Privacy Notice
Free public trial. Ages are self-declared, and moderation is occasional. Operator address and safety/privacy preparation remain incomplete; this trial is not a certification of legal compliance.
Updated 21 September 2026. This notice describes the current beta service, optional gender filters and credit payments when enabled. Outstanding operational and privacy work is still in progress.
Who is responsible
Dominic Shannon trading as Hello Stranger is the controller for the personal data used to operate this service. Business correspondence address: not supplied by the operator. Privacy requests: on-site support. Privacy email, including for people unable to sign in: anyaonly90@gmail.com. These contact details must be supplied before public launch.
Information used
Admins can see the total number of guest and account records to measure use of the service. This includes private-test accounts and does not count visitors who have never started a guest session or signed in.
The online counter uses the account identifier and a recent activity time for guest and signed-in visitors. Each identity counts once, even with several tabs open. The displayed total includes accounts active in the last 90 seconds and refreshes about every 30 seconds. Presence records expire from the count after 90 seconds and are deleted on the next counter request. No list of online accounts is published. Optional gender filters use your self-declared gender and the gender you choose to meet. These choices are stored in the temporary chat session for matching, not inferred from your camera. Prefer not to say is available. Choosing not to share a gender means you will not appear in gender-specific searches.
Sign-in supplies a site-specific account identifier and account email; optional name data may be available from the sign-in provider. The chat application stores the account identifier, temporary session identifiers, both participants’ account references on each room record, the terms version acknowledged and the time of acknowledgement. Your email and account identifier are not shown to your chat partner.
The application uses connection messages to establish live calls. These can include network and IP-address information. A payment-provider customer reference, credit transactions, invoice references, reports, suspension status and moderator access logs are stored where those features are used. The site does not store full card numbers.
Live video, audio and safety spot-checks
Your camera and microphone start only after you initiate chat and allow browser access. Media uses browser real-time communication through the configured Cloudflare TURN relay service. Authorised moderators may view and hear both participants during disclosed safety spot-checks or report investigations. The required acknowledgement before chat explains this access; no additional notification appears when a review begins. You can mute, pause your camera or stop the chat.
The safety table creates temporary camera snapshots in the moderator’s browser from a receive-only live video stream, refreshing about every eight seconds. These images are held in browser memory during the review, cleared when it stops or the page closes, and not saved to a server gallery. The snapshot table does not request audio; opening a live review can include audio. There is no video/audio recording, facial recognition or gender-detection feature. Participants may still use external recording tools against the rules. Relay-only connections are required in the application; Cloudflare TURN is configured, and the operator has tested video and audio on two devices. A relay provider receives network information and carries encrypted media traffic.
Text chat alongside calls
Typed messages travel between the two participants over the encrypted WebRTC connection, using the configured relay. The application does not upload or save conversation text in its database. Each browser displays up to the most recent 100 messages in memory and clears them when the conversation ends, you skip or the page closes. The other person can still copy or capture what you send, so do not share sensitive information.
Camera spot-checks and live reviews do not include text messages. Report & leave sends the description you enter, not an automatic copy of the conversation. Describe unwanted messages in your report; text that you choose to include is then held as part of that report under the report retention rules.
Purposes and lawful bases
The current purposes are to provide requested free chats, investigate safety concerns, handle support requests, apply restrictions and meet legal obligations. When enabled, one-off credit purchases use Stripe to process payment and maintain your credit balance. The operator must document an appropriate lawful basis for each purpose before public launch. Contract may apply where processing is necessary for a service you request. Safety monitoring may require a documented legitimate-interests assessment or another appropriate basis depending on the facts.
Acknowledge-monitoring boxes explain the design; they are not a claim that bundled consent automatically makes all monitoring lawful. A data protection impact assessment and assessment of unexpected sensitive content are required as launch work. No marketing or sale of webcam footage is part of this design.
Who can receive information
The current chat partner receives your live media, typed chat messages and connection data. Approved moderators receive live media only during a safety review. The hosting, sign-in, networking and payment providers process information needed for their services. Cloudflare TURN is the configured relay provider. Supplier and data-transfer review remains part of public-launch preparation.
The operator must identify actual contracted suppliers, relevant controller or processor roles, processing locations and any international-transfer safeguards before launch. Information may be disclosed where legally required, but the site does not automatically forward webcam footage to authorities.
Abuse prevention and blocks
Short-lived request counters limit repeated actions per account. Room account references remain with the room for up to 24 hours before traffic-driven cleanup, so leaving a chat does not immediately erase the account needed for a report. A submitted report retains its subject account reference under the report retention rules below. Reporting stores a block between the two account identifiers to prevent rematching. These blocks remain until reviewed or removed through account/privacy support; a final retention and rights-handling process is still required. Counters expire from enforcement after their short window and are deleted on subsequent cleanup.
Support requests
The support inbox stores your account identifier, chosen category, subject, messages, status and timestamps. Authorised support staff can read and reply. Safety-category requests are listed first; no AI model classifies messages or makes decisions. Automatic receipts only confirm storage. The site does not send support email alerts. Resolved requests and their messages are deleted on cleanup after 90 days without an update; unresolved requests remain pending human review. Avoid sending unnecessary sensitive information, identity documents or images. You can request access, correction or deletion through this inbox, subject to applicable rights and any lawful retention needs. This is a human-handled request process, not automatic account deletion.
Retention
Temporary sessions expire after 90 seconds without activity and are deleted on the next cleanup. Connection rooms and their technical signalling messages are removed after 24 hours on cleanup. Cleanup currently runs on joins, account refreshes and admin reads, not on a guaranteed timer; information can therefore remain longer while the service is idle.
A review’s connection messages are cleared when it ends or is cleaned up after expiry. Review metadata and action logs are retained for up to 90 days before cleanup. Resolved reports are eligible for deletion after 90 days; unresolved reports currently require operator review. Account and credit records currently have no automatic deletion schedule. The operator must define lawful and proportionate retention for them, implement an operational deletion process, and assess legal holds before launch.
Your choices and rights
You can stop transmitting at any time, leave a conversation and report a concern. Depending on the circumstances, data-protection rights include access, correction, erasure, restriction, portability and objection. These rights have legal conditions and exceptions, including where records must be kept for legal obligations.
Guest and signed-in users may submit rights requests through the support inbox. If you cannot sign in, email anyaonly90@gmail.com. We will explain any further identity checks needed to handle your request. You can complain to the UK Information Commissioner’s Office. The site does not currently provide a completed self-service account deletion workflow.
Minimum age and age checks
Hello Stranger is only for people aged 18 and over. If we learn that a user is under 18, we will restrict access and handle their information in accordance with applicable law, keeping only what is necessary for safety, legal obligations or resolving the concern. A tick box is a declaration, not verified age.
Separate age verification is currently switched off. The site does not send new age-check requests to Yoti in this mode or mark declarations as verified ages. The following describes the retained integration for possible future use. When enabled, Yoti receives the information you submit directly for a verified digital ID or identity-document and live-selfie check, plus technical information needed to operate its service. Hello Stranger sends a random check reference rather than your account email. This integration receives the result and check metadata, not your identity images or date of birth. The app stores your account identifier, random reference, provider session identifier, result status and timestamps. Successful checks are valid for 30 days; failed attempts restrict retries for 24 hours. Expired records are eligible for deletion 24 hours after expiry on the next cleanup, so they may remain longer while the service is idle. Provider results and raw response bodies are not stored in application logs or databases. Yoti’s own processing and retention are explained in its age-verification privacy notice. No promise about supplier deletion overrides its applicable terms. The operator must complete supplier contracting, lawful-basis and biometric-data assessments, transfer safeguards, accessibility and appeals arrangements before enabling live checks. This integration does not perform facial age estimation. Whether children are likely to access this service, and the resulting protections and application of the ICO Children’s Code, must be assessed before launch.
Cookies and browser storage
Starting guest chat sets a necessary first-party cookie named __Host-hello_guest for up to 30 days. It holds a random secret; the database stores its hash, a separate guest identifier and expiry time. The cookie is Secure, HttpOnly and SameSite=Lax. It identifies your browser for chat, blocks, suspensions, reports and support. The guest token record is removed on cleanup after expiry; associated safety and account records follow the retention rules above. Clearing this cookie loses guest access to previous support requests and allows a new guest identity. Where the hosting service supplies a client network address, guest creation uses a daily-hashed version in short-lived anti-abuse counters, which become eligible for deletion after an hour. The raw address is not stored by that counter.
The chat application does not currently add advertising or analytics tracking. Sign-in, hosting and any payment checkout may use cookies or similar technology for their own functions. A complete deployed cookie inventory, including supplier names, purposes and lifetimes, must be verified before launch. Optional tracking must not be introduced without the required notice and any legally required consent. Browser camera permission is separate from cookie choices and agreement to the terms.
Security and limits
Admin access is checked on the server against an explicit allowlist. Moderator review and enforcement actions are logged. Credit grants require server-side payment verification with Stripe. Checkout uses your account email, site-specific account reference and payment-provider customer reference. Payment and refund references and credit transactions are retained with your account; full card details are handled by Stripe. Purchase availability is shown on the Credits page.
These controls do not amount to a security certification. Rate limits, abuse resistance, account recovery, independent security testing, age assurance, reliable video relaying and an incident-response process still require launch review. No claim of guaranteed safety, anonymity or continuous monitoring is made.