CollaBoard

Privacy Policy & Usage Terms

Effective 2026-09-27. What CollaBoard processes, why, and when it is deleted.

Privacy Policy

Transparent documentation of what data CollaBoard processes, why, and when it is deleted, based on current service code and production architecture.
Effective 2026-09-27 · Operator Jonghoon Kim (Still Coding) · Republic of Korea · Contact still.coding.cc@gmail.com

01 / SCOPE

Information We Process

Stored in Browser Storage

  • Nickname, avatar, randomly generated session identifier
  • Room member tokens for re-entry (expires in 24 hours)
  • Notice drafts, poll/quiz records, feedback templates, user guide seen status

Stored on Service Server (Cloudflare Durable Objects)

  • Room code, title, initial board type, approval settings, creation and active timestamps
  • Host session identifier and owner token, password salt and hash (plaintext passwords never stored)
  • Participant session IDs, member token hashes, kicked list and rejection logs
  • Waiting room requests: nickname, avatar, verification code (max 2 minutes)
  • Hashed IP addresses to throttle brute force and spam (plaintext IP never stored)

Transient In-Memory Signaling (Not Persisted)

  • Nickname, avatar, role, join time for live participants list
  • WebRTC SDP offers, answers, and ICE candidates for peer connectivity relay

Operational Logs: Cloudflare Workers Logs samples approximately 10% of HTTP/WebSocket requests, recording request URLs, metadata, and error codes.

02 / PURPOSE

Purpose of Processing

  • Room creation, admission authentication, and host privilege verification
  • Displaying participant rosters and relaying peer-to-peer connection signals
  • Protecting rooms against brute force password attacks and join spam
  • Error diagnostics, service reliability, and uptime monitoring

We never process data for user profiling, behavioral tracking, advertising targeting, or sale to third parties.

03 / PEERS

Peer-to-Peer Data Transmission

Drawings, ideas, questions, votes, quiz responses, notices, feedback, and files are designed to never touch server storage, transmitting directly between participant browsers over encrypted P2P channels.

Anyone admitted to the room can receive these materials. Do not post unauthorized or sensitive materials, and share invite links only with trusted team members.

04 / THIRD PARTY

External Services and Cross-Border Transfers

  • Cloudflare — Website delivery, Worker execution, Durable Object storage, operational logs, and fallback TURN relay when direct P2P is blocked. Content remains end-to-end encrypted across Cloudflare's global edge network.
  • Google STUN Servers — Queries public IP addresses and ports to facilitate WebRTC NAT traversal.
  • jsDelivr CDN — Delivers web fonts and client-side QR generation libraries; request IP address and browser headers may be transmitted during download.

05 / RETENTION

Data Retention & Deletion

  • Room Data: Automatically deleted along with member tokens and kick records after 24 hours of inactivity
  • Empty Rooms: Inactive empty rooms eligible for overwrite after 10 minutes
  • Short-lived Tokens: Admission tickets expire in 60s, waiting requests in 2m, rate-limit logs in 10m
  • Cloudflare Workers Logs: Retained for up to 3 days
  • Browser Storage: Retained until user clears site data in browser settings (expired tokens auto-pruned)

06 / CONTROL

User Rights and Data Control

  • You can purge all locally saved CollaBoard data at any time via your browser's 'Clear Site Data' settings.
  • Room hosts can kick unwanted participants, and authors/hosts can delete announcements. Note that already downloaded copies on peer devices cannot be remotely deleted.
  • Privacy inquiries can be submitted via email. We only request the minimum information required for verification, never IDs or sensitive documents.

07 / COOKIES & ADS

Advertising and Cookie Policy

No advertisements are ever displayed inside real-time team rooms, collaborative whiteboard canvases, file transfer panels, voting sheets, or admission dialogs.

Non-personalized or consent-based ads (such as Google AdSense) may be displayed exclusively within eligible public informational areas, such as the lobby overview and user guide.

Google and third-party ad vendors may use cookies and web beacons to serve ads on public pages. Users may opt out of personalized ads via Google Ads Settings (adssettings.google.com) or browser cookie controls.

For users in the European Economic Area (EEA), the UK, and Switzerland, compliance with Google's Consent Management Platform (CMP) standards is observed.

When service data practices or policies change, both the effective date and text will be updated.

Important Notes Before Use

Key guidelines to ensure safe, smooth collaboration.

01Data Handled by Server vs Data Kept on Devices

Room codes, room titles, nicknames, avatars, presence status, and connection signaling pass through the service server. Passwords are stored only as cryptographic hashes, never plaintext.

Collaboration artifacts such as canvas strokes, brainstorm cards, questions, votes, notices, and files are never stored on the server — transferred directly between browsers via encrypted P2P. Rooms inactive for 24 hours are permanently purged.

02Room Links and Entry Protection

Anyone with the room link or code can attempt to enter, inspect shared material, and save copies. Do not share invite links on public forums for confidential sessions.

For sensitive meetings, enable both room password and admission approval. Unwanted participants can be removed by the room host at any time.

03Responsibility for Shared Materials

Ensure you have proper authorization or rights to share any uploaded files, images, or notices. Verify before transmitting sensitive confidential documents or personal data.

Since materials are delivered directly to peer devices, content already received and saved by participants cannot be remotely revoked.

04Browser Storage and Network Topology

Nicknames, notice drafts, poll records, and feedback templates are saved in browser local storage. Clear site data when using public computers. Clearing site data removes locally cached items.

Direct P2P connections may be restricted on enterprise, school, or firewall-protected networks. In such cases, traffic relays through encrypted TURN servers without compromising privacy.

05Intended Use and Service Evolution

Poll tallies, quiz scores, and feedback answers are intended for collaborative teamwork and do not guarantee cryptographic voting auditability. Do not rely on them for legally binding elections or official appraisals.

Data stored only in browser memory may disappear after all participants leave; export necessary summaries before closing. Features and guides may evolve to improve collaboration.

Contact & Inquiries

We accept bug reports, privacy inquiries, and usage questions via email. Please include details to help reproduce any issues.

PUBLIC CONTACT

still.coding.cc@gmail.com

Operator Jonghoon Kim · Still Coding · Republic of Korea

01 / REPORT

Helpful Information When Reporting Issues

  • Board name used and the approximate time the issue occurred
  • Browser, device model, and exact error message displayed
  • Room code if related to a room. Never send passwords, host tokens, or full invite links.
  • Brief explanation necessary for verification if requesting privacy or rights inquiries

02 / SAFETY

⚠️ Do Not Send Sensitive Personal Information

Never include national IDs, passwords, financial details, or API keys in support emails. We only require the minimum information necessary to resolve your issue.

Create Room Now →