Legal / Plain language
Privacy policy
NulBridge has no accounts and stores no messages. This policy explains the limited technical data involved in connecting two browsers: what it is, who handles it and for how long.
Last updated:
The short version
No account, no profile.
NulBridge never asks for your name, email address or phone number.
Conversations aren’t stored.
Messages, files and calls go between the two browsers and vanish when the session ends.
No cookies, no tracking.
No analytics scripts, ads or third-party code. Only your theme choice is saved, on your device.
The link secret stays private.
The part of a private link after the # never reaches any server.
A few services help you connect.
They see technical data such as your IP address. Never your messages, files or keys.
Your peer sees your IP address.
The person you connect with can see it. That is how peer-to-peer connections work.
On this page12 sections
Who we are
This policy covers NulBridge at nulbridge.pages.dev: the website and the web app that runs in your browser. It is run by the operator of this deployment (“we”, “us”).
It is written in plain language and describes this deployment exactly, including the outside services it is configured to use.
What we don’t collect
- No accounts. There is no sign-up, so there is no name, email address, phone number or password to store.
- No conversations. We never receive the content of your messages, files or calls.
- No cookies. NulBridge doesn’t set any.
- No analytics or tracking scripts. The site loads no third-party scripts, fonts or tracking pixels.
- No data sales. We don’t sell or rent data, and we don’t use it for advertising.
On your device
NulBridge saves one setting in your browser’s local storage: your theme choice, under the key nb-theme. It never leaves your device. Choosing “System” again, or clearing this site’s data, removes it.
If the site is updated while a tab is open, that tab may keep a timestamp in session storage (nb-chunk-reload-at) so that it reloads only once. Session storage is cleared when you close the tab.
Your conversations
Messages, files and calls travel directly between the two browsers whenever the network allows. When it doesn’t, they can pass through a relay that only forwards encrypted traffic (see TURN relay below).
- Messages and file chunks are end-to-end encrypted with AES-256-GCM, using keys created in your browser for that session only.
- Calls use WebRTC’s built-in DTLS-SRTP encryption. NulBridge doesn’t record them.
- Everything lives in the memory of the two browser tabs. When either tab closes or the session ends, it is gone. Files you download stay wherever you save them.
We never have your conversations, so we can’t read, recover or hand them over. The other person can copy, save or screenshot anything you send, so share only what you’re comfortable with them keeping. The security model explains the encryption in detail.
Your private link
A private link looks like https://nulbridge.pages.dev/join/<id>#<secret>. The part after the # is a 256-bit secret created in your browser.
- Browsers never send the part after
#to a server. The secret doesn’t reach our host, the signaling server or anyone else on the network. - When the other person opens the link, NulBridge removes the secret from their address bar.
- The secret is mixed into the session keys, so even a misbehaving signaling server can’t read or forge your messages.
Anyone with the full link can join until someone does, and the service you send it through, such as your email provider or messenger, can see it. Send it only to the person you mean, through a channel you trust. Once someone has joined, or the host’s tab closes, the link stops working.
Services that help you connect
Two browsers can’t find each other on their own. The services below help set up the connection. They handle technical data such as IP addresses, never the content of your messages, files or calls, and never your encryption keys.
Reading this website only involves our host. The others are contacted only when you create or join a session, or run the connection check.
Hosting
Cloudflare Pages- Provider
- Cloudflare, which serves this website through Cloudflare Pages.
- Sees
- Your IP address, browser type and the pages you request, like any web server.
- When
- Every time you load a page.
- Kept
- In Cloudflare’s logs, under its privacy policy. We can see aggregate traffic numbers in Cloudflare’s dashboard, such as request counts.
Signaling server
PeerJS cloud- Provider
- The public PeerJS cloud server (
0.peerjs.com), run by the PeerJS open-source project. It is NulBridge’s default. - Sees
- Your IP address, a random peer ID for the session, and connection-setup data: network addresses and public keys.
- Never sees
- The content of your messages, files or calls, your encryption keys or the link secret.
- When
- From the moment you create or join a session until it ends, and during the connection check.
- Kept
- By the PeerJS project, under its own policies. We don’t control its logs.
STUN servers
Google and Cloudflare- Provider
- Google and Cloudflare
- Servers
stun.l.google.com,stun1.l.google.com,stun.cloudflare.com- Sees
- Your public IP address and port. A STUN server tells your browser how it appears on the internet, so a direct connection can be set up.
- When
- While a connection is being set up.
- Kept
- Under each provider’s own privacy policy.
TURN relay
Optional · not configured- Status
- Not configured on this site.
- What it means
- Sessions only work where a direct connection is possible, and no relay ever handles your traffic.
6-digit code service
Supabase- Provider
- Supabase, which hosts the small database behind 6-digit codes.
- Stores
- The code and the waiting host’s peer ID. A code works once and is unusable after 10 minutes. It is deleted when it is used or cancelled, and otherwise shortly after it expires.
- Also stores
- A hashed form of your network address (SHA-256 with a secret pepper; for IPv6, of the /64 block), never the address itself. It enforces rate limits and is deleted after about an hour.
- Rate limits
- Per network address, every 10 minutes: 10 failed code attempts, 20 new codes and 60 cancelled codes.
- Platform logs
- Supabase’s own logs may record IP addresses, under its privacy policy.
- Not involved
- Private links. They never touch this service.
What the other person sees
- Your IP address. To connect directly, the two browsers exchange network addresses during setup, so the person you connect with can see your public IP address, even if the connection ends up running through a relay.
- Everything you send. Messages, files, and your voice and camera image during calls.
To keep your IP address from the other person, use a VPN you trust, and connect only with people you’re comfortable sharing it with. See also: Is NulBridge anonymous?
How long data is kept
| Data | Kept for |
|---|---|
| Messages, files and calls | Never stored. They live in the two tabs’ memory until the session ends. |
| Link secret | Never sent to any server. |
| Theme choice | On your device, until you change it or clear the site’s data. |
| 6-digit code and peer ID | Unusable after 10 minutes, deleted shortly after. |
| Hashed network address | About an hour. |
| Server and network logs | Kept by the providers above, under their own policies. |
Your rights
Depending on where you live, you may have the right to access, correct or delete personal data about you, to object to how it is used, and to complain to a data protection authority.
In practice, we hold almost nothing that could identify you: no account, no messages and no raw IP addresses. Code records disappear within minutes and rate-limit records within about an hour, so by the time you ask there is usually nothing left to share or delete.
Logs kept by the providers above are covered by their own privacy policies. For any other request, contact the operator of this deployment. We use the limited data described here only to connect you and to protect the service from abuse.
Children
NulBridge is not directed at children under 13, and we don’t knowingly process data about them. There are no accounts, so we can’t check anyone’s age. If you are a parent or guardian with a concern, contact the operator of this deployment.
Changes to this policy
If the way NulBridge handles data changes, we will update this page and the “Last updated” date at the top. There are no accounts, so we can’t notify you directly: check back here if it matters to you.
Contact
This deployment doesn’t list a contact address. For questions about privacy or this policy, contact the operator of this deployment.
To report a security problem, see the security page.
End of document
Read next
Last updated: