S
SecretMsg Zero-Log
Strict Zero-Log Policy • Updated September 2026

Privacy Policy

At SecretMsg (secretmsg.net), privacy is not an afterthought or marketing slogan—it is the foundational design constraint of our entire architecture.

visibility_off

No Sender Identity

When sending an anonymous message, zero personal identifiers or accounts are tied to your text.

money_off

Zero Data Brokers

We never sell, trade, or monetize user data. No Facebook or Google tracking pixels exist on our platform.

delete_forever

1-Tap Total Erasure

Account deletion permanently wipes out your email, handle, and every single message in the database instantly.

01 What Information We Collect

A. For Anonymous Message Senders

  • Zero Identification: We do NOT collect or store your real name, phone number, address, or social profile credentials.
  • Message Content: The text you submit is stored securely in encrypted storage solely so the recipient can read it.
  • Spam Defense (Cloudflare Turnstile): Non-invasive browser validation verifies human interaction without storing tracking cookies.
  • Transient Edge Telemetry: Cloudflare edge nodes process request headers transiently for anti-DDoS rate-limiting; your IP is never saved with the message text.

B. For Registered Recipients (Account Holders)

  • Email Address: Used solely to authenticate your login via passwordless One-Time Passcodes (OTP).
  • Unique Username / Handle: The public slug used to generate your public TBH card link (e.g., secretmsg.net/yourname).
  • Inbox Contents: Received anonymous messages, archived notes, and responses.

02 What We Will NEVER Do

🚫 We never sell, rent, license, or trade your personal email address or message logs to third-party data brokers or marketing conglomerates.

🚫 We never disclose the sender's identity or IP address to the message recipient.

🚫 We never run retargeting pixels, advertising trackers, or invasive analytics scripts.

03 Third-Party Service Providers

SecretMsg relies only on minimal, enterprise-grade privacy infrastructure:

Cloudflare (Edge & D1 Database) Provides TLS 1.3 encrypted edge routing, DDoS shielding, and distributed SQLite database storage.
Resend (Transactional OTP Email) Dispatches short-lived 6-digit login verification codes directly to your inbox. Zero marketing newsletters.

04 GDPR & CCPA Rights: Instant Complete Deletion

Under the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and our fundamental engineering principles, you retain the unmitigated right to erasure:

lock_reset Self-Service Account Wipeout

Open Settings → Delete Account at any time. When confirmed, a cascaded SQL transaction permanently purges your account row, email address, custom handle, and all inbox messages forever. This process is instant and cannot be undone.

05 Inquiries & Data Protection Contact

If you have questions regarding this Privacy Policy or wish to request data verification, contact the project maintainer:

SecretMsg Privacy Contact privacy@secretmsg.net
Send Inquiries
© 2026 SecretMsg. All rights reserved.