Privacy Policy
Last updated: 13 July 2026
Telepathy is a browser extension that synchronizes video playback between people in a shared, unlisted room and adds live chat. This policy explains exactly what data we handle, why, and your choices. We collect the minimum needed to run the service and we never sell your data.
By creating an account, continuing as a guest, joining a room, or otherwise using Telepathy, you acknowledge that you have read and agree to this Privacy Policy. If you do not agree, please do not use the extension.
1. Who we are (data controller)
The service is operated under the name Telepathy. For any privacy question or data request, contact privacy@telepathy.video. A self-hosted deployment has a different controller: the person or organization operating that server.
2. Single purpose
Telepathy exists for one purpose: to keep video playback in sync across people in a shared room and let them chat about it. Every permission below serves that purpose.
3. What we collect and why
| Data | Why | Where |
|---|---|---|
| Email + password (account) | So you can sign in and keep your identity across sessions. The password is transmitted over HTTPS and stored only as a salted scrypt hash. | Telepathy server |
| IP address and security events | Abuse prevention, rate-limiting, bans and operational security. Events may include an account identifier, room code and action metadata. | Telepathy server |
| Approximate location and network details (optional) | If the operator explicitly enables geo lookup, the IP-derived country, region, city, approximate latitude/longitude and internet service provider are used for security visibility. This is not device GPS or a precise street address. | Telepathy server and ipwho.is |
| Playback and live connection signals | Play/pause/seek position, playing/video-availability state and a recent round-trip-time estimate to the Telepathy service keep the room synchronized. The short-lived latency value may be shown to other current room members as a connection-quality indicator. | Telepathy service; limited playback-action metadata may also enter a bounded operational log |
| Chat and reactions | Relayed to room participants. Recent messages remain available while the room is active so late joiners can receive context. Durable security logging stores sender/room/length metadata by default; an operator can explicitly enable body logging and must disclose that configuration. | Telepathy server |
| Watched page (domain + URL) | The host's page address lets an invite open the same page and helps player detection. It may appear in time-limited operational logs. | Telepathy server |
| Display name and avatar | Shown to room participants and attached to room activity. Bounded operational metadata can retain the display name. | Your browser and Telepathy server |
| Preferences | Remember settings such as cinema mode and optional ad skipping. | Your browser (local) |
| Session token | Keeps you signed in without re-entering your password. A copy is stored locally and the corresponding session record is stored server-side until logout or expiry. | Your browser and Telepathy server-side database |
| Random installation identifier | Supports abuse prevention for the optional player-detection service. It is not a hardware identifier. | Your browser and Telepathy server |
We do NOT collect: the video/audio stream itself, a general history of pages you visit outside an active Telepathy session, keystrokes, biometric data, or payment information. We do not sell your data or use it for advertising.
4. Legal basis for processing (GDPR Art. 6)
- Performance of a contract / steps at your request — account, session, room, chat and sync data are processed to provide the service you request.
- Legitimate interests — proportionate IP, abuse-prevention and security records support service security and reliability. You may object as described below.
- Consent — used only where the operator presents a genuine optional choice and applicable law requires consent. Merely using Telepathy is not treated as blanket consent for unrelated processing.
The production operator must confirm the applicable legal bases and required notices for its jurisdiction with qualified counsel; this repository is not a substitute for legal advice.
5. Browser permissions
- storage — save your name, avatar, preferences and session token locally.
- sidePanel — show Telepathy in the browser side panel.
- scripting + optional host access — when you accept Chrome's optional all-sites prompt, the grant remains until you remove it and Telepathy can start automatically on ordinary web pages and permitted embedded frames. Protected Chrome surfaces remain unavailable. Room data and page structure are sent to the service only for the active Telepathy flow described here.
- activeTab + tabs — identify the active watched tab, inject the player agent after a user action, read the active tab address needed for the room, and detect an invite payload when its page finishes loading.
- declarativeNetRequest + alarms — when you explicitly enable ad skipping, limit temporary controls to the current watch-party tab and remove them when no longer needed. Ad skipping is off by default.
6. Third-party services (sub-processors)
- Approximate geolocation (optional) — if the operator enables approximate-location protection, your IP is sent over HTTPS to IPWhois / ipwho.is to derive country/region/city, approximate coordinates and ISP for security display.
- AI player and ad detection (optional) — if local detection fails and the operator has configured AI assistance, Telepathy may send the watched-page URL and a limited technical representation of page structure to Groq. It excludes page text, scripts and form values, but may contain technical element attributes and resource URLs. Do not treat it as anonymous.
The production operator must document the processor locations, contractual safeguards and processor-side retention that apply to its actual accounts and hosting configuration. If an optional tunnel or another hosting/observability provider handles user traffic, that provider must be added here before use.
7. How we protect your data
Passwords are salted and hashed with an industry-standard algorithm — never stored in plain text. Sessions use random, expiring tokens. We rate-limit requests and validate input to reduce injection risk. The hosted Telepathy production service serves public browser connections over HTTPS; self-hosted operators must configure and maintain TLS for their own deployment. No method is 100% secure, but we apply reasonable, industry-standard safeguards.
8. Retention
Account records persist until deletion. Account sessions expire after 30 days. Durable activity/security records are pruned after 30 days by default; the configured period is bounded by the service. Approximate-location cache entries are also pruned after 30 days by default. Temporary bans expire at the operator-selected time; IP or account bans can otherwise remain until an operator removes them. Live room state, including recent chat bodies, member playback position and recent connection-latency samples, remains only while that room is active.
Telepathy retains bounded site-compatibility records containing a site hostname and limited technical player-detection data. These records are removed under a bounded retention policy. The random installation identifier is used temporarily for abuse prevention.
Database backups are retained for seven days by default and can therefore contain a record that was deleted from the live database until the applicable backup expires. A production operator may use a different documented schedule and must apply the same lifecycle to any encrypted off-site copies.
You can request account deletion through the contact below. Deletion removes the account, its sessions and associated identifiable records from the live service. Some active connections may take a short time to close.
9. International data transfers
Depending on where the operator hosts the service and where the third-party services above are located, your data may be processed in countries outside your own, including outside the EEA. Before production publication, the operator must identify those locations and establish and document any legally required transfer mechanism, such as Standard Contractual Clauses. This repository does not prove that those agreements are already in place.
10. Your rights
Subject to applicable law (including the GDPR), you have the right to:
- Access the personal data we hold about you, and obtain a copy (portability).
- Rectify inaccurate data and complete incomplete data.
- Erase your data (“right to be forgotten”) — request account and personal-data deletion through the contact below.
- Restrict or object to processing based on legitimate interests.
- Withdraw consent at any time, without affecting prior processing.
- Lodge a complaint with your local data protection / supervisory authority (in the EEA, your member-state authority).
- Use Telepathy as a guest — no account, no stored email — and clear local data any time by removing the extension.
To exercise any right, contact us (Section 14). We respond within the legally required time frame.
11. Children
Telepathy is not directed to children under 13 (or the minimum age in your jurisdiction) and we do not knowingly collect their data. If you believe a child has provided data, contact us and we will delete it.
12. Cookies & local storage
The Telepathy website does not load advertising or analytics tags and does not set third-party tracking cookies. The extension stores functional data in Chrome storage, including your display name, avatar, preferences, session token, random installation identifier and temporary watch-party state. Removing the extension clears extension-managed local data under Chrome's normal removal behavior.
13. Changes
We may update this policy; material changes will be reflected by the “Last updated” date above and, where appropriate, announced in the app.
14. Contact & data requests
Questions, complaints or data requests (access, deletion, etc.): privacy@telepathy.video.