Privacy Model Overview
Buzzio is built with two honest product lanes:
- Privacy section (sealed conversations) — 1-to-1, E2E groups, Whisper private chat, and private calls: encrypted on your device, relayed briefly, then readable history stays on your phones.
- Feature mode (shared rooms and feeds) — open-history groups, Communities, and Broadcast: store more on purpose so history, roles, discovery, and moderation can work.
- Bots — third-party and official Forge chats are not end-to-end encrypted. Buzzio and the developer can read that text while Buzzio still has it (~7 days). Paid bot access is billed by the developer, not Buzzio.
Either way, Buzzio does not sell your messages, metadata, Buzzio IDs, community posts, Whisper content, backups, or wallet activity.
Get started
- Read the comparison table below once.
- Pick the feature that matches the job (private chat vs shared room vs public feed).
- Open that feature’s page in Help if you need step-by-step controls.
Quick comparison
| Feature | What it’s for | Can Buzzio read the content as part of the product? | History model (plain language) |
|---|---|---|---|
| 1-to-1 chat | Private two-person messaging | No | E2EE · zero durable chat metadata after delivery · history on your devices |
| Encrypted calls | Voice / video / screen share with a private chat partner | No call recordings | Encrypted setup · peer-to-peer media when possible · Cloudflare TURN only if a direct path is blocked (encrypted packets only) · local call list only |
| Whisper private chat | Time-limited QR anonymous chat | No | E2E session · zero durable chat metadata after expiry |
| E2E groups | Private group chat with sealed history | No readable transcript | End-to-end · short catch-up relay · new joiners do not get a full open archive |
| Open-history groups | Groups that need shared backscroll | Yes — plaintext | Durable history for members |
| Communities | Discord-style spaces with roles and channels | Yes — plaintext | History, roles, and moderation on Buzzio servers |
| Broadcast channels | One-to-many announcements | Yes — plaintext | Posts kept for the retention window (~30 days) |
| Stories | 24-hour status posts | Media is sealed for delivery; audience / views need product data | Expires about 24 hours · not a permanent private chat archive |
| Whisper Questions | Anonymous ask links | Yes — so you can read answers | Stored for the link owner · not the Whisper private-chat model |
| Bots (Forge + third-party) | Searchable bot 1:1; optional paid access billed by the developer | Yes — not E2E. The developer also receives your text. | About 7 days of text on Buzzio · media loads from the developer · not Buzzio app Premium |
| Contact sync | Optional saved-contact map | Contact IDs / nicknames map (not chat bodies) | Opt-in · off by default |
| Encrypted backup | Optional restore copy you control | Encrypted blobs only; unlock needs your recovery key | Off unless you enable it |
How to choose
Use the Privacy section — 1-to-1, Whisper private chat, E2E groups, and private calls — when you want a sealed conversation and minimal durable “who talked to whom” archive on sealed surfaces.
Use Feature mode — open-history groups, Communities, and Broadcast — when shared continuity, roles, discovery, or one-to-many publishing matter more than operator-blind history.
Use Stories for short social updates, and Whisper Questions when you want anonymous answers you can read later.
Use bots only if you accept that Buzzio and the bot’s developer can read that chat, and that Get Premium on a bot pays the developer — not Buzzio.
What “zero metadata” means here
1-to-1 chat and Whisper private chat are Buzzio’s zero-metadata conversation surfaces:
- 1-to-1: after messages are delivered (nothing left undelivered on our relay), we do not keep a lasting server record of who talked to whom for that chat, and never keep a searchable archive of what was said.
- Whisper private chat: after the session expires and cleanup runs, we do not keep a durable server archive of that conversation’s content or who privately talked to whom.
Readable history for those chats stays on your phones.
That does not mean Buzzio stores nothing at all. Account records, safety tools (blocks and reports), push delivery, short-lived undelivered queues, and Feature mode (shared rooms) still need operational data.
What never changes
- We do not sell your data.
- Features that need more storage say so honestly in this overview.
- Maximum secrecy where the product is a sealed conversation; transparent extra storage where the product is a shared room or public feed.
Tips and limits
- “Encrypted” does not always mean “Buzzio cannot operate the feature.” Shared rooms need server-managed keys on purpose.
- Whisper Questions is intentionally readable by the link owner — do not confuse it with Whisper private chat.
- Optional contact sync and optional backup are opt-in — leave them off if you do not need them.
- Retention windows differ by feature (for example Stories ~24 hours, broadcast posts ~30 days, community history on a longer schedule).
Related features
- Security overview — keys, local encrypted database, delete-on-delivery.
- Account and Buzzio ID — identity without a phone number.
- Backup and recovery — optional encrypted restore path.