OddHello
Back to chat
Terms of ServicePrivacy NoticeCommunity GuidelinesSafetyPrivacy explainedAbout
Effective September 23, 2026

Privacy Notice

OddHello is designed to minimize collection. There are no accounts, advertising IDs, third-party analytics trackers, marketing pixels, or third-party tracking scripts. Optional first-party usage statistics are explained below.

Who operates OddHello

CritHit Studio operates OddHello. Joé Weis is the Owner and Founder of CritHit Studio. In this notice, "we" means CritHit Studio as the service operator.

What the service processes

  • A signed anonymous session cookie and server-side session state, retained for at most 24 hours from creation. Using the session does not extend that lifetime.
  • A keyed one-way hash derived from the connection IP for rate limits and bans. The application does not store the raw IP.
  • Up to 50 recent chat messages per room, while active and for 30 minutes after the room ends.
  • Operational queue, room, rate-limit, and ban records, plus moderation-audit records retained for at most 30 days and 1,000 entries.
  • Community Hot Take submissions, moderation status, public aggregate vote totals, and a 24-hour anonymous-session vote marker.
  • Invitation links you create: a random code and the issuing session identifier, kept for 24 hours, plus a marker on the invited session so a link cannot be claimed twice or by its creator.
  • Aggregate service totals and, only when you opt in, browser usage statistics, both described under Product statistics and your choice.

Video and audio

Calls use encrypted WebRTC peer-to-peer connections between participants. If a direct connection fails, coturn relays encrypted media packets without decrypting the media stream. WebRTC and the relay necessarily process network addresses, and a peer-to-peer connection may reveal network information to the other participant. OddHello does not record calls.

Live safety checks

Incoming video classification runs continuously in your browser using a self-hosted model and worker. Unsent drafts and unreported video samples remain on your device. The last two compressed remote video frames stay in browser memory and leave your device only when you explicitly submit a safety report for moderation review.

Sent chat messages are relayed immediately, then checked asynchronously by the OddHello server through Cloudflare Workers AI. A check includes the candidate message and a bounded context containing only earlier messages the model marked safe, labeled with pseudonymous speakers A and B. Until a verdict arrives, the recipient's client covers the message.

Reports and retention

A submitted report contains its reason, attached video evidence frames, the server's recent room chat transcript, and keyed hashes for the reporter and reported connection. Reports expire after seven days, except where a moderator places a report on hold because it is subject to a legal, safety, or law-enforcement process; a held report is kept until that process ends and the hold is released. Ban-level metadata may remain through the ban and a 30-day clean-period decay window. Encrypted recovery backups are retained for no more than seven days. Unreported video samples never reach the server.

Community Hot Takes

A community Hot Take submission contains the question and its two answer choices. It remains private while awaiting moderator review and expires after 30 days if still pending or rejected. If approved, it becomes public with aggregate vote totals and stays available until a moderator removes it. A per-session vote marker expires after 24 hours and prevents duplicate counting; it is not connected to an account or real-world identity.

Product statistics and your choice

Help us understand whether people reach a conversation. What is counted?

We keep aggregate counts of service operations, including anonymous sessions created, queue entries, matches, connections, ended conversation durations, skips, reports and connection failures. These totals contain no chat messages, media, interests, network addresses or user profiles.

Optional browser statistics are off until you choose to share them. They count visits to known pages, Start, chat mode selection, whether interests were entered, safety warnings and Hot Take interactions. A random visit token stays in browser memory for at most 30 minutes; the server uses it for temporary deduplication and attribution to an existing chat session. It is not an account or a returning-user identifier. We honor Do Not Track and Global Privacy Control. Your browser stores only a yes/no preference for this choice.

For consenting visits, we record a broad acquisition category such as search, social, referral or unknown, and the known landing page. Full referrers, URL parameters, referral codes, detailed browser information and individual votes are not included in analytics. Daily counters and duration histograms expire from the live service after 30 days by default, and never more than 90 days. Encrypted recovery copies can remain for up to seven additional days. The temporary visit and attribution records expire after 30 minutes without renewal. Turning the preference off requests deletion of the current attribution. A temporary revocation marker prevents delayed requests from restoring that visit until its original expiry; previously combined totals cannot identify or be separated back into your visit.

Referrals use random links that expire after 24 hours and existing short-lived safety sessions to limit self-referrals and duplicate claims. They create no public referrer profile, rewards, tracking across sites or matchmaking advantage. Public Hot Take results show aggregate votes only. The referral and vote limits do not establish that each session is a different person.

Browser statistics are based on your optional consent. They are not required to chat. Aggregate service totals help us operate and improve reliable conversations. We do not attempt to identify returning users or add identity information to make these statistics more complete.

AI-assisted moderation

When enabled, sent chat messages, the reported participant's transcript messages, and deliberately attached report frames are sent by the OddHello server to Cloudflare Workers AI for safety classification. Model requests omit report, room, session, and keyed IP-hash identifiers, disable AI Gateway request logging and caching, and are not made directly by your browser. Community Hot Take questions and both answer choices are sent for the same kind of pre-screening, without session or submitter identifiers.

Live-chat verdicts are stored only with the short-lived room transcript. Report categories, policy score, and action are retained with the report for the same seven-day period. In shadow mode, report findings are shown to human moderators but take no automatic action; unsafe live messages can still be covered in the conversation. If the operator later enables enforcement after documented accuracy and appeal checks, only narrowly defined unsafe text report findings can cause a 15-minute provisional suspension; permanent bans remain human decisions. You may contest a restriction using the appeal link on the restriction screen.

Purposes and legal grounds

Session, room, chat, and connection data is processed to provide the service you request under the Terms. Rate limits, safety screening, reports, bans, and audit records support our legitimate interests in preventing abuse and operating a secure service, balanced against the limited and pseudonymous data involved. Evidence may be preserved or disclosed where necessary to meet a legal obligation. Where consent is the applicable ground, you may withdraw it without affecting earlier lawful processing.

Processors and international transfers

Data is disclosed only to authorized moderators, infrastructure processors needed to operate OddHello, Cloudflare when its relay or Workers AI services are used, or authorities when legally required. A processor may handle data outside Luxembourg or the European Economic Area. The operator maintains an appropriate data-processing agreement and, where required, an adequacy decision or contractual transfer safeguards.

Your privacy rights

Depending on the circumstances, you may request access, correction, erasure, restriction, objection, or portability of personal data, and may contest an automated decision. Because OddHello has no accounts and does not know your identity, we may be unable to locate a session after its cookie or short-lived records expire, and we will not collect extra identity data merely to satisfy a request. Send requests or questions to [email protected]. You may also complain to Luxembourg's data protection authority, the CNPD.

AboutSafetyPrivacy explainedTermsPrivacyCommunity Guidelines Send feedback
OddHello by CritHit Studio. Joé Weis, Owner and Founder.