Sidewalk Privacy Policy
Effective September 24, 2026 · Version 2
Sidewalk is a website and browser extension for public conversations in Global, website and page rooms. This policy explains the data used by those features.
What we collect and why
- Chat identity: an anonymous authentication account, profile number and session tokens keep messages, blocks, reports and age agreements tied to your profile rather than your changing alias. This is a pseudonymous account, not a guarantee of anonymity. No email or password is needed for ordinary chat.
- Conversations: messages, aliases, timestamps, room identifiers, replies, reports, blocks and short-lived presence support chat, counts, live website rankings and moderation. Public messages can be read or copied by room participants. Moderators can review messages and reports.
- Website and page information: while the extension is open, it reads the active tab address and title to choose a website room and offer a page room. Website room names go to our service. Selecting a page room sends the domain and a hash identifying that page; hashes are not a promise that a public page cannot be guessed. The extension does not scrape page contents, form fields, passwords or your browser history.
- Optional page sharing: off by default. When enabled, sending a message attaches the previewed website, page title and sanitized path so others can open the page. Sharing supports public websites classified as non-adult, except disabled rooms. These destinations are not guaranteed free of harmful content. Most query parameters and recognized private paths are omitted; YouTube video IDs are retained. Adult-site sharing is disabled. These filters are imperfect: review the preview before sending. Turning sharing off does not remove information already sent.
- Service analytics: moderators see aggregate chat counts and website activity calculated from chat records needed to run the service. We do not collect individual browsing histories for analytics. Optional extension measurements are off until selected in Settings. They count opens by day, display mode and version, without websites, URLs, titles, message text or profile identifiers in events. Moderators see aggregate counts. A separate daily profile quota protects this endpoint against abuse. Events older than 90 days and quota entries older than the current UTC day are removed on the next measurement or analytics read. Turning the setting off stops future events; unlinked counts cannot be identified for individual deletion. Previously collected opening histories and profile opening totals have been deleted from the active database.
- Bug reports: your description, profile, app version and view mode go privately to moderators. Do not include passwords or confidential information.
- Local preferences: your aliases, themes, agreements, points, streak, sharing choices and session are stored on your device. Clearing storage can lose access to your chat identity.
Service providers and access
Supabase hosts authentication, chat data and backend processing. Vercel hosts the website and downloads. Cloudflare Turnstile checks new chat connections and moderator sign-in attempts for bots. Cloudflare receives connection and browser signals needed for that security check; Sidewalk sends the resulting single-use verification token to Supabase Auth. Chat messages, room names and browsing history are not included in that verification request. See Cloudflare’s privacy policy. Hosting providers receive connection information such as IP addresses and request metadata needed to deliver and protect their services; their own operational logging and retention apply. Authorized Sidewalk moderators access data for moderation, support and the usage dashboard. Other chat participants see your public messages and any attached page context. Sidewalk does not sell personal information or use it for advertising.
Retention and controls
Chat messages and moderation records are retained until removed by the operator; automatic chat-retention cleanup is not implemented in this beta. Presence counts expire after 45 seconds of inactivity. Moderator removal hides messages from chat; it does not physically delete moderation records. Contact us to request access, correction or deletion. We verify requests without asking for passwords or session tokens. We may retain records needed for abuse prevention or legal obligations and explain any exception. Provider backups may retain copies until they expire under the provider’s retention settings. Page sharing is a separate setting. Closing Sidewalk stops active chat polling. Uninstalling removes extension storage, not server records or copies others made.
Automated message checks
Before saving new messages, the server checks for pasted links, selected explicit hate/threat patterns, repeated messages and flooding. Rejected messages are not saved as chat messages by these checks. Matching is imperfect and may reject legitimate discussion or miss harmful content. Report problems through the message actions or bug-report form.
Age and safety
Users must be at least 13. Adult-site rooms are unavailable. Adult websites are excluded from discovery and page sharing. We do not collect birthdates or identity documents to verify age. Classification and profanity filters can make mistakes. Report unsafe content using the visible Report action.
Limited Use and security
Sidewalk uses browser-derived information only to provide and improve the described chat features. Its use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is transmitted over HTTPS. Access checks restrict moderator tools, but no service can guarantee absolute security.
Contact and changes
Contact the Sidewalk operator at admin@sidewalk.chat for support, access, correction, deletion, privacy requests or appeals. Email works even if you are banned or have lost your chat session. Include your profile number if available, but never send passwords or session tokens. We may need information to confirm control of a profile. Material changes to data practices will be disclosed in the product before the changed collection begins.