Privacy notice
What Anymus processes
Anymus has no accounts, advertising, analytics, fingerprinting, or cross-site tracking. Some limited metadata is still necessary to connect users, secure the service, and answer requests.
Controller and contact
BLEKEN DESIGN is the controller. Contact privacy@anymus.net about personal data. Full business particulars are on the legal page.
Data, purposes, and legal bases
| Data | Why | Legal basis |
|---|---|---|
| IP address, request details, user agent, request/session/room identifiers, connection and security events | Deliver, troubleshoot, protect, and operate the service | Legitimate interests in a reliable and secure requested service |
| Transient signaling and TURN transport metadata; encrypted relay traffic when direct P2P fails | Connect room participants and relay their WebRTC traffic when necessary | Legitimate interests in providing the requested connection |
| Optional error report text, diagnostics, and screenshot | Investigate a problem you choose to report | Legitimate interests in requested support and service reliability/security |
| Email address, message, and related correspondence | Answer support, privacy, abuse, or lawful authority requests | Legitimate interests and, where applicable, legal obligations |
Do not include sensitive information in an error report or email unless it is necessary for your request.
P2P content and local data
Text, attachments, and voice travel over encrypted WebRTC connections. They normally travel directly between peers. If TURN is needed, the relay handles encrypted traffic transiently but the operator still cannot read the P2P plaintext. Anymus does not store that content on its application servers.
Voice uses your browser's microphone permission, requested only when you start or join a call — audio only, never camera. The audio stream goes directly to other participants and is never recorded or sent to Anymus's servers; you can revoke the permission in your browser at any time. Because messages, attachments, and voice come directly from other participants rather than the operator, Anymus's server cannot scan or filter that content.
Your browser stores room records, settings, messages, and attachments at your request. Public room-message history is normally limited to 30 days and 5,000 messages per room. Private messages, room data, and attachments remain until you delete the room or clear the site's data. Exported backups remain wherever you save or share them. Other participants control their own copies.
Retention
- Origin request, application, security, and TURN logs: 7 days.
- bunny.net CDN request logs: up to 3 days, with one-digit IP anonymization enabled.
- Optional error reports: 90 days.
- Signaling messages: normally delivered or expired within seconds, with a 90-second maximum queue lifetime.
- TURN credentials: 10 minutes; relay allocations exist only as needed for a connection and are capped at one hour.
- Correspondence: until the request is resolved and no longer reasonably needed, unless law requires longer retention.
Cookies and device storage
Anymus uses only strictly necessary cookies: an anonymous session identifier and a CSRF security token, each lasting up to 7 days. No advertising or analytics cookies are used, so there is no tracking-cookie banner.
Room history, messages, attachments, preferences, and similar requested features use browser storage. You can remove them with the app's room deletion controls or your browser's site-data controls.
Recipients and international processing
Hetzner hosts the service in Germany. bunny.net processes CDN requests at globally distributed edges. Cloudflare provides authoritative DNS only. Migadu processes service correspondence in Switzerland; Switzerland has an EU adequacy decision. These providers may disclose data when legally required and use their applicable contractual and transfer safeguards. Provider DPA links are on the legal page.
Room participants receive the content and connection information needed for P2P communication. In direct mode, peers may learn candidate-derived network information about each other. TURN can hide direct peer addresses from the other peer, while the relay still sees connection metadata.
Your rights
Depending on the circumstances, you may ask for access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. There is no solely automated decision-making with legal or similarly significant effects.
Because Anymus has no accounts, the operator may be unable to link anonymous technical records to you without information such as a request ID or the email used to contact us. The operator may need to verify a request before disclosing data.
Email privacy@anymus.net. You may also complain to Norway's Data Protection Authority (Datatilsynet) or another competent supervisory authority.