discussion.win — Privacy Policy
Last updated: 2026-10-03
This page explains, honestly and without jargon, what discussion.win does with your data. The short version:
- We store the email address and username of your account, your profile fields, your contacts, and your server memberships.
- In forum rooms (the global room, servers and their channels) messages are readable by the operator and pass an automated content filter.
- The shared encrypted room is encrypted at rest, but the service distributes its key to visitors — it is not zero-knowledge and should not be considered fully end-to-end encrypted.
- Private link rooms (addresses containing a key) are end-to-end encrypted; the operator cannot read them.
- Direct messages between mutual contacts can be end-to-end encrypted; the decryption keys never leave your devices.
- In every room, the operator can see metadata: IP addresses, timing, message sizes, and a random client identifier.
- Posted images load directly from the websites hosting them; those sites see your IP address (the referrer is suppressed).
- Voice notes and video messages are kept at most 7 days, then deleted automatically. In encrypted conversations they are encrypted before upload — we store ciphertext we cannot read.
- If you enable notifications, we store the push endpoint or device token needed to reach you — never message content.
- If you sign in with Google, Google shares your email address with us.
- No advertising, no analytics, no third-party trackers.
Accounts
You create an account by signing in with Google; we store the email address of that Google account and your username, and use the email address to sign you in (and nothing else — we do not send marketing email). Your username can be renamed once every 30 days; profile links under an old username stop working after a rename. Your profile fields (display name, bio, external link), the people you add as contacts, and the servers you join are also stored with your account. Anyone can view your public profile page.
Who can read your messages
- Forum rooms (the global room, servers and their channels): messages are stored and transmitted in plain text. The operator can read them, and they pass an automated content filter before other members see them.
- The shared encrypted room: messages are stored only in encrypted form — but every visitor receives the room key from the service itself. Because the operator distributes that key, the operator could read these messages too. This room is encrypted at rest, not zero-knowledge, and not full end-to-end encryption.
- Private link rooms (room addresses that contain a key
after
#k=): the key is part of the address and stays in your browser; it is never sent to our servers. These rooms are end-to-end encrypted and the operator cannot read them. Anyone who has the full link can read the room — share it carefully. - Direct messages (between mutual contacts only): can be end-to-end encrypted per conversation. Each device generates its own private key, which never leaves that device; we only ever see public keys and encrypted key material. We cannot read encrypted conversations. Any member of an encrypted conversation can reset its key — encrypted rooms rely on mutual trust between members.
Metadata we see in every room
Encryption hides message content — never the fact that you are using the service. In all rooms, including end-to-end encrypted ones, the operator can see:
- your IP address;
- when you connect, and when each of your messages is posted;
- the size of each message you send;
- a random client identifier your browser generates (used to avoid duplicate posts);
- presence — your mutual contacts can see that you were online within the last five minutes.
Images
Images posted in chat are not stored or proxied by us. Your browser loads them directly from the original hosting website, which will see your IP address and the request. We suppress the referrer, so the image host is not told which page linked the image. A blocklist of known adult and shock-content hosts is applied before an image is loaded.
Voice notes, video messages, and photo files
Media you send as messages — voice notes, video messages, photo files — is stored on our infrastructure and kept at most 7 days, then deleted automatically. In end-to-end encrypted conversations your device encrypts the media before upload; the stored bytes are ciphertext we cannot read.
Notifications
If you turn on notifications, we store the subscription needed to reach you (a web-push endpoint and its keys, or a device push token in the mobile apps). Notifications carry a name and a room reference — never message content. Turning notifications off deletes the subscription.
Google sign-in
Google's sign-in library is the only third-party script the site loads (only when the sign-in button is shown). If you sign in with Google, Google shares the email address of that account with us; we use it to find or create your account and derive a username from it. We never see your Google password. Google is currently the only sign-in method on the public site.
Contact backup
You can optionally back up the contact list from your phone. The backup is off by default and exists only if you turn it on. When it is on, we keep a readable copy of those phone contacts (names and phone numbers) so the list can be restored and so people you know can be found here. Only phone contacts you choose to include are stored — Telegram contacts are never uploaded. We do not use the backup for advertising and we do not give it to third parties. A backup is not a guarantee: we are not responsible for lost data. You can export or delete your backup at any time in settings.
Telegram
You can link a Telegram account to your profile. Linking works through a one-time code: you send the code to our Telegram bot from the Telegram app, and once the bot confirms it, the account is linked. You choose separately whether other people can find you by your Telegram account or by your phone number, and you can unlink at any time. Telegram chats and Telegram contacts stay on your device — the Telegram conversations you open in the app run through Telegram on your phone, and we never receive your Telegram contact list.
Cookies and local storage
- Session cookie: one cookie (
dw_session) keeps you signed in for about 30 days. It is HttpOnly (JavaScript cannot read it). There are no tracking cookies. - Local storage: your browser stores your devices' encryption keys (private keys never leave your device), your last-read position per room (unread badges — this stays on your device only), and your theme preference.
- Service worker: the app caches its own static files (the shell, styles, script) so it loads fast and works offline. Messages and API responses are never cached.
Where your data lives
All data — accounts, contacts, and stored messages — lives on Cloudflare's infrastructure, which also processes the traffic. We run no other databases and use no other hosting providers. The service is not directed at children under 13, and we do not knowingly collect email addresses from children under 13.
Moderation and retention
The operator can read and remove messages in forum rooms and in plain text direct messages. In encrypted rooms the operator cannot read content but can remove a message by its position in the room. Removed messages are hidden from everyone; a minimal record that a removal happened is kept for moderation audit. Messages are otherwise kept until removed. If you want specific content or your account data removed, contact the operator and we will do what is technically possible.
Changes to this policy
If this policy changes, the "last updated" date above changes with it. The service itself will tell you in-chat when something material changes.
Contact
The operator can be reached in the site's global room at discussion.win. See also: Terms of Service.