or unlawful conduct permissible.

When a participant intentionally reports a message, the app asks for confirmation and sends a readable copy of only that selected message, its category, timestamp, and limited room or session context to Faceless Talk for moderation. The reporting participant supplies that readable copy; it is not represented as a cryptographically verified transcript. Other room content remains encrypted unless separately reported. Blocking alone does not disclose message content.

We may use limited non-content safety signals—such as rate limits, unusual posting or upload volume, repeated failed access attempts when available, multiple independent blocks, report counts, and room status—to restrict activity or flag a room or participant for review without decrypting unreported content. For example, multiple independent participants blocking the same room-scoped sender may automatically suspend that sender from that room. These signals do not reveal the text or image content of ordinary encrypted messages.

Client-side safety checks may run before content is encrypted, but technically sophisticated users may attempt to bypass client software. We therefore do not guarantee that every harmful, illegal, false, or unwanted communication will be detected, prevented, or removed.

6. Retention and deletion

Rooms are designed to expire approximately five days after creation. After expiration, room content is scheduled for automated deletion from active systems. Because cleanup runs on a schedule, deletion may not be instantaneous.

Dismissed readable reports are ordinarily scheduled for deletion after about 30 days, and actioned or resolved reports after about 90 days. Moderation-event logs may be retained for up to about 180 days. Security logs, rate-limit records, backups, and technical records may remain longer when reasonably necessary for abuse prevention, troubleshooting, legal compliance, dispute resolution, or platform protection. Content subject to a valid preservation request, court order, serious safety investigation, or legal hold may be retained until the matter is resolved. Backup copies may remain until overwritten under normal backup cycles.

7. Information sharing

We do not sell or rent user communications or room content to advertisers or data brokers. We may disclose limited information to:

  • Service providers that supply hosting, database, storage, content delivery, security, logging, email, or other technical services. They may process information only as needed to provide those services.
  • Law enforcement, courts, regulators, emergency responders, or other parties when required by valid legal process or when we reasonably believe disclosure is necessary to prevent imminent harm, investigate serious abuse, or protect legal rights.
  • Professional advisors such as attorneys, accountants, insurers, auditors, or compliance consultants acting under confidentiality obligations.
  • A buyer, successor, or transferee in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of the business or assets.

8. State privacy rights

Depending on your state and whether an applicable privacy law covers our activities, you may have rights to request access to, correction of, or deletion of certain personal information; obtain information about categories of data processed or disclosed; appeal a denied request; and opt out of sale, targeted advertising, or certain profiling.

We do not currently sell personal information, share it for cross-context behavioral advertising, or perform profiling that produces legal or similarly significant effects. To make a privacy request, email privacy@facelesstalk.com. Because we do not maintain conventional user accounts, you may need to provide a room identifier, session token, approximate timestamp, or other verifiable technical information. We may be unable to locate or verify information without it, and legal exceptions may apply.

9. Global Privacy Control and Do Not Track

Because we do not currently sell personal information or use it for cross-context behavioral advertising, Global Privacy Control and Do Not Track signals do not change how the service operates. If our practices change, we will update this Policy and honor legally required browser-based opt-out signals.

10. International users

Faceless Talk is operated from the United States, and information may be processed or stored in the United States and other countries where our service providers operate. Those countries may have different data-protection laws from your country.

Where the GDPR, UK GDPR, or similar law applies, processing may be based on contractual necessity to provide requested room functionality, legitimate interests in security and abuse prevention, legal obligations, and consent where required. Eligible users may request access, correction, deletion, restriction, objection, or portability and may complain to their local data-protection authority. International transfers will be handled using legally recognized safeguards where required.

11. Children

Faceless Talk is intended only for users who are at least 18 years old. It is not directed to children, and children under 13 may not use it under any circumstances. If we learn that we processed personal information from a child in violation of this rule, we may delete the information and restrict access.

12. Security

We use reasonable administrative, technical, and organizational safeguards, including encrypted transport, restricted credentials, access controls, automated expiration, rate limits, and security monitoring. No online service can be guaranteed fully secure, private, uninterrupted, or error-free.

13. Your choices

You can avoid sharing personal information, leave a room, clear browser or app storage, report or block content, and stop using the service. Do not post addresses, phone numbers, financial information, health information, identification documents, passwords, private records, confidential information, or anything you do not want other participants to see or save.

14. Changes to this Policy

We may update this Privacy Policy as the service, law, or our practices change. The effective date at the top identifies the current version. Continued use after an update means the revised Policy applies to your continued use.

15. Contact

Privacy and data-rights questions may be sent to: privacy@facelesstalk.com