Privacy Policy
Last updated: June 2026
partyline (“partyline”, “we”, “us”) is operated by 1550652 BC Ltd, a company incorporated in British Columbia, Canada. This policy explains what we collect and why. It is a general policy, not legal advice.
What we collect
- Account info — your email, name, and avatar, provided by GitHub or Google when you sign in, or your email when you use an email sign-in code.
- Profile & preferences — display name, timezone, and notification settings you choose.
- Session metadata — join codes, the orgs/teams/people on a line, and timestamps. We use this to run and coordinate sessions.
- Diagnostics — crash and error reports (via Sentry) to keep the service working. We don't attach your name or IP to these.
- Cookies & analytics — an essential cookie to keep you signed in. For analytics we use PostHog. In the signed-in app it runs in cookieless mode — no cookies, no device storage, no persistent identifier. On our public marketing pages only, we additionally record anonymized session replays — the pages a visitor views and what they click — so we can see where people get stuck and improve the site. These replays use short-lived browser session storage, and everything you type is masked and never captured. We don't record any signed-in area of the app. We also use Google Analytics on our marketing pages to understand traffic and where visitors go; it sets its own cookies and shares aggregate usage data with Google. We don't run advertising cookies and we don't sell your data.
Your terminal sessions are encrypted
Live sessions are encrypted in transit. Terminal data is encrypted on your machine before it leaves. Our relay (pppp.sh) is blind— it forwards ciphertext it can't read and never holds the key. So your team can see the join link in the web app and in invites, our control plane stores the session's encryption key. That means sessions are encrypted in transit and the relay can't read them, but this is nota zero-knowledge service: we hold the key. We don't read your sessions. The relay sees connection metadata(the routing code, timing, and data volume), not what's on your screen. Treat the join link like a password — anyone who has it can join and decrypt the session.
Who we share data with (subprocessors)
We use a small set of trusted providers to run partyline:
- Supabase — authentication and database
- Control Plane — application hosting
- Resend — transactional email (invites, sign-in codes)
- Sentry — error diagnostics
- PostHog — product & traffic analytics; cookieless in the signed-in app, plus anonymized session replay on public marketing pages (everything you type is masked)
- Google Analytics — traffic analytics on our public marketing pages only (sets cookies; aggregate usage processed by Google)
- Loops — product update emails for account holders (unsubscribe anytime)
- Slack — only if you connect a Slack workspace for notifications
- GitHub / Google — only when you choose to sign in with them
We do not sell your personal data.
Retention & your rights
We keep account and session metadata for as long as your account is active. You can access, correct, or delete your data — email us and we'll help. partyline is not directed to children under 16.
Changes & contact
We'll update this page if our practices change. Questions or requests: privacy@partyline.sh.