Privacy Policy
Last updated: August 27, 2026
The short version
marge.ma puts you on camera with three strangers. To do that, and to keep it usable, here is what happens to your data:
- Your video and audio go directly to the other people in the room wherever the network allows it. When it does not, the encrypted stream is relayed through our server, which cannot read it and does not record it.
- Still frames from your camera are checked automatically for nudity by software running on our own server. Frames that are not flagged are discarded immediately.
- Text chat is logged for moderation and deleted after 30 days.
- We log your IP address, who you were connected to, and when.
- We do not sell your data, we run no advertising, and we use no third-party analytics.
- Other users can record their own screen, and some of them stream. We cannot detect it. Assume you can be recorded.
The rest of this document is the same thing in detail.
1. Who this covers
marge.ma (“we,” “us,” or “our”) provides four-way video chat between people who have not chosen each other (“Service”). This policy explains what we collect, why, how long we keep it, and what you can ask us to do about it. It applies to everyone who uses the Service, including guests.
2. What We Collect
2.1 Accounts
- Guests: no registration. A temporary username is assigned to you and released when your session ends. We record the IP address the session was opened from.
- Registered accounts: a username and a password, nothing else. Passwords are hashed with bcrypt before storage and we never hold the plain text. We record the IP address and the time at which the account was created.
- We do not ask for your real name, your email address, or your date of birth.
- Your acceptance of these documents: when you create an account or continue as a guest, you confirm that you agree to our Terms and this policy and that you are 18 or over. We record that you did so, when, the IP address you did it from, and which dated version of each document you were shown. Guests are recorded the same way as accounts: the agreement is made by the session, and a guest session is as much a party to it as a registered one. We also store a one-way hash of the session identifier, so the record can be tied to a session without our holding anything that could be used to enter one.
2.2 Identifiers
- IP address: recorded at account creation, when you connect to another user, when you file a report, and when a moderation decision is made. It is the only handle we have on somebody who is not signed in, so it is what bans are applied to.
- Approximate country: derived from your IP address by a local lookup table. Used for the “X online in Y countries” readout and nothing else. No request leaves our server to obtain it.
- Browser and device information: sent by your browser with every request, and used to work out why a connection failed.
2.3 Connections
- Signalling: to start a call, browsers exchange descriptions of what they support and of the network paths between them. We pass these messages between the participants. We do not store them.
- Who met whom: we record the usernames in each room and the time, so that reports made after the fact can be investigated.
- Relayed media: video and audio are peer-to-peer by default. When a direct path cannot be established, which is common on mobile networks, the stream is relayed through our TURN server. It stays encrypted end to end throughout, we cannot read it, and it is not recorded. See §8.
2.4 What happens on camera
- Video and audio: not recorded by us at any point, and not stored anywhere.
- Automated nudity checks: your browser periodically sends a still frame from your camera to our server, where software we run ourselves looks for exposed body parts. If the frame is clean it is discarded as soon as it has been examined and is never written to disk. If it is flagged, it is kept as the evidence for the decision that follows. The same check runs on any profile picture you upload.
- Reports: when another user reports you, one still of your video is stored with the report, along with recent messages from the room, so that a person can review it. That still is not necessarily from the moment they pressed the button — see below.
- Stills held briefly by other people's browsers: while you are in a room, everyone in it with you keeps one still picture of your video, in their browser's memory, refreshed every few seconds. Its only purpose is the report button. Someone who does something they should not and immediately leaves would otherwise be unreportable, because by the time anyone reacts they are gone from the screen — so the report window offers the last few people you were with and you choose which of them you mean.
These pictures never reach us and are never written to anyone's disk. They exist only in the memory of the browsers of the people who were in the room with you, they are replaced as they are retaken, at most a handful are kept, and all of them are discarded when that person closes the page. The single exception is the one still attached to a report that is actually sent, which reaches us and is then handled as described above and in §5. Nobody is shown a picture of anybody they have not just shared a room with.
- Text chat: messages sent in a room are logged with the usernames and the time.
Other users can record you. You are always visible to the other three people in your room, any of them can record or photograph their own screen, and there is nothing we can build that would stop them or tell you it was happening. Some people come here specifically to stream. Our Terms set conditions on what they may then publish, and give you the right to have footage of yourself taken down, but those are rules we can enforce after the fact and not a technical protection. Treat the camera accordingly: assume anything you do here can be seen by more people than the three in front of you.
2.5 Profile and preferences
If you choose to fill them in, we store your bio, any social handles you add, your profile picture, your cosmetic choices, your buddy list, and settings such as whether you accept buddy requests. All of it is optional, all of it is visible to other users except the settings, and you can clear any of it at any time.
2.6 Cookies
We set one, it is strictly necessary, and it is shared with nobody. A session cookie, so the site knows you are still you between requests. It expires after 7 days for a registered account and 2 hours of inactivity for a guest. It is HttpOnly, SameSite=Lax, and marked Secure.
There are no advertising cookies, no analytics cookies, and no third-party trackers on this site.
3. How We Use It
- To run the Service: sign you in, put you in a room, and connect you to the people in it.
- To keep it usable: detect and act on nudity, harassment, and other conduct our Terms forbid.
- To investigate reports, including ones made after the conversation has ended.
- To enforce bans, which is why IP addresses are retained.
- To count how many people are online and roughly where, in aggregate.
- To comply with the law, including responding to valid legal process.
Where the UK GDPR or EU GDPR applies to you, our lawful bases are the performance of a contract with you (running the Service) and our legitimate interests in keeping the Service safe and in enforcing our Terms.
4. Automated Decisions
The nudity detector can suspend an account without a human having looked first. It is not the final word: every automatic ban is recorded for review, all bans have an end date, and you can contest one (see §10 and our Terms). If you tell us a decision was wrong, a person will look at it.
5. How Long We Keep It
These periods are enforced by a job that runs every day, not merely intended:
- Unflagged camera frames: not retained at all. Examined in memory and discarded.
- Text chat logs: 30 days, then deleted.
- Connection records (who met whom, and when): 60 days, then deleted.
- Stored frames from reports and from moderation decisions: 30 days, then erased from the record they are attached to. For a ban, the 30 days runs from the day the ban ends, because the frame is shown to the banned person while it is in force.
- Moderation records (what was decided, why, and against whom): kept, without the image, so that repeat conduct is visible.
- Account records: kept until you ask us to delete the account.
- Agreement records (that you accepted, when, and which version): kept indefinitely, because they are what makes the Terms binding and the question they answer can be asked years later. The IP address attached to one is cleared after 400 days: it is there to place the acceptance, it stops being useful long before the record does, and holding an address for years to support a tick is not proportionate. The rest of the row stays.
- Sessions: expire as described in §2.6.
6. Who We Share It With
We do not sell, rent, or trade your data, and we do not share it for advertising. It goes to:
- Our hosting provider, which stores it on our behalf and does not use it.
- Law enforcement, where we are legally required to disclose it, or where we believe it necessary to prevent serious harm.
- Us, meaning the people who moderate the site.
7. Security
- All web traffic is served over HTTPS, with HSTS enabled and preloaded, and plain HTTP is redirected.
- Passwords are stored as bcrypt hashes. Session cookies are HttpOnly, SameSite=Lax, and Secure.
- A Content Security Policy restricts what the page is allowed to load and run.
- The moderation panel is not reachable from the internet. It listens on the server's loopback interface only and is additionally password protected, so reaching it requires an authenticated connection to the machine itself.
- Media between users is encrypted by WebRTC as standard, including when it passes through our relay.
No system is perfectly secure. If you find a weakness in ours, please tell us at the contact below rather than demonstrating it on other users.
8. Third Parties
- STUN servers operated by Google and Cloudflare, used to discover the public address of your connection. They see that a device at your IP address asked, and nothing else. No video, audio, or account data reaches them.
- Our own TURN relay, run by us on our own server, used only when a direct connection cannot be made.
- The nudity detector runs on our own server, in a separate process. No frame is sent to any outside company at any point.
- Hosting: DigitalOcean, in their New York region.
There are no analytics providers, advertising networks, or social media pixels on this site.
9. Age
The Service is for adults. You must be 18 or over, you confirm it when you create an account or continue as a guest, and our Terms require it. We do not knowingly collect anything from anyone under 18. If you believe a minor is using the Service, tell us and we will remove the account and its data. If you are a parent or guardian and find that a child has used the Service, contact us and we will delete what we hold.
10. Your Rights
Wherever you are, you can ask us to:
- Show you what we hold about your account.
- Correct anything that is wrong.
- Delete your account and the data attached to it. Moderation records are the exception: deleting an account cannot be a way of clearing a ban.
- Export your data in a portable format.
- Object to a decision made automatically, and have a person review it.
We answer within 30 days. There is no charge. Because accounts need no email address, we may have to ask you to prove you control the account before we act on a request about it.
If you are in the UK or the EU and you are not satisfied with our response, you may complain to your national data protection authority.
11. Where Your Data Is
Our servers are in the United States. If you use the Service from elsewhere, your data is transferred there and processed there, under laws that may differ from your own. Where the UK GDPR or EU GDPR applies, we rely on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses for that transfer.
12. Changes
We may update this policy. The date at the top will change, and anything significant will be announced on our Discord.
13. Contact
For anything in this policy, including requests under §10:
Email: amin@marge.ma
Discord: @margema, or our server