Legal
Privacy Policy
Last updated: July 23, 2026
SealTwo (“SealTwo,” “we,” “us”) provides a browser-based private chat service for two people. This Privacy Policy explains what information is processed when you use SealTwo and what is intentionally not stored.
1. Summary
- We do not require an account, email, or phone number.
- Message content and media are end-to-end encrypted in your browser. We cannot read them.
- Active sessions are kept in server memory only for delivery and are not written to a message database.
- We use a short-lived seat cookie so the same browser can reconnect to a room.
2. Information we process
2.1 Session and connection data
To operate the service, the server may process:
- Room/invite identifiers
- Anonymous seat identifiers and seat tokens
- Connection metadata needed for WebSocket delivery
- Basic technical logs such as timestamps and error events
This data is used to create rooms, enforce the two-seat limit, relay encrypted packets, and keep the service reliable.
2.2 Seat cookie
SealTwo sets an HttpOnly cookie (for example
sealtwo_seat_*) that binds your browser to a seat in a
room. The cookie contains the room code, seat id, and a secret token.
It is not used for advertising and is not a marketing tracker.
2.3 Message content
Chat text, reactions, and media are encrypted on your device before they are sent. The server relays ciphertext. SealTwo does not store a readable message history, and conversations are not available after a room ends or the in-memory session is cleared.
2.4 Local device data
Your browser may keep temporary data in memory while the page is open (for example the on-screen transcript or media object URLs). Clearing or leaving the page removes that local view. SealTwo does not provide cloud backups of chats.
3. How we use information
We use the limited data above only to:
- Provide and secure the chat service
- Enforce room capacity and one-shot invites
- Support reconnection for reserved seats
- Diagnose outages or abuse of the service
4. Sharing
We do not sell personal information. We do not share message content with third parties because we do not have readable message content. Infrastructure providers that host SealTwo may process connection-level data as needed to run the service.
5. Retention
Room state is retained in memory while a session is active and for a short grace period to allow reconnects. When a room is dissolved or abandoned, that in-memory state is removed. Seat cookies expire after their configured lifetime or when you leave/dissolve a chat.
6. Security
SealTwo uses transport encryption (HTTPS/WSS in production) and end-to-end encryption for chat payloads. No method of transmission or storage is perfectly secure. You are responsible for sharing invites only with the intended recipient and for the security of your own device.
7. Children
SealTwo is not directed to children under 13 (or the minimum age required in your jurisdiction). Do not use the service if you are under that age.
8. Your choices
- Do not create a room or share an invite if you do not want to chat.
- Leave or dissolve a chat to end the session.
- Clear site cookies in your browser to remove seat cookies.
9. International users
If you access SealTwo from another country, connection data may be processed where the service is hosted. By using SealTwo, you understand that processing may occur outside your home country.
10. Changes
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Continued use of SealTwo after an update means you accept the revised policy.
11. Contact
For privacy questions about SealTwo, contact the operator of the SealTwo instance you are using (for the public site: [email protected]).