Privacy Policy
Last updated: 2026-09-01
1) What this product does
WeHuddle (including the “Huddle Watch Party” browser extension) helps users watch content together by synchronizing playback (e.g., play/pause/seek) and enabling room-based chat. The extension works on Netflix, and on Prime Video only if you explicitly enable it — Prime access is an optional permission that is requested when you turn it on, never at install.
2) Data we collect and process
When you use the service, we may process:
- Room information (e.g., the Room ID you enter).
- Playback sync events (e.g., play, pause, seek actions and timestamps).
- Page URL (e.g., a Netflix or Prime Video watch URL) to keep participants synchronized on the same title.
- Chat messages you send in a room.
- Account details if you choose to register: a username and password. Accounts are optional — rooms work without one. Passwords are never stored in plaintext; we store only a salted, hashed value (scrypt) used to verify your login.
- Saved rooms that you bookmark while logged in. These are stored on our servers and tied to your account.
- Content fingerprint on Prime Video only. Prime’s page address can keep pointing at the previous episode after you move to the next one, so the extension also sends a short label for what is actually playing: the season and episode number, plus a 32-bit FNV-1a fingerprint of the series name. We do not send the series name itself. To be precise rather than reassuring: that fingerprint is a fast, non-cryptographic checksum, not an anonymisation measure — someone holding it could test a list of candidate titles against it. It exists so a room can tell whether everyone is on the same episode, and it is stored with the room’s playback state.
- Sync quality measurements — counts of events such as how often playback drifted or a command failed. These are cumulative counters tied to a random session identifier, with no room, user, title or URL attached, and they are deleted after 30 days. They tell us whether syncing works on a given service; they are never used for product, account or billing decisions.
- Voice/video and screen-share connection data. Optional calls and screen sharing use peer-to-peer WebRTC. The server only relays the connection-setup signaling needed to start a call (offers/answers and ICE candidates) — it does not relay or record the audio/video itself. Setting up a direct peer-to-peer connection reveals participants’ IP addresses to one another; this is standard WebRTC behavior.
- Technical data such as IP address and basic connection metadata for security, abuse prevention, and service reliability.
- Aggregate usage and performance analytics via Vercel Web Analytics and Speed Insights (e.g., page views, referrers, and anonymized page-performance metrics). This is privacy-friendly: it uses no cookies, does not track you across other sites, and does not build an advertising profile.
We do not collect your streaming service credentials (for example your Netflix or Prime Video username and password) or payment information.
3) How we use data
We use data only to:
- Synchronize playback for room participants
- Deliver and display chat messages
- Enable optional peer-to-peer voice/video calls and screen share
- Create and authenticate your account, keep you signed in, and store the rooms you save (only if you choose to register)
- Operate, secure, and improve reliability (e.g., preventing abuse, diagnosing outages)
- Understand aggregate, anonymized usage (e.g., which pages are visited) to improve the product
We do not use your data for advertising, and we do not sell it. We use no advertising SDKs and run no third-party tracking cookies.
4) Data storage and retention
- Chat messages and room activity may be stored on our servers to support features like chat history.
- If you register, your account (username and hashed password) and your saved rooms are stored on our servers for as long as your account exists.
- Recent room history is stored only in your browser’s localStorage on your own device — it stays client-side and is not sent to our servers. You can clear it by clearing your browser storage.
- In some cases (e.g., during outages), data may be handled temporarily and could be lost on server restart.
- Sync quality measurements are deleted 30 days after they are recorded.
- We retain data only as long as necessary to provide the service and for legitimate operational needs.
5) Cookies
When you log in, we set a single first-party, HttpOnly session cookie so we can keep you signed in. It is not readable by client-side JavaScript and is used only for authentication.
We do not use third-party or advertising tracking cookies. Our analytics (Vercel Web Analytics and Speed Insights) are cookie-free.
6) Data sharing
We do not sell user data. We do not share user data with third parties except:
- service providers required to operate our infrastructure (hosting, databases, monitoring), under appropriate protections;
- a third-party STUN server (currently Google's public STUN server) contacted only during voice/video call setup to discover your network address — a standard step in establishing a peer-to-peer WebRTC connection; or
- when required by law.
7) User controls
- You can stop data processing by disconnecting or uninstalling the extension.
- Room IDs are user-provided; using a different Room ID creates a separate session.
- You can use the service without an account. If you registered, logging out ends your session, and you can add or remove saved rooms at any time.
- Recent room history lives in your browser; clearing your browser storage removes it.
8) Security
We use reasonable technical measures to protect data in transit and at rest. No method of transmission or storage is 100% secure.
9) Children’s privacy
This service is not intended for children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children.
10) Contact
Questions or requests about this Privacy Policy can be sent to:
- Website: https://wehuddle.tv/
- Email: support@wehuddle.tv