Privacy Policy
Platform: Hourglass (hourglasschat.com)
Effective Date: June 18, 2026
This Privacy Policy explains what information Hourglass (“Platform”, “we”, “us”, or “our”) collects, why, and what rights you have over it. It is incorporated by reference into our Terms of Use.
1. Information We Collect
1.1 Anonymous Browsing
You can use most of the Platform without registering. We issue your browser an anonymous, randomly-generated identity (via Supabase Auth) stored in a session cookie. It is not linked to your name or email. We also log the IP address associated with that identity (see 1.4).
1.2 Registered Accounts
If you create an account, we collect the email address and password you provide (passwords are hashed by our authentication provider; we never see or store them in plain text), plus any display name or username you choose.
1.3 Content You Submit
We store the media (images/videos), room/album titles, chat messages, comments, private messages, and reports you submit, along with metadata such as file size, dimensions, and timestamps. Media in non-persistent rooms is automatically deleted after that room's configured TTL (as short as 15 minutes by default); see the room/category for its specific retention window.
1.4 IP Addresses
We record the IP address(es) associated with each identity solely for abuse prevention — so that a ban on one identity can be extended to other identities created from the same IP to evade it. Moderators and admins cannot read raw IP addresses through the Platform UI; this data is only used internally by automated ban-enforcement logic.
1.5 Payment Information
Hourglass does not currently process payments. If a paid subscription tier is enabled in the future, billing will be handled entirely by a third-party payment processor — we will never receive or store your full card number. This section will be updated to name that processor before any paid tier goes live.
1.6 Cookies & Local Storage
We use:
- Strictly necessary cookies — set by our authentication provider (Supabase) to keep you signed in / maintain your anonymous session. These are required for the Platform to function and are not used for tracking or advertising.
- Local storage (no cookies)— your 18+ adult-content confirmation, kept on your device only, so we don't store it in our database.
- Third-party advertising cookies — see Section 3.
2. How We Use This Information
- To operate core features: rooms, uploads, chat, comments, private messages, and voting.
- To enforce our Terms of Use — content moderation, reports, and ban/abuse prevention.
- To keep the Platform secure and to detect, investigate, and prevent fraud or abuse.
- To comply with legal obligations, including responding to lawful requests from authorities.
We do not sell your personal information.
3. Third-Party Service Providers
We share data with the following categories of service providers, only as needed to run the Platform:
- Supabase— authentication, database, and realtime messaging infrastructure. Account, content, and IP data described above is stored in Supabase's infrastructure.
- Cloudflare (R2 storage + Workers) — hosts uploaded media files and runs the background job that deletes expired media.
- ExoClick (magsrv)— our advertising network. ExoClick may set its own cookies or similar technologies in your browser to serve and measure ads, and may collect technical data (such as IP address and device/browser information) under its own privacy policy. Ads do not run for active subscribers. We do not control, and are not responsible for, ExoClick's data practices — review their privacy policy directly for details.
- A future payment processor — once a paid tier is enabled (see 1.5), checkout and billing data will be handled directly by that processor under its own privacy policy.
We do not share your data with third parties for their own independent marketing purposes beyond the advertising delivery described above.
4. Data Retention
- Media and chat messages in non-persistent rooms are deleted automatically per that room's TTL.
- Reports, ban records, and IP records are retained as long as needed for moderation and abuse prevention, and may persist after the related content is deleted.
- Account data (email, username) is retained until you delete your account or request deletion.
5. Your Rights
5.1 All Users
You may request access to, correction of, or deletion of your personal data, or ask us to stop processing it, by emailing legal@hourglasschat.com. We will respond within a reasonable time and may need to verify your identity first. Deleting your account does not retroactively delete content already shared with other users, or records we're legally required to keep (e.g. abuse/ban records).
5.2 EEA / UK Users (GDPR / UK GDPR)
If you are located in the European Economic Area or United Kingdom, you have the right to access, rectify, erase, restrict, or port your data, and to object to certain processing. Our legal basis for processing is generally our legitimate interest in operating and securing the Platform, your consent (e.g. for non-essential cookies), or performance of a contract (for registered accounts). You may lodge a complaint with your local data protection authority.
5.3 California Users (CCPA/CPRA)
California residents have the right to know what personal information we collect, to request deletion, and to opt out of the “sale” or “sharing” of personal information. We do not sell personal information for money. To the extent ad delivery (Section 3) constitutes “sharing” under the CCPA/CPRA, you may opt out by declining non-essential cookies where prompted, or by emailing legal@hourglasschat.com. We will not discriminate against you for exercising these rights.
6. Children's Privacy
The Platform is not directed to children under 13, and adult-designated areas are restricted to users 18 or older (see our Terms of Use). We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us personal information, contact legal@hourglasschat.com and we will delete it.
7. International Data Transfers
The Platform is operated from the United States, and our service providers may process data in the United States or other countries. By using the Platform, you understand your data may be transferred to and processed in jurisdictions with different data protection laws than your own.
8. Security
We use reasonable technical and organizational measures to protect your data, including encrypted connections (HTTPS), hashed passwords, and access controls on our database. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be noted by updating the Effective Date above, and where appropriate, by notifying registered users directly. Continued use of the Platform after changes are posted constitutes acceptance of the revised policy.
10. Contact
Hourglass
Email: legal@hourglasschat.com
Website: hourglasschat.com
© 2026 Hourglass. All rights reserved. This Privacy Policy was last updated on June 18, 2026.