Legal
Privacy Policy
Effective 17 August 2026 · Last updated 17 August 2026
Chamber watches how you work in order to prove you worked. That only earns your trust if the watching stays on your machine. It does. This page is the specific, checkable account of what is measured, what is stored, what is sent, and what is never sent at all.
The short version
- Your screen is condensed before anything is stored. A session's full-resolution capture is never written to disk and never uploaded. It exists only in memory, while the block runs, so that a ~30 second timelapse can be built from sampled frames. That clip is the only recording of the session that survives, and it is stored in your cloud library, private to you unless you publish it.
- You can blur it, and the blur is not reversible. Blurring destroys the pixels at the frame, before the clip is encoded. There is no unblurred version held anywhere, including by us.
- Focus signals are computed on your device and discarded. Window titles are hashed and thrown away. No keystroke, no URL and no title text is ever stored or transmitted.
- The camera check never leaves your machine. The likeness signature is computed locally and is never uploaded to us.
- Nothing is published unless you publish it, one session at a time. When you do, we receive a small set of numbers — not a recording.
- No ads, no analytics, no trackers, no advertising cookies. We do not sell or share personal information, and never have.
- You can use Chamber with no account at all. An account exists only for the Commons.
1. Who we are
Chamber is operated by Mua Media LLC ("Chamber", "we", "us"). We are the controller of the personal data described here. For anything on this page — questions, requests, complaints — write to y@muamedia.com.
This policy covers the Chamber web app at your-chamber.com, the Chamber desktop app, and the Commons API that serves them.
2. What stays on your device
This is the part that matters most, so it comes first. The following are measured, used, and then discarded entirely on your own computer. They are not transmitted to Chamber, in raw or summarised form, at any point:
- The full-resolution screen capture and every camera frame. These are never written to storage of any kind, ours or yours. They are read from the live capture, sampled into a short timelapse, and discarded when the block ends. What is stored is the timelapse, and section 5 covers where that goes.
- Window titles. Where screen recording permission is granted, the desktop app reads the frontmost window's title, converts it into a category and a one-way hash, and throws the text away. In the browser, the title strip is hashed from pixels and never read as text. Equal hashes mean "same surface"; that is all the scoring needs and all that exists.
- Keyboard and pointer activity. Chamber samples system idle time and pointer travel roughly once a second, which distinguishes keyboard-shaped work from pointer-shaped work. Chamber is not a keylogger. No key, no combination of keys, and no clipboard content is recorded.
- URLs and document contents. Never read, never stored, never sent.
- The frontmost application, screen-lock state, and the surface class inferred from the pixels of a frame.
- Your camera likeness signature (see section 6).
- Your local session history — every block you have run, its score, and your streak — which lives in a file on your disk (desktop) or in your browser's local storage (web).
If you never create an account, the desktop app makes no network calls at all, and the web app talks to our servers only to load the page itself. Verification, history, exports and share cards all work in that state, and timelapses are still made — they simply wait on your machine until there is an account to store them under, or until you delete them.
3. What we actually receive
Everything below is what a Chamber server can see. It is deliberately short.
| What | When we get it | What it contains |
|---|---|---|
| Account | You create an account | Your email address, a hash of your password (scrypt — we never store the password itself), a hash of your one-time recovery code, your public handle, display name and colour. |
| Sign-in sessions | You sign in | A hash of your session token, when it was created, when it was last used, an optional device label, and whether it was issued to the desktop app or a browser. |
| Published hours | You publish a session | Activity type, minutes, integrity score, mode, evidence tier, and the start and end timestamps. No recording, no titles, no app names. |
| Timelapses | You choose to upload one | A short, decimated video and one poster frame, plus its duration, dimensions and size. Uploaded only when you ask for it, session by session. |
| Cheers | You cheer someone | Which account cheered which post, and when. |
| Billing | You buy a membership | Your Stripe customer and subscription identifiers, plan, status and renewal date. Never your card number. |
| Waitlist | You submit the form | Your email address, and nothing else. |
| Request data | Any API call | Your IP address and request metadata, used transiently for rate limiting and held briefly in server logs by our hosting provider. |
We do not build advertising profiles, we run no analytics or tracking scripts of any kind, and we do not buy personal data about you from anyone.
4. Why we use it, and our legal bases
If you are in the UK, EU or another region with a similar law, these are our purposes and the legal bases under the UK/EU GDPR:
- Running your account and the Commons — performance of our contract with you (Art. 6(1)(b)).
- Taking payment and managing a membership — performance of a contract, and compliance with tax and accounting obligations (Art. 6(1)(b) and (c)).
- Keeping the service standing up: rate limiting, abuse prevention, fraud prevention, debugging — our legitimate interest in a service that works and is not being gamed (Art. 6(1)(f)).
- Protecting the meaning of a verified hour: detecting scripted or forged submissions — legitimate interest (Art. 6(1)(f)).
- Publishing what you asked us to publish — your consent, given per session, withdrawable by deleting the post (Art. 6(1)(a)).
- Waitlist and product email — your consent, withdrawable at any time (Art. 6(1)(a)).
5. Recordings and timelapses
What a session actually records
Chamber captures your screen while a block runs, and condenses it as it goes. Roughly every few seconds one frame is composited and kept; at the end those frames are assembled into a timelapse of about thirty seconds and a few megabytes. The full-resolution capture is never encoded to a file, never written to your disk, and never uploaded. It exists only as a live stream in memory, and it is gone when the block ends.
This changed in August 2026. Chamber used to write an hour-long, full-resolution video into ~/Movies/Chamber/ for every session. It no longer does, and it never touches or deletes the files it wrote before that change — if you have them, they are still yours to keep or remove. The reason for the change is that the condensed clip is the artifact people actually use, and holding a gigabyte of raw screen per hour created a large, revealing thing that nobody was watching.
The timelapse
This is the only recording of a session that survives it, and it lives in your cloud library rather than on your machine. It is private to your account by default. Nobody else can watch it — not other members, not us as a product feature — unless you publish it.
The video travels directly from your device to our object storage using a short-lived signed URL; the bytes never pass through our application servers. The bucket is not public. Playback is served through URLs we sign on request and that expire, and a public post exposes only the poster frame plus the clip you attached.
Be clear-eyed about the trade this makes. Because the clip is stored with us, we hold it: our storage provider has the bytes, and a lawful order could compel us to produce them, which was not true of a file that only ever sat on your disk. It is not end-to-end encrypted today. Two things follow, and both are choices you control: blur any block whose screen is not yours to hand over, and remember that you can delete any clip at any time, from the Library, from the player, or from your own card in the feed — the row and both stored objects go with it.
Blur
Blurring is applied to each frame, on your device, before the clip is encoded: the frame is reduced to a few dozen pixels across and blurred back up to size, which destroys the content rather than obscuring it. Shape and colour survive; text does not. There is no unblurred version of a blurred clip anywhere — not on your machine, not in our storage, not recoverable by us. Whether a block is blurred is your decision, made before it starts, and you can make blur the default in Settings.
Retention, and what it means now
An unpublished clip is kept for the retention window that applies to your account (see section 12), and is then deleted automatically. Because the clip is now the only recording of that session, that deletion is final: there is no local copy behind it. The Library shows a warning on any clip inside two weeks of expiry. Publishing a clip stops it ageing out, and the player offers Save a copy if you want the file on your own disk. Chamber is not a backup service, and you should not treat your cloud library as one.
Understand what publishing means. A published timelapse is visible to anyone who can see the Commons feed. Treat it as public, permanently, from the moment you post it — the internet copies things. Deleting a post removes it from Chamber and deletes the stored object; it cannot retrieve a copy someone else already made.
6. Camera, presence and the likeness check
The camera is optional on desktop and is used for presence in the browser tier. Two separate things can happen with it, and both happen locally:
- Presence. Chamber checks that a person appears to be there. This is motion and shape, not identity.
- The likeness check. A weak on-device signature that helps stop a friend farming your streak. It is computed on your machine, compared on your machine, and stored on your machine. It is never uploaded to Chamber.
We want to be exact rather than flattering about this: the likeness check is not biometric identification, it is not designed to identify you among strangers, and a photograph can defeat it. It is a speed bump against casual cheating. Because the signature never leaves your device and is never used to identify a person from a population, we do not operate it as a biometric identifier system — but if you are in a jurisdiction with a specific biometric statute and you would rather not run it at all, leave the camera off. Chamber still runs sessions on activity signals alone.
7. What is public
Your email address is your private login and is never shown to other users. The Commons shows only:
- your handle (an anonymous, Reddit-style name such as
@quiet_otter_482), display name and colour; - the hours you chose to publish — type, minutes, integrity, mode and evidence tier;
- any timelapse you attached, and its poster frame;
- cheers you give and receive, and your position in the weekly leaderboard.
You choose the handle and can change it. If you want to be unidentifiable in the Commons, pick a handle and a display name that say nothing about you, and check what a timelapse actually shows before you attach it.
8. People other than you
A screen recording can capture people who never agreed to be recorded: a colleague on a video call, a client's document, an inbox full of other people's names. Chamber's local-first design means we do not see any of that — but you do, and when you publish a timelapse, so does everyone else.
You are responsible for the lawfulness of what you record and, especially, what you publish. Blur the block when the screen is not yours to share, get consent before recording a call, and follow your employer's rules. If a timelapse you published exposes someone else's information, delete the post and email us so we can purge the stored object.
9. Payments
Commons memberships are billed by Stripe. Your card details are entered on Stripe's own checkout, go directly to Stripe, and are never seen, handled or stored by Chamber. We keep only the identifiers and status we need to know whether your membership is active: Stripe customer ID, subscription ID, plan, status and renewal date. Stripe processes your payment data as an independent controller under its own privacy policy.
11. Who else touches the data
We use a small number of infrastructure providers, each bound to process data only on our instructions. We do not sell personal information, and we do not share it with anyone for their own marketing.
| Provider | What for | What they can see |
|---|---|---|
| Vercel | Hosting and API functions | Requests to the site and API, including IP addresses in short-lived logs |
| Neon | Postgres database | Account records, published hours, cheers, timelapse metadata |
| Cloudflare R2 | Object storage | Timelapse clips and poster frames you uploaded |
| Stripe | Payments | Your payment details and billing history |
| Google Fonts | Web fonts on public pages | IP address and user agent of the browser loading the page |
We may also disclose data where we are legally required to, or where it is necessary to protect the rights and safety of Chamber or its users. If Chamber is ever acquired or merged, account data may transfer to the acquirer, who would remain bound by this policy or give you notice before changing it.
12. How long we keep things
- Account records — for as long as your account exists, and deleted when you ask us to delete it.
- Published hours and cheers — until you delete the post or your account.
- Timelapses — an unpublished clip is swept automatically after its retention window: 30 days on a free account, 400 days with a Commons membership. Published clips remain while the post does. Because the clip is the only recording of a session, this sweep is a real deletion with nothing behind it: the Library warns you before it happens, publishing stops the clock, and the player will hand you a copy to keep.
- Sign-in sessions — until you sign out or the session is revoked.
- Waitlist emails — until you ask to be removed, or the waitlist is retired.
- Server logs — kept briefly by our hosting provider on its own rolling schedule, and not used to build any profile of you.
- Billing records — retained by Stripe and by us for as long as tax and accounting law requires, typically seven years.
13. Security
Passwords are stored as scrypt hashes, never in the clear. Session tokens and recovery codes are stored only as hashes, so a leak of the database does not hand anyone a working credential. All traffic runs over TLS. The storage bucket is private and reachable only through short-lived signed URLs. Sign-in and signup are rate limited, and the sign-in path is written not to reveal whether an email address is registered.
Whether a published hour was earned on the desktop or in a browser is decided by the server from the request origin, never from anything the client claims. That is an integrity measure rather than a privacy one, but it is the same principle: we do not take the client's word for things that matter.
No system is perfectly secure. If you find a vulnerability, please tell us at y@muamedia.com before telling anyone else, and we will work with you.
14. Your rights and how to use them
Depending on where you live, you have some or all of these rights: to access the personal data we hold about you, to correct it, to delete it, to restrict or object to our processing, to portability, and to withdraw consent at any time without affecting what came before.
Most of these you can exercise yourself, immediately, without asking us for anything: change your handle and display name, delete an individual published hour, delete a timelapse, sign out to revoke a session, and export your full local history as CSV from the Library.
Deleting your account is one of them. Settings → Community → Delete this account. It runs in one step and takes with it every hour you published, every cheer you gave or received, every timelapse held in our storage, your sign-in sessions and your email address. If you hold a membership it is cancelled in the same step, so you are not billed again. There is no waiting period and no grace period: it is immediate, and we cannot undo it or restore what it removed.
One thing deliberately survives it: Stripe keeps the billing record of payments you actually made, which tax and accounting law requires us to retain (see section 12). Your local session history — the stats, streak and XP held on your own machine — also stays, because it was never ours to take; delete it yourself from Settings if you want it gone. Everything else goes, timelapses included: deleting your account deletes every clip in your cloud library and the objects behind them, and since those are the only copies, save anything you want to keep before you do it.
If you would rather we did it, or you cannot get into the account, email y@muamedia.com from the address on the account. We will verify that it is you, act within 30 days, and tell you when it is done. There is no charge for any of this, and we will never make your experience worse for having asked.
If you are in the EEA or UK you also have the right to complain to your local data protection authority. We would rather you came to us first, but the right is yours either way.
15. US state privacy rights
If you are a resident of California, Colorado, Connecticut, Virginia or another state with a comprehensive privacy law, you have rights to know, delete, correct and obtain a portable copy of your personal information, and to be free from discrimination for exercising them. Use the same contact address above.
Two disclosures that these laws specifically require: in the past twelve months Chamber has not sold personal information and has not shared it for cross-context behavioural advertising, and we do not process personal information for targeted advertising or profiling that produces legal or similarly significant effects. Because we do not sell or share, there is no opt-out to offer — but if you send a Global Privacy Control signal, it changes nothing about our behaviour, because there was nothing to stop.
16. International transfers
Chamber is operated from the United States and our providers process data in the United States and other countries. If you are in the EEA or the UK, that means your personal data is transferred outside your region. Where a transfer requires a safeguard, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) as incorporated into our agreements with the providers listed in section 11.
17. Age
Chamber is for people 16 and over. We do not knowingly collect personal data from anyone under 16. Because Chamber records screens and can use a camera, this is a line we take seriously rather than a formality. If you believe someone under 16 has an account, write to y@muamedia.com and we will delete it.
18. Changes
When this policy changes we will update the date at the top of the page. If a change is material — new categories of data, a new purpose, a new recipient — we will tell account holders directly before it takes effect, and where the law requires consent we will ask for it rather than assume it. We will not retroactively apply a weaker policy to data we already hold.
19. Contact
Mua Media LLC
Privacy requests and questions: y@muamedia.com
A real person reads that address. If a policy on this page and the way the product behaves ever disagree, tell us — we would consider that a bug in one of the two.