Nydus Chat
Privacy Policy
Effective August 20, 2026. Nydus Chat is operated by SR2 Labs LLC (Virginia, USA).
This policy explains what we collect, why, and what happens to it. The short version: we collect what a chat service needs to function, we don't run ads, we don't sell your data, and we don't use your content to train AI models.
What we collect
- Account information: email address, username, and a hash of your password (we store bcrypt hashes, never the password itself), plus optional profile details you add such as display name, avatar, status, timezone, and theme.
- Your content: messages, uploaded files and images, emoji reactions, and similar content you submit. Message content is stored unencrypted at rest on our servers so the service can render, search, and deliver it — an administrator with database access could technically read it. Do not treat Nydus Chat as an end-to-end-encrypted messenger.
- Technical data: IP addresses and standard request logs, session cookies that keep you signed in, connection metadata, and device push tokens if you enable notifications.
- Voice and video in calls are transmitted through our servers, encrypted in transit (DTLS-SRTP), and are not recorded or stored.
- Payments: if you buy supporter features, your card details go to Stripe, not to us; we receive confirmation of the purchase and what it unlocks.
What we use it for
Operating the service: delivering messages, storing your uploads, keeping you signed in, sending transactional email (password resets, account notices), preventing abuse and enforcing our Terms, and debugging with request logs. If you joined our pre-launch mailing list, we send occasional product announcements; every one has an unsubscribe link. We do not sell personal information, we do not use your content for advertising, and we do not use your content to train AI models.
Where it lives and who touches it
Data is stored on servers we control at our hosting provider, DigitalOcean (USA). Nightly encrypted backups are kept for 14 days, with an off-site copy retained for up to 21 days. Our service providers are: DigitalOcean (hosting), Resend (email delivery), Stripe (payments), and Apple/Google push-notification services if you enable mobile notifications. Each receives only what its function requires. We disclose data beyond this only if required by law (for example, a valid subpoena), to protect the safety of users, or in a business transfer — in which case this policy continues to apply to it.
Retention and deletion
Your data stays as long as your account exists. You can delete your account in account settings; doing so permanently deletes your account record and the messages and direct messages you sent from the live database. Messages you delete individually are removed from the live database when you delete them. Deleted data persists in backups until those expire on the schedule above (at most 21 days).
Your rights
Email sdhar@protonmail.com to request a copy of your data or its deletion, and we will respond within 30 days. California residents: we do not sell or share personal information as defined by the CCPA, and we honor access and deletion requests as above. The Service is operated from the USA; if you use it from elsewhere, your data is handled as described here and requests can be sent to the same address.
Children
The Service is not for children under 13, and we do not knowingly collect their data. If we learn an account belongs to a child under 13, we delete it. Contact sdhar@protonmail.com if you believe this has happened.
Security
Passwords are bcrypt-hashed, connections use TLS, and voice/video use DTLS-SRTP encryption in transit. Access to production systems is limited to the operator. No system is perfectly secure — if we learn of a breach affecting your data, we will notify affected users without unreasonable delay.
Changes
We will post changes here, and for material changes we will notify you in the Service or by email before they take effect.
Contact
SR2 Labs LLC · 8401 Mayland Dr Ste A, Henrico, VA 23294, USA · sdhar@protonmail.com