Your privacy.

Private alpha notice · September 2026. Contact about access, corrections, deletion or account closure.

The short version

One-to-one Dialogues are live voice with text alongside if you want it. When either of you chose Type they are typed instead. Dialogue records a Dialogue only when everyone speaking says yes on their own screen, and writes one down only once they all keep it. Anyone in the Dialogue could still record with their own equipment, which our rules do not allow. The person you talk with sees the first name you chose and what you are meeting on. If you both let people listen, listeners hear you live and see your first names and where you each stand. What you save is encrypted. Messages to people you keep talking with are encrypted between your devices and Dialogue cannot read them. You can export or delete what we hold at any time from You.

Your account and what we hold

We store your account email, a salted hash of your password, your sign-in sessions, the first name you chose and the code after it, the names you went by before, the terms and promises you accepted, your answers to the questions and the scores worked out from them, your answers to statements, the lines you write for stories and decisions, the decisions you mark as made, the subject suggestions you write, the subjects you save for later, the kinds of Dialogue you stay in, your private feedback after Dialogues, your badges and milestones, your preferences and service records. Passwords and sign-in tokens are stored only as hashes.

Your name has a short code of four letters and numbers after it in People, invitations and your page, so people with the same name can be told apart. It is never shown in a Dialogue. You can change your name once at any time and after that once every 30 days. A name cannot hold slurs, threats, explicit terms or swearing. We keep the names you went by before for 180 days for our staff reviewing a report. They go with Delete my data.

What you save is encrypted with keys managed separately from the database, so you do not need a key of your own. Dialogue can decrypt it to run your account, pairing and safety review, so this part of the service is not end-to-end encrypted. Account identifiers, email addresses, statuses, timestamps and counts remain searchable service records, protected by access controls and encrypted storage.

The questions and How you talk

Before your first one-to-one Dialogue you answer ten short questions, about ninety seconds. After it you can answer the full set, one question at a time. We note how long each answer takes and check two answers against each other, only to learn which answers are usable. These notes never stop anyone taking part and are deleted after a year.

Your answers work out How you talk: three leans and, once the whole set is done, one of eight personas. After a few Dialogues, what actually happens counts too: whether you changed your answer after talking with someone who saw it differently, whether partners say they felt heard and whether you take a listening or speaking seat in group Dialogues. Your answers keep most of the weight. It is private unless you choose to show it. It never affects who you are introduced to and it never ranks anyone. How quickly heat rises for you is only ever shown to you. You can separately choose to help the research, which shares de-identified scores and after-call ratings in aggregate, never your name, email, answers to statements or messages. That choice is off until you turn it on. How you talk describes general tendencies from what you said about yourself. It is not a measure of mood or health.

On the questions page anyone can answer without an account. Those answers stay in that browser until the person keeps them in an account or forgets them. Nothing about them reaches Dialogue before then.

How introductions are chosen

Pairing uses a few short questions and how you like to talk. That means the ten short questions and the starter part where you have it, four parts of the full set once you and the other person have both done them (Thinking things through, Speaking up, Weighing things up and Taking advice), your language and, once you have saved them under You, your pace and what draws you in and, for a statement, your answer. Someone who sees it differently answered it another way. Someone who sees it the same way gave the same answer. Feeling things strongly, staying patient and noticing feelings are never used. Neither are How you talk, your persona or your badges. When you start a Dialogue from one you listened to, we look first for someone who heard it too. The approach is experimental and has not been shown to predict good conversations. A smaller daily allowance applies during your first few one-to-one Dialogues.

What the person you talk with sees

They see the first name you chose and what you are meeting on: for a statement, both answers; for a story, a decision or a friend of a friend story, the line each of you wrote; in Been there, that you both know the subject and which of you is living it now. They may see a short reason for the introduction, such as that you both heard the same Dialogue. Your email, your answers to the questions, How you talk and your notes are never shared with them.

What you talk about

Most one-to-one Dialogues start from a statement: the monthly statement or one of the statements on Talk. You answer Agree, Not sure or Disagree before searching and can say where you stand afterwards. These answers are stored encrypted, are used to introduce you to someone suitable and are deleted after 12 months or when you delete your data. Whether an answer changed after a Dialogue is kept without the answer itself. After seven days nothing links it to that Dialogue or to the person you talked with. Community splits are anonymous counts and appear only once enough people have answered.

For a story, a decision or a friend of a friend story, the one line you write names the Dialogue. The person you meet sees it, and so do listeners if you both let people listen. A one-to-one Dialogue you list on Talk shows its line to other members, never your name, until someone picks it or you stop, for up to 15 minutes. The category it is filed under goes with it. Lines are checked for slurs, threats, links and contact details. A decision you mark as made is kept so that someone deciding the same thing can meet you later, until you unmark it or delete your data. A subject suggestion is one short line read only by the administrators who choose subjects. It is never shown with your name and is deleted after 90 days.

Been there

Been there is a separate, quieter space for talking about hard things with someone who knows the subject first-hand. It is a Dialogue between two members. It is not support, counselling or a crisis service. It is never open to listeners. It opens after a few introduced Dialogues. You choose a subject and whether you are living it now or have been through it. Those two choices are stored encrypted with your search and cleared with it. Your partner learns only that you both know the subject and which of you is living it now. Nothing you choose there is used for pairing elsewhere or shown anywhere else. The support services are shown before you start and after each Dialogue.

Your Dialogues

Voice is encrypted between the browsers using WebRTC. A privacy relay carries that encrypted audio and prevents a direct connection from showing your network address to the other person. Unless a Dialogue is on the record, Dialogue does not record audio or create transcripts. Nothing on our servers listens to a live call or analyses what is said. The speaking indicator and the private talk-time nudge are worked out on your own device from audio levels. Nothing about them is stored or sent to Dialogue, except the turn-taking numbers described below while you let people listen. Either person can mute, leave, block or report a concern. Another participant can still record with separate software or equipment. Our agreement prohibits recording without permission.

Letting people listen

Letting people listen is something you and the other person both turn on inside the Dialogue, after a few introduced Dialogues each. Either of you can close it at any time and everyone listening leaves at once. We keep a record of when it opened and closed for thirty days. Listeners hear both voices live, either through the privacy relay or through our media server, which passes the audio on to them and never records it. Your call with the other person stays encrypted between your two browsers as usual. Listeners see your first names, the statement or title, the format, where you each stand and where you are in the guide. They do not see your network address or anything else about you. You never see who is listening, only roughly how many. While it is open, your devices send how the two of you take turns, as numbers only, so we can suggest good Dialogues to listeners. Those numbers are deleted when the Dialogue ends.

Members can listen, and so can visitors without an account once they confirm they are 18 or over. A visitor is remembered by a random identifier in a cookie and is forgotten after 30 days without a visit. The first seconds in a Dialogue are a preview: it holds a seat for a moment but is not counted and never joins the record of who listened. After that, we keep a record of who listened to which Dialogue and when. It is kept for seven days so a report can be looked into and, if you start a Dialogue from one you heard, to find someone who heard it too. Listeners can say where they stand before and after. Listening and answers from visitors are limited per network, each hour and in each Dialogue, using a digest that cannot be turned back into an address. Those answers are kept without names and only for the Dialogue’s totals. They are deleted within a day.

When listeners’ questions are switched on and your 25 minutes are up, you can stay five more minutes for them or finish. Each member listening can send one short question. You see the question without the listener’s name and can answer it, pass or report it. Other listeners see a question only while you answer it. Reporting a question sends it to the administrators with the words the listener wrote and the account behind it. That listener stops listening to your Dialogue and cannot come back to it, and the report is kept under the safety-report retention rules below. Questions are stored encrypted and deleted when the Dialogue ends. A listener can also report either speaker. That report goes to the administrators and never pauses anyone by itself.

Afterwards each of you can write a few sentences and say yes to a Dialogue card: the statement or title, both first names and where you stood, how long you talked, how many listened and how the listeners’ answers moved. A card is published only when both of you say yes. Either of you can withdraw it later, and blocking the other person takes it down for good. An administrator can take a card down if it breaks our rules, and a suspended member’s cards come down with their account. A card nobody published is deleted after 30 days. Letting people listen never records a Dialogue, but a listener could record what they hear against our rules, so leave it closed for anything you would not say in public.

Dialogues for you

Listen and Talk bring Dialogues like the ones you stay in a little earlier. When you spend a minute or more in a Dialogue we add to the kinds of Dialogue you choose: its category, whether it is a one-to-one or a group Dialogue, its format and whether it is spoken or typed. Joining, chatting, asking, voting, raising a hand, following and sharing there add a little more. Looking through one kind of conversation on Listen for a while, such as Q&A or Stories, adds a little to that format on your own profile only. We never count Dialogues about health, identity, relationships or life experiences. Nor do we count a statement marked sensitive. These kinds are stored encrypted with your account, halve in weight every two weeks and are forgotten after 60 days without a visit. On Listen they move a Dialogue a few places at most. In the Directory we also add to each topic you open, follow, start, post in or ask in. Picking a Dialogue in it, voting there and listening to its Dialogues add a little too. A topic is held here by a coded form of its name, so one started again later finds its place. On Talk, the topics and questions that suit you come a little earlier, along with topics followed by people who follow what you follow. We never say who those people are. Nobody else sees any of this and it is never used for introductions.

Dialogues also rank on how much their people take part: the share of members there who chatted, asked, voted, raised a hand, followed, shared or came back. How long they stay counts too. It is never how many are in a Dialogue, and there are no likes. For this we keep which live Dialogues you were in, how long you stayed and what you did there, without any words, for a day after you were last there. A preview is never counted. You can see what Dialogues for you holds, forget it or turn it off under You. Forgetting clears the kinds and the day’s record of your Dialogues. Turning it off clears both and keeps them off.

What stays on your device

Dialogues on Listen are ordered by how they are going. On your own device, and only there, a tally of the subjects you listen to for a minute or more moves similar Dialogues a little earlier. Sensitive subjects never count and the tally fades over a few weeks. A member turns it off or forgets it with Dialogues for you under You, and a visitor on Listen. Nothing about it is sent to Dialogue. A visitor’s saved subjects also stay on their device until they sign in and choose to keep them. A member’s saved subjects are stored encrypted in their account for 30 days.

After a Dialogue

We may ask three short private questions about how it went. Your answers are stored encrypted and are never shown to the other person. Whether people would talk with someone again is used only in aggregate to order future introductions. Whether partners felt heard counts, added up across Dialogues, towards their How you talk. Who an answer is about is kept as a code that cannot be traced back to anyone without our key. After seven days nothing links your answers to the Dialogue. These answers are deleted after 180 days or when you delete your data.

Keeping in touch

After a one-to-one Dialogue each person can privately choose to keep talking. A choice made by only one person is never revealed and expires, by default after 24 hours. When both choose it you appear in each other’s People list by first name and can exchange messages or invite each other to talk again.

Messages are end-to-end encrypted. Your browser creates a key pair, keeps the private half on your device and shares only the public half. Signing out removes that key from the browser and from your account. Dialogue stores encrypted text that it cannot read and cannot recover for you. Signing out, clearing your browser’s storage or changing device makes earlier messages unreadable there. Messages expire, by default after 30 days. We keep the fact of the connection, message timing and unread counts so the service can work. Either person can remove the connection, which deletes the messages for both. When someone ends a connection with you, in any way, you can still report or block them from People for seven days. People shows only that the connection ended. We keep a record of it with its date for those seven days, even if they delete their data. A report made from People contains only what you write in it. A recipient can always copy what they can see.

Two people who follow each other are mutuals too. Each sees the other under Mutuals in People, so each knows the other follows them. Either can invite the other to a Dialogue. Following each other never allows a message or a call. If you start a Dialogue you can invite your mutuals. A one-to-one you start for a mutual stays off Talk and only the people you invite can pick it. Each is told once in the app that you invited them and to which Dialogue. You can also share a link, which anyone can open once they sign in or ask to join. We keep only who invited whom, to which Dialogue and when. No words. An invitation goes when its Dialogue ends or after one day, and with Delete my data.

Typed Dialogues

When Dialogue offers Talk or Type, each person starting a one-to-one Dialogue can choose to type. A one-to-one Dialogue is spoken only when both of you chose Talk. A typed one uses the live text described below and no microphone. We store which of you chose Type with the introduction, and whether the Dialogue started typed, so it is never opened to listeners. Either of you can suggest talking out loud and it becomes spoken only when the other says yes.

Live text chat

In a one-to-one Dialogue, and in a group Dialogue without a floor, session messages travel encrypted between participants’ browsers through the private relay. Message text is held in browser memory and is not saved to your account or our database. Closing chat, leaving or refreshing clears that local history. There is no automatic replay for people who join later. A recipient can still copy or capture what they see.

We process temporary message identifiers, participant permissions, timing and moderation records to deliver messages and control abuse. These records do not contain the text. Hosts and assigned moderators may pause group chat, set slow mode, restrict typing separately from speaking and remove a message from the interface. A removed message may already have been read or copied.

Only when you report from the chat and confirm is any of it sent to Dialogue: the last few lines other people wrote, which you see before you confirm. They are stored encrypted with the report and are visible to authorized administrators. We treat it as participant-submitted material, not independently verified evidence. The safety-report retention rules below apply.

The chat under a one-to-one Dialogue

While people listen to a one-to-one Dialogue there is a chat under it. The two people talking and members listening can write short lines that everyone who can hear the Dialogue reads, members and visitors aged 18 or over, so unlike live text our servers read it. Your first name shows next to what you write. Listening and reading without writing shows nothing about you to anyone.

Each line is checked against the short list below when you send it, stored encrypted and deleted when the Dialogue closes to listeners or ends. Only the latest 200 lines are kept while it runs. You can take your own line away and the two people talking can take any line away. When one of them reports a line, the words go into the safety report, its writer stops listening to that Dialogue and the retention rules below apply. Deleting your data removes what you wrote in any chat that is still open. A reader can always copy what they see.

The floor of a Dialogue

Public group Dialogues have a floor: a chat, questions that others vote up and hands raised to speak out loud. The floor is written for everyone who can listen to the Dialogue, members and visitors aged 18 or over, so unlike live text our servers read it. Your name shows next to what you write and a raised hand shows your name to the host. Listening and reading without writing shows nothing about you to the people in the Dialogue.

What you write is checked against the short list below when you send it, stored encrypted while the Dialogue runs and deleted when the Dialogue ends. A Dialogue keeps only its latest 300 chat messages while it runs. Votes, raised hands, a host’s pause on someone’s messages and the votes to open a Dialogue’s stage go at the same time. Hosts and moderators can hold questions until they approve them, slow or pause the chat, remove anything and pause someone’s messages. When a host or moderator reports something written on the floor, those words go into the safety report and the retention rules below apply. Deleting your data removes what you wrote on any floor, your votes and your raised hands. A reader can always copy what they see.

Feedback Dialogues

A group Dialogue that starts with “Pitch:” or “New material:” is a Feedback Dialogue. The presenter shows something they made and asks one question. Members listening can answer it once after the pitch and again at the end. They can also suggest what they would change. When you answer we keep only that you answered, under a code made from your account with a key held apart from the database, so the code cannot be turned back into you. Your answer is added to the totals and never stored on its own. The record that you answered is deleted when the Dialogue ends.

Suggestions are checked and stored encrypted like floor text and show your first name while the Dialogue runs. When it ends the ten voted highest stay on the presenter’s feedback card without names, and the rest and every vote on them are deleted. Taps on Ha during new material are counted in five second steps with nothing about who tapped. The presenter can show up to four photos. Your phone shrinks each one and saves it again before sending it, which leaves out where it was taken and the camera’s details. We check that what arrives is a photo. Photos are stored encrypted with a key for each photo, and deleting that key makes the photo unreadable before the file itself is removed. Dialogue’s staff see a public Feedback Dialogue’s photos before anyone else. A reported photo is hidden from everyone but staff until they look again. Photos are deleted when the Dialogue ends.

Adding photos opens after a member’s first few Dialogues. When a screening service is switched on, each photo goes to it before anyone else sees it, to check for explicit images. It receives the cleaned photo and nothing else: no name, account or Dialogue. Anything it flags, and anything it cannot check, waits for staff. A photo nobody has checked shows blurred until you tap it. Hide photos keeps every photo off your screen, and that choice stays in your browser. If staff take down a photo, its presenter cannot add photos for a while. We keep that pause, and only the date it ends, until it runs out, even if the presenter deletes their data, as we keep a block.

A private Feedback Dialogue is not listed. Its link carries a random code we keep only as a keyed digest, and making a new link closes the old one. The presenter’s feedback card shows the question, both sets of totals, how far the room moved, the top suggestions, where people laughed and how many listened. Only the presenter sees it, and it is deleted when they delete it or after a year at most. Deleting your data removes your Feedback Dialogues with their cards and photos. It also removes the suggestions you wrote, your votes and the records that you answered.

Scenarios

Scenarios on Talk are a Courtroom, Switch sides, a Mock interview, a Pitch and a Toast. A Pitch and a Toast are Feedback Dialogues and are kept as described above.

A Courtroom is a group Dialogue about a made-up case. Its host is the Judge, two members take the lawyers’ seats and members who raise a hand can be called to play a witness. Each seat is sent only its own papers. We keep who sits in each lawyer’s seat with the trial and remove it a week after the trial ends. Who plays a witness is kept only while the trial runs, and so is a code for each member who has sat as a lawyer or a witness, so nobody swaps sides or sits on the jury after taking part. Members listening are the jury. While the trial runs everyone in it sees how many jurors lean each way, never who. When you lean or give a verdict we keep only a code made from your account with a key held apart from the database, so the code cannot be turned back into you, with where you first leaned, where you lean now and your verdict, so a changed mind is counted once. The codes are deleted when the trial ends and are never in a recovery copy. The totals, the objections and their rulings and how many jurors changed their minds stay with the trial and go with the group’s record. A case a Judge writes is checked when it is sent, stored encrypted and deleted when the trial ends.

Switch sides and a Mock interview are one-to-one Dialogues. We keep which one it is and, for Switch sides, the side its poster took, with the Dialogue’s other records. In a Mock interview the job each of you is practising for is checked and passed to the other person like any live message. When people listen, members listening can vote once on who argued the other side best or whether they would hire the candidate. We keep only a code for each vote, made the same way, delete the codes when the Dialogue ends and keep the totals with the Dialogue’s other listener tallies. A scenario is recorded only when everyone speaking says yes. Deleting your data removes your lawyer’s seats and witnesses and closes any Courtroom you are Judge of.

Recorded Dialogues and Monologues

A Dialogue is put on the record only when the people speaking say yes on their own screens: both of you in a one-to-one, and in a group the host and then each speaker for their own voice. Been there, typed Dialogues and calls between People are never recorded. Each speaker’s phone records their own voice and sends it to us in five second pieces, stored encrypted. We copy the encrypted files to a storage provider that works for us and never holds their keys. The copy on our own servers goes after a few days. We keep who is in each recording, their first names, when it started and ended and whether each person said yes. Anyone speaking can pause it at any time.

When the Dialogue ends everyone whose voice was kept is asked whether to keep it. If anyone says no or does not answer within the time shown, every piece is deleted. Listen holds whole conversations, so a recording that ends before it has run the shortest length we keep, ten minutes at present, is deleted without anyone being asked. A recording everyone kept goes on Listen with how many people have listened. A listen counts once someone has played it for half a minute, once for each person. For that we keep only a code made from the recording and the listener that nobody can trace back to who listened, and it goes with the recording or with Delete my data. Members can report it. When enough members with a few Dialogues behind them report it, it comes off Listen until our staff listen and put it back or delete it. One report of a threat, someone under 18 or private information is enough. So does one whose written-out words hold a word we do not allow. We may also ask staff to listen to every recording first, and then one not reviewed in time is deleted. We keep each report of a recording (who made it, the reason and what staff decided) until the recording goes or you delete your data. An approved recording can be played by anyone who can listen on Dialogue, and shows on Listen with a chat under it. Members playing it write short lines that everyone playing it reads by first name. We check each line when it is written, keep it encrypted and delete it after a day or with the recording. A report takes it out of the chat and sends it to our administrators. We note which members are playing a recording so a name in its chat can open their page. We forget that after a day. Members can clip up to a minute of a replay. The clip is made on their device and never sent to us.

A kept recording may be sent to a transcription service that works for us, which gets the audio and nothing else, to write out what was said for captions. The words are stored encrypted. You can record a Monologue on your own, which works the same way and can be posted once it has run a few minutes. Recording and Monologues open after your first few Dialogues. Anyone in a recording can take it down from You at any time, and Delete my data or closing your account deletes every recording you are in, with its words.

The Dialogue Directory

Every Dialogue belongs to a topic, such as a book, a place or an idea. Each topic has one public page. Anyone with its link can see its name, its line, how many follow it and the questions asked in it over the last day, with how many members voted each up. It also shows the group Dialogues in it that are open to every member. Nobody’s name is shown there. Signed in, members also see the first name of whoever asked a question. One-to-one Dialogues posted in a topic show by their line alone, never who posted them.

Any member with a confirmed email can start a topic by naming it in a word or two when they post a Dialogue, a few a week. A new topic is listed on Talk once two other members follow it, post in it or ask in it. A Dialogue held in it lists it at once. Until then we keep a coded mark for each member who took part instead of their name. The marks are deleted once the topic is listed and are never kept in our recovery copies.

We keep each topic’s name and line, and which members follow it and when each last opened it, until they stop following it or delete their data. Only you see what is new in a topic you follow. We keep who started a topic while the topic lasts. A new topic nobody takes up is deleted after a week. Any topic nobody uses for 45 days is deleted too, and its name is free for anyone to start again. Questions are checked when they are written, stored encrypted and deleted with their votes after a day. They are never kept in our recovery copies. We keep who voted for a question only to count the votes and to tell those who voted, once in the app, when a Dialogue starts from it. Nobody is ever told who voted. A report takes a question off at once and sends it to our administrators.

Your standing

We work out a private standing for each member from how many Dialogues they have had, whether their email is confirmed, how old their account is, whether several people they talked with would rather not talk with them again and whether our staff upheld a report about them. It never uses points or How you talk. Only our staff see it, and it is worked out when it is needed rather than kept.

It decides whether you can record or post a Monologue and whether a report you make counts towards taking a recording off Listen. When our staff review a report they note whether they upheld or dismissed it. A report upheld about you lowers your standing for 90 days. Reports you make that staff keep dismissing stop counting towards pausing anyone or taking a recording down, though staff still read them.

Tips, paid questions and booked time

Where they are switched on, payments go through Stripe, on the Stripe account of the person being paid. You pay on Stripe’s own page and your card details go to Stripe, never to us. To be paid you set up a Stripe account from You, and Stripe collects what it needs to check who you are and pay you out. We keep which Stripe account is yours and whether it can take payments and pay out.

For each payment we keep who paid, who was paid, the amount, our share, what it was for and Stripe’s references to it. The person paid sees the amount and when, never who paid. A question you pay for waits with us, sealed, until the payment is held and then goes on the floor like any other. Booked time keeps who booked it, when, for how long and the price. Delete my data leaves each payment’s record without you as the payer, calls off slots and bookings still to come with a refund and forgets your Stripe account link. Stripe keeps its own records under its own privacy policy.

Points and games

Taking part earns points: listening, saying where you stand, having a question of yours answered, a top suggestion in Feedback, talking for ten minutes or more and three Dialogues in a week. Each point is a row saying what earned it and when, kept for a year. Your totals stay until you delete your data. Points cannot be bought, cashed or passed on and have no money value. Only you see them, and they never decide who you meet or what anyone sees. Points spent on a question that is not answered come back. Playing a Scenario through earns points too, with more for winning it. A juror or a witness in a Courtroom earns a few.

In a Feedback Dialogue you can call which way the room will move. We keep your call until the Dialogue ends and then delete it, and a right call earns points. If you ask to be invited to special events, staff can see your level and your email but nobody else’s. Delete my data removes your points, what earned them and any call you made.

Automatic checks

Names, titles, notes, questions, suggestions, card sentences, Dialogue descriptions and what is written on a Dialogue’s floor or in the chat under a one-to-one are checked against a short list of slurs, threats and explicit terms. Matching text needs rewording or is held for an administrator. Voice is never checked. Live text and messages never reach Dialogue for checking: your own device shows slurs and threats as *****, you can show them with a tap and nothing about this is sent to Dialogue. Ordinary swearing is never filtered. If several members independently report the same person, that person’s new introductions pause until an administrator has reviewed the reports.

Following and your page

You can ask to hear when a statement is live, and follow someone who lets listeners follow them. We keep who and what you follow, the first name you heard, when you followed and when you last listened to them, with the words encrypted. A follow of a person lapses after 90 days in which you never listened to them. It ends if either of you blocks the other or if they report your question. After a report you cannot follow them again. We keep a record of that with its date while both accounts exist, and deleting your data does not remove it. Alerts come in the app, at most once a day for each follow and never between 10 pm and 7 am on your device. By default a new follow of a person sends no alerts in its first week. We keep which Dialogue each follow last alerted about for one day.

If you let listeners follow you, your followers are told when you are live and people can listen. They never see your answers or past Dialogues and cannot message you. You see roughly how many follow you and never who unless you follow them too. Nobody is ever shown who follows whom. Two people who follow each other each see the other under Mutuals. You can pause alerts or remove all your followers at any time. Before you accept an introduction you are told if the other person lets listeners follow them, because their followers may be told when you are live together. They are told the same about you.

While you let listeners follow you, you have a page at a random address with your first name, your persona if you choose to show it and up to three badges you pick. Anyone with the link can see it. Search engines are asked not to list it.

Creator nights

A creator night is a public page where the people watching a creator’s show say where they stand before the argument and after it. It needs no account and asks for nothing about you. Voting sets a cookie with a random value so a browser votes once before and once after. We keep a keyed digest of it with that night, and the sealed vote until the result is out, two days at most. After that only the totals remain. Votes are limited per network, each hour and in each vote of a night, using a digest that cannot be turned back into an address. Those limits lapse within a day. A result shows totals only and is never broken down.

Group Dialogues and moderation

Members of a group Dialogue can see the names and speaking roles of other admitted members. Audio is encrypted between the participating browsers through privacy relays. All admitted listeners can hear the speakers. A group Dialogue open to every member lets people listen without joining unless its host turns that off when asking for it, and then members and visitors aged 18 or over can listen that way, up to the limit shown. They hear the people speaking through our media server, which passes the audio on to them and never records it. The people in the Dialogue see only how many are listening, never who. Anyone listening this way can report someone speaking and a member listening this way can send one question in question time. A group Dialogue for invited members only is heard by the people in it and nobody else, and the Dialogue says which it is before you join. We keep who listened to which group Dialogue, and when, for seven days for safety review. Hosts and assigned moderators can manage speaking permissions, timed rounds and access to the Dialogue. A moderator cannot turn on someone’s microphone. If the browser loses current permission information, it stops audio. If you drop out while speaking, your place is held for three minutes.

A group Dialogue runs for 25 or 50 minutes plus ten minutes for questions and can be extended when everyone speaking agrees. Each member listening can send one short question, which the people speaking see without the sender’s name. A reported question goes to the administrators with the words the sender wrote and the account behind it. That listener stops listening to the Dialogue, and the report is kept under the safety-report retention rules below. Questions are stored encrypted and deleted when the Dialogue ends. No system can prevent another participant from capturing what they hear with separate equipment.

If you tap Remind me on a group Dialogue that has not started, we keep which Dialogue, when you asked and whether you still want it. That goes when the Dialogue ends, a day after a start that never came or after thirty days at most. We tell you in the app when it starts and, if reminder emails are on, send one email to your account address shortly before. Nothing else is sent because of it. Its host sees only how many people asked.

We keep approved Dialogue descriptions and schedules, moderator assignments, membership and attendance timing, restrictions within a Dialogue, reports and moderation decisions. These records support running group Dialogues and safety review. Group connection messages are removed after two minutes or when a Dialogue closes. Moderator decision logs follow the same retention limit as administration logs. Only administrators can review submitted safety reports.

Badges and progress

Badges and milestones recognise taking part, never a particular score or opinion. Only you can see them, unless you pick some for your page. A sustained one-to-one Dialogue counts once when both browsers report being connected for at least ten minutes of overlapping time in it. Connection reports cannot verify attention, speech or quality. Temporary connection timing is removed when a Dialogue ends. Your counts and the date you reached each milestone stay until you delete your data. To count each person you talk with only once, we keep a code for each of them that cannot be traced back to anyone without our key. It is deleted when you delete your data. Badges are not a trust or safety rating and they never affect pairing. Your progress under You counts the one-to-one Dialogues you have had, the minutes you have talked and the Dialogues you have listened to, as numbers only. A Dialogue and its minutes count there once it reaches ten minutes, the same rule as badges. Nobody else sees it.

Retention and deletion

One-to-one Dialogues allow up to five minutes to join and 25 minutes for a conversation, plus five minutes for listeners’ questions when people can listen and those questions are switched on. Both people can agree to ten more minutes near the end, a limited number of times. Group Dialogues run for 25 or 50 minutes plus ten minutes for questions and can be extended when everyone speaking agrees. Connection setup records are cleared when a Dialogue closes. Ended searches are cleared after an hour, and match details an hour after the Dialogue ends. Minimal participation and closure records remain for seven days so safety actions can work after a call, and so two people who have just talked are not introduced to each other again straight away. Scheduled maintenance normally runs each minute to remove expired records. Outages can delay physical deletion.

Unfinished question drafts expire after 30 days and your latest 20 completions of each part are kept. Saved subjects lapse after 30 days. Your profile and notes stay until you change or delete them. Use You to export or delete your data. Deleting removes your name, your answers, your searches, your saved subjects, the kinds of Dialogue you stay in, who and what you follow, everyone who follows you, your page, your progress counts, your connections and their messages, your message keys, where you stood as a listener and the Dialogue cards you appear on and every recording you are in. Records of payments stay without you as the payer. Your own blocks stay, so nobody you blocked is introduced to you again. So does a record that you can no longer follow someone after a report or a removal. Reports you made that have not been reviewed yet stay too. For seven days the people you kept talking with can still report or block you from People. Your sign-in account and invitation records remain after that. You can close your account from You by entering your password, or ask us to. Closing deletes everything Delete my data deletes, signs you out everywhere and closes the account for good. Its name becomes Member. Your sign-in email is kept only in encrypted form with the closed account, so the address itself can be invited again. Closing cannot be undone. Reports and blocks submitted by others, and relevant administrative records, may remain for abuse prevention. Open reports remain until reviewed. Resolved reports are deleted 180 days after the last review unless reopened. Reports that led to a suspension are kept while the account exists, so a pattern can be recognised. Administrative logs keep up to 365 days or the latest 10,000 events.

Encrypted online backups keep recent recovery copies for two days, hourly copies for eight days and daily copies for 31 days. Disk snapshots keep up to 14 days. Offline encrypted backups are manually rotated during weekly backup maintenance. Deleted information can remain in these copies until they expire or are removed. Backups are restricted to recovery and are not available to other members. When restoring a backup, the operator must review and reapply later deletion requests before normal service resumes.

Forms and what your browser keeps

The sign-in and request forms carry one field nobody sees. Automated sign-ups tend to fill in every field they find, so anything written in it marks the request as automated. Nothing from that field is stored. While a one-to-one or a group Dialogue is live, your browser remembers the Dialogue and its access pass in that tab, so a reload can take you back to it. It stays on your device, it is not part of your saved data and closing the tab clears it. Your message keys, the listening tally, a visitor’s saved subjects and answers given without an account also stay in your browser and nowhere else.

Access requests and safety

Administrators review access requests, email invitations and safety reports. Request notifications, with the email, name and note from the request, are sent to the support mailbox. A declined request is deleted 180 days after it was declined, and administrators can delete a request sooner. Answers to the questions and private notes are never included in these emails. The admin dashboard does not show anyone’s answers to the questions or their notes. Reports are not monitored live. Dialogue is not a clinical or emergency service. Dialogue does not sell your answers, your notes or anything about your conversations. It does not use them to train software.

Return to Dialogue