Privacy Policy & Usage Terms
Effective 2026-09-27. What CollaBoard processes, why, and when it is deleted.
Privacy Policy
Transparent documentation of what data CollaBoard processes, why, and when it is deleted, based on current service code and production architecture.
Effective 2026-09-27 · Operator Jonghoon Kim (Still Coding) · Republic of Korea · Contact still.coding.cc@gmail.com
01 / SCOPE
Information We Process
Stored in Browser Storage
- Nickname, avatar, randomly generated session identifier
- Room member tokens for re-entry (expires in 24 hours)
- Notice drafts, poll/quiz records, feedback templates, user guide seen status
Stored on Service Server (Cloudflare Durable Objects)
- Room code, title, initial board type, approval settings, creation and active timestamps
- Host session identifier and owner token, password salt and hash (plaintext passwords never stored)
- Participant session IDs, member token hashes, kicked list and rejection logs
- Waiting room requests: nickname, avatar, verification code (max 2 minutes)
- Hashed IP addresses to throttle brute force and spam (plaintext IP never stored)
Transient In-Memory Signaling (Not Persisted)
- Nickname, avatar, role, join time for live participants list
- WebRTC SDP offers, answers, and ICE candidates for peer connectivity relay
Operational Logs: Cloudflare Workers Logs samples approximately 10% of HTTP/WebSocket requests, recording request URLs, metadata, and error codes.
02 / PURPOSE
Purpose of Processing
- Room creation, admission authentication, and host privilege verification
- Displaying participant rosters and relaying peer-to-peer connection signals
- Protecting rooms against brute force password attacks and join spam
- Error diagnostics, service reliability, and uptime monitoring
We never process data for user profiling, behavioral tracking, advertising targeting, or sale to third parties.
03 / PEERS
Peer-to-Peer Data Transmission
Drawings, ideas, questions, votes, quiz responses, notices, feedback, and files are designed to never touch server storage, transmitting directly between participant browsers over encrypted P2P channels.
Anyone admitted to the room can receive these materials. Do not post unauthorized or sensitive materials, and share invite links only with trusted team members.
04 / THIRD PARTY
External Services and Cross-Border Transfers
- Cloudflare — Website delivery, Worker execution, Durable Object storage, operational logs, and fallback TURN relay when direct P2P is blocked. Content remains end-to-end encrypted across Cloudflare's global edge network.
- Google STUN Servers — Queries public IP addresses and ports to facilitate WebRTC NAT traversal.
- jsDelivr CDN — Delivers web fonts and client-side QR generation libraries; request IP address and browser headers may be transmitted during download.
05 / RETENTION
Data Retention & Deletion
- Room Data: Automatically deleted along with member tokens and kick records after 24 hours of inactivity
- Empty Rooms: Inactive empty rooms eligible for overwrite after 10 minutes
- Short-lived Tokens: Admission tickets expire in 60s, waiting requests in 2m, rate-limit logs in 10m
- Cloudflare Workers Logs: Retained for up to 3 days
- Browser Storage: Retained until user clears site data in browser settings (expired tokens auto-pruned)
06 / CONTROL
User Rights and Data Control
- You can purge all locally saved CollaBoard data at any time via your browser's 'Clear Site Data' settings.
- Room hosts can kick unwanted participants, and authors/hosts can delete announcements. Note that already downloaded copies on peer devices cannot be remotely deleted.
- Privacy inquiries can be submitted via email. We only request the minimum information required for verification, never IDs or sensitive documents.
07 / COOKIES & ADS
Advertising and Cookie Policy
No advertisements are ever displayed inside real-time team rooms, collaborative whiteboard canvases, file transfer panels, voting sheets, or admission dialogs.
Non-personalized or consent-based ads (such as Google AdSense) may be displayed exclusively within eligible public informational areas, such as the lobby overview and user guide.
Google and third-party ad vendors may use cookies and web beacons to serve ads on public pages. Users may opt out of personalized ads via Google Ads Settings (adssettings.google.com) or browser cookie controls.
For users in the European Economic Area (EEA), the UK, and Switzerland, compliance with Google's Consent Management Platform (CMP) standards is observed.
When service data practices or policies change, both the effective date and text will be updated.
Important Notes Before Use
Key guidelines to ensure safe, smooth collaboration.
01Data Handled by Server vs Data Kept on Devices
Room codes, room titles, nicknames, avatars, presence status, and connection signaling pass through the service server. Passwords are stored only as cryptographic hashes, never plaintext.
Collaboration artifacts such as canvas strokes, brainstorm cards, questions, votes, notices, and files are never stored on the server — transferred directly between browsers via encrypted P2P. Rooms inactive for 24 hours are permanently purged.
02Room Links and Entry Protection
Anyone with the room link or code can attempt to enter, inspect shared material, and save copies. Do not share invite links on public forums for confidential sessions.
For sensitive meetings, enable both room password and admission approval. Unwanted participants can be removed by the room host at any time.
03Responsibility for Shared Materials
Ensure you have proper authorization or rights to share any uploaded files, images, or notices. Verify before transmitting sensitive confidential documents or personal data.
Since materials are delivered directly to peer devices, content already received and saved by participants cannot be remotely revoked.
04Browser Storage and Network Topology
Nicknames, notice drafts, poll records, and feedback templates are saved in browser local storage. Clear site data when using public computers. Clearing site data removes locally cached items.
Direct P2P connections may be restricted on enterprise, school, or firewall-protected networks. In such cases, traffic relays through encrypted TURN servers without compromising privacy.
05Intended Use and Service Evolution
Poll tallies, quiz scores, and feedback answers are intended for collaborative teamwork and do not guarantee cryptographic voting auditability. Do not rely on them for legally binding elections or official appraisals.
Data stored only in browser memory may disappear after all participants leave; export necessary summaries before closing. Features and guides may evolve to improve collaboration.
Create Room Now →