Last Updated: September 12, 2026
Product surface: Linked web companion at https://web.buzzio.dev
Privacy contact: founder@buzzio.dev (subject: Privacy Request)
Not legal advice. This notice describes how Buzzio handles data on the linked web companion. Have a qualified lawyer review it for your markets before relying on it as compliance.
At a glance
web.buzzio.dev is a phone-approved, time-boxed browser companion for shared Buzzio rooms only — open-history groups, Communities, Broadcast, and service bot DMs. It is not a sealed chat client. Private 1:1, E2E groups, Whisper private chat, encrypted calls, and your recovery phrase stay on your phone. Shared room content uses TLS in transit and is stored so the product can work (Buzzio can read it). We do not sell your data. Revoke the web session anytime from your phone.
0. Who controls your data
| Item | Detail |
|---|---|
| Controller / operator | The Buzzio Team — currently an unincorporated operator of Buzzio and related services. We may assign operations to a future registered legal entity; this notice will be updated with that entity’s legal name and address when that happens. |
| Privacy contact | founder@buzzio.dev — subject Privacy Request |
| Main website | https://buzzio.dev |
| This web companion | https://web.buzzio.dev |
| DPO | Not appointed at this time. If law later requires a DPO or EU/UK representative, we will publish those details here. |
1. What this policy covers
This Web Privacy Policy covers the linked web companion at web.buzzio.dev only: linking a browser session from your phone, using that session, and data needed to run shared rooms and service bot DMs in the browser.
It does not replace the full product Privacy Policy for the Buzzio mobile app and other Buzzio services.
Full app Privacy Policy: https://buzzio.dev/privacy
Plain-language overview: see the “At a glance” section above and doc.buzzio.dev
Where this notice is silent, the main Privacy Policy applies.
2. What web.buzzio.dev is — and is not
| Is | A phone-approved linked companion for shared surfaces: permanent open-history groups (OHG), Communities, Broadcast channels, and service bot DMs. |
| Is not | A second sealed client. It does not provide end-to-end private 1:1 chat, E2E groups, Whisper private chat, encrypted calls, Private Vault, recovery phrase entry, or messaging keys in the browser. |
Buzzio will not ship sealed private chat in a normal browser under our current threat model. Background: Why E2E chat is not on the web.
3. How linking works
- The browser starts a short-lived link challenge and shows a QR code.
- You scan with the Buzzio phone app, choose a duration, and approve.
- A second confirm QR binds the same browser.
- The browser receives an opaque session token (shown once). The server stores only a hash of that token.
- You can revoke the session anytime from the phone. Linking a new browser replaces any previous active web session (one active web session per account).
Durations (product): freemium typically 1h · 6h · 12h · 1d · 3d · 7d; Premium may unlock 14d. Exact options shown in the phone approval sheet control.
A linked web session is not exclusive device login and does not replace or bump your phone’s exclusive session controls.
4. Data we process for the web companion
Depending on how you use the site, we may process:
| Category | Examples | Why |
|---|---|---|
| Session | Opaque session token (browser); token hash, session id, status, expiry, chosen duration on our servers | Authenticate the linked browser |
| Browser binding | Random browser fingerprint / id; coarse label (e.g. “Chrome · Windows”) | Bind QR confirm to the same browser; show you which device is linked |
| Scopes | ohg, community, broadcast, bot | Limit what the web session can access |
| Account pointers | Your Buzzio ID (internal account id) linked to the session | Serve your shared rooms and profile display fields needed for the companion |
| Shared room content | Messages, media, membership, roles, and other content in OHG / Communities / Broadcast you access on web | Run shared rooms (history, moderation, multi-device shared history) |
| Service bot DMs | Bot chat content you open under the bot scope | Same shared/cloud bot model as on phone — not E2E |
| Security / abuse | Challenge status, short-lived QR secrets, rate limits; infrastructure may see IP / request logs and similar technical signals as described in the main Privacy Policy | Prevent abuse and keep the service reliable |
| App Check (when enabled) | Integrity / bot-protection tokens for web API calls | Reduce automated abuse |
We do not use advertising cookies or sell web companion data.
5. What we do not process on web
On web.buzzio.dev we do not ask for, store, or process:
- Your 12-word recovery phrase
- Messaging private keys or Private Vault keys
- Decrypted sealed 1:1 / Whisper / E2E group ciphertext as a web feature
- Encrypted call media as a web feature
If someone asks you to enter a recovery phrase on a web page claiming to be Buzzio, treat it as suspicious and stop.
6. Shared-room honesty (important)
Open-history groups, Communities, and Broadcast are not end-to-end encrypted.
- Traffic uses TLS in transit.
- Content is stored so those products can work (including plaintext at rest on Buzzio systems).
- Buzzio can read that content for product function, safety, and moderation where applicable.
Service bot DMs on web use the same non-E2E bot model as the phone. Ordinary bot message text retention and bot media rules are described in the main Privacy Policy and Bot Privacy. Bot developers who receive webhook or API copies are independent controllers of their copies.
We still do not sell that data.
7. Cookies & browser storage
web.buzzio.dev is designed around essential technical storage so linking and your session work. Today the companion uses:
| Storage | What | Purpose |
|---|---|---|
| sessionStorage | Linked session token and session metadata | Keep you signed into the companion until expiry, logout, or revoke |
| localStorage | Random browser fingerprint id | Bind the link challenge / confirm to this browser |
| Cookies | No first-party advertising cookies. We do not rely on marketing cookies for this companion. | — |
Third-party infrastructure (for example Firebase / Google Cloud) may set strictly necessary technical cookies or similar technologies when the page calls our backends. We do not use them for ads.
How to control: clear site data in your browser, or revoke the session on your phone. Blocking essential storage may break linking.
8. Retention
| Data | Retention |
|---|---|
| Active linked web session | Until the chosen wall-clock expiry, phone revoke, or replacement by a new link |
| Challenge / QR secrets | Short-lived (minutes-scale) then expired / unused |
| Token hash & session records | While useful for security/audit after revoke or expiry, then removed under our normal cleanup (see main Privacy Policy for operational logs) |
| Shared room / bot content | Same retention as the main Buzzio product for those features — not a separate “web-only” archive |
9. Your controls
- Revoke the linked web session from the Buzzio phone app anytime.
- End the browser session (sign out / clear site data).
- Delete account or make access / export / California rights requests via the app or email founder@buzzio.dev with subject Privacy Request (or Privacy Request — Delete Account).
- Deny camera (for QR) or other browser permissions in your browser settings.
10. Children’s privacy
You must be at least 13 to use Buzzio, including the web companion. We do not knowingly collect personal information from children under 13. If we learn a user is under 13, we will terminate the account / session as described in the main policies.
11. We do not sell your data
We do not sell your data. We never have. We never will.
Under California law (CCPA/CPRA), we also do not “sell” or “share” personal information for cross-context behavioral advertising, consistent with the main Privacy Policy.
12. International users & contact
Buzzio may be used from many countries. Processing locations and subprocessors are described in the main Privacy Policy / transparency materials on buzzio.dev.
For privacy requests: founder@buzzio.dev — subject Privacy Request.
Support: https://support.buzzio.dev
13. Changes to this policy
We may update this Web Privacy Policy. The Last Updated date will change. For material changes, we will provide notice when appropriate (for example on the web companion or via the app). Continued use after the effective date means you acknowledge the updated notice, except where mandatory law requires a different method.
14. Full app Privacy Policy
For sealed chat, calls, Stories, Premium, wallet, bots detail, analytics, and everything beyond this companion, read:
Related: Web Terms · Main Terms · Why no E2E on web