Skip to content
  • P2P
  • E2EE
  • No accounts
  • Nothing stored
  • Free

Legal / Plain language

Privacy policy

NulBridge has no accounts and stores no messages. This policy explains the limited technical data involved in connecting two browsers: what it is, who handles it and for how long.

Plain-language document

Last updated:

The short version

6 points
  • No account, no profile.

    NulBridge never asks for your name, email address or phone number.

  • Conversations aren’t stored.

    Messages, files and calls go between the two browsers and vanish when the session ends.

  • No cookies, no tracking.

    No analytics scripts, ads or third-party code. Only your theme choice is saved, on your device.

  • The link secret stays private.

    The part of a private link after the # never reaches any server.

  • A few services help you connect.

    They see technical data such as your IP address. Never your messages, files or keys.

  • Your peer sees your IP address.

    The person you connect with can see it. That is how peer-to-peer connections work.

On this page12 sections

Who we are

This policy covers NulBridge at nulbridge.pages.dev: the website and the web app that runs in your browser. It is run by the operator of this deployment (“we”, “us”).

It is written in plain language and describes this deployment exactly, including the outside services it is configured to use.

What we don’t collect

  • No accounts. There is no sign-up, so there is no name, email address, phone number or password to store.
  • No conversations. We never receive the content of your messages, files or calls.
  • No cookies. NulBridge doesn’t set any.
  • No analytics or tracking scripts. The site loads no third-party scripts, fonts or tracking pixels.
  • No data sales. We don’t sell or rent data, and we don’t use it for advertising.

On your device

NulBridge saves one setting in your browser’s local storage: your theme choice, under the key nb-theme. It never leaves your device. Choosing “System” again, or clearing this site’s data, removes it.

If the site is updated while a tab is open, that tab may keep a timestamp in session storage (nb-chunk-reload-at) so that it reloads only once. Session storage is cleared when you close the tab.

Your conversations

Messages, files and calls travel directly between the two browsers whenever the network allows. When it doesn’t, they can pass through a relay that only forwards encrypted traffic (see TURN relay below).

  • Messages and file chunks are end-to-end encrypted with AES-256-GCM, using keys created in your browser for that session only.
  • Calls use WebRTC’s built-in DTLS-SRTP encryption. NulBridge doesn’t record them.
  • Everything lives in the memory of the two browser tabs. When either tab closes or the session ends, it is gone. Files you download stay wherever you save them.

We never have your conversations, so we can’t read, recover or hand them over. The other person can copy, save or screenshot anything you send, so share only what you’re comfortable with them keeping. The security model explains the encryption in detail.

Services that help you connect

Two browsers can’t find each other on their own. The services below help set up the connection. They handle technical data such as IP addresses, never the content of your messages, files or calls, and never your encryption keys.

Reading this website only involves our host. The others are contacted only when you create or join a session, or run the connection check.

Hosting

Cloudflare Pages
Provider
Cloudflare, which serves this website through Cloudflare Pages.
Sees
Your IP address, browser type and the pages you request, like any web server.
When
Every time you load a page.
Kept
In Cloudflare’s logs, under its privacy policy. We can see aggregate traffic numbers in Cloudflare’s dashboard, such as request counts.

Signaling server

PeerJS cloud
Provider
The public PeerJS cloud server (0.peerjs.com), run by the PeerJS open-source project. It is NulBridge’s default.
Sees
Your IP address, a random peer ID for the session, and connection-setup data: network addresses and public keys.
Never sees
The content of your messages, files or calls, your encryption keys or the link secret.
When
From the moment you create or join a session until it ends, and during the connection check.
Kept
By the PeerJS project, under its own policies. We don’t control its logs.

STUN servers

Google and Cloudflare
Provider
Google and Cloudflare
Servers
stun.l.google.com, stun1.l.google.com, stun.cloudflare.com
Sees
Your public IP address and port. A STUN server tells your browser how it appears on the internet, so a direct connection can be set up.
When
While a connection is being set up.
Kept
Under each provider’s own privacy policy.

TURN relay

Optional · not configured
Status
Not configured on this site.
What it means
Sessions only work where a direct connection is possible, and no relay ever handles your traffic.

6-digit code service

Supabase
Provider
Supabase, which hosts the small database behind 6-digit codes.
Stores
The code and the waiting host’s peer ID. A code works once and is unusable after 10 minutes. It is deleted when it is used or cancelled, and otherwise shortly after it expires.
Also stores
A hashed form of your network address (SHA-256 with a secret pepper; for IPv6, of the /64 block), never the address itself. It enforces rate limits and is deleted after about an hour.
Rate limits
Per network address, every 10 minutes: 10 failed code attempts, 20 new codes and 60 cancelled codes.
Platform logs
Supabase’s own logs may record IP addresses, under its privacy policy.
Not involved
Private links. They never touch this service.

What the other person sees

  • Your IP address. To connect directly, the two browsers exchange network addresses during setup, so the person you connect with can see your public IP address, even if the connection ends up running through a relay.
  • Everything you send. Messages, files, and your voice and camera image during calls.

To keep your IP address from the other person, use a VPN you trust, and connect only with people you’re comfortable sharing it with. See also: Is NulBridge anonymous?

How long data is kept

Retention at a glance
DataKept for
Messages, files and callsNever stored. They live in the two tabs’ memory until the session ends.
Link secretNever sent to any server.
Theme choiceOn your device, until you change it or clear the site’s data.
6-digit code and peer IDUnusable after 10 minutes, deleted shortly after.
Hashed network addressAbout an hour.
Server and network logsKept by the providers above, under their own policies.

Your rights

Depending on where you live, you may have the right to access, correct or delete personal data about you, to object to how it is used, and to complain to a data protection authority.

In practice, we hold almost nothing that could identify you: no account, no messages and no raw IP addresses. Code records disappear within minutes and rate-limit records within about an hour, so by the time you ask there is usually nothing left to share or delete.

Logs kept by the providers above are covered by their own privacy policies. For any other request, contact the operator of this deployment. We use the limited data described here only to connect you and to protect the service from abuse.

Children

NulBridge is not directed at children under 13, and we don’t knowingly process data about them. There are no accounts, so we can’t check anyone’s age. If you are a parent or guardian with a concern, contact the operator of this deployment.

Changes to this policy

If the way NulBridge handles data changes, we will update this page and the “Last updated” date at the top. There are no accounts, so we can’t notify you directly: check back here if it matters to you.

Contact

This deployment doesn’t list a contact address. For questions about privacy or this policy, contact the operator of this deployment.

To report a security problem, see the security page.