The short version

1. Who we are

Chamber is operated by Mua Media LLC ("Chamber", "we", "us"). We are the controller of the personal data described here. For anything on this page — questions, requests, complaints — write to y@muamedia.com.

This policy covers the Chamber web app at your-chamber.com, the Chamber desktop app, and the Commons API that serves them.

2. What stays on your device

This is the part that matters most, so it comes first. The following are measured, used, and then discarded entirely on your own computer. They are not transmitted to Chamber, in raw or summarised form, at any point:

If you never create an account, the desktop app makes no network calls at all, and the web app talks to our servers only to load the page itself. Verification, history, exports and share cards all work in that state, and timelapses are still made — they simply wait on your machine until there is an account to store them under, or until you delete them.

3. What we actually receive

Everything below is what a Chamber server can see. It is deliberately short.

WhatWhen we get itWhat it contains
Account You create an account Your email address, a hash of your password (scrypt — we never store the password itself), a hash of your one-time recovery code, your public handle, display name and colour.
Sign-in sessions You sign in A hash of your session token, when it was created, when it was last used, an optional device label, and whether it was issued to the desktop app or a browser.
Published hours You publish a session Activity type, minutes, integrity score, mode, evidence tier, and the start and end timestamps. No recording, no titles, no app names.
Timelapses You choose to upload one A short, decimated video and one poster frame, plus its duration, dimensions and size. Uploaded only when you ask for it, session by session.
Cheers You cheer someone Which account cheered which post, and when.
Billing You buy a membership Your Stripe customer and subscription identifiers, plan, status and renewal date. Never your card number.
Waitlist You submit the form Your email address, and nothing else.
Request data Any API call Your IP address and request metadata, used transiently for rate limiting and held briefly in server logs by our hosting provider.

We do not build advertising profiles, we run no analytics or tracking scripts of any kind, and we do not buy personal data about you from anyone.

4. Why we use it, and our legal bases

If you are in the UK, EU or another region with a similar law, these are our purposes and the legal bases under the UK/EU GDPR:

5. Recordings and timelapses

What a session actually records

Chamber captures your screen while a block runs, and condenses it as it goes. Roughly every few seconds one frame is composited and kept; at the end those frames are assembled into a timelapse of about thirty seconds and a few megabytes. The full-resolution capture is never encoded to a file, never written to your disk, and never uploaded. It exists only as a live stream in memory, and it is gone when the block ends.

This changed in August 2026. Chamber used to write an hour-long, full-resolution video into ~/Movies/Chamber/ for every session. It no longer does, and it never touches or deletes the files it wrote before that change — if you have them, they are still yours to keep or remove. The reason for the change is that the condensed clip is the artifact people actually use, and holding a gigabyte of raw screen per hour created a large, revealing thing that nobody was watching.

The timelapse

This is the only recording of a session that survives it, and it lives in your cloud library rather than on your machine. It is private to your account by default. Nobody else can watch it — not other members, not us as a product feature — unless you publish it.

The video travels directly from your device to our object storage using a short-lived signed URL; the bytes never pass through our application servers. The bucket is not public. Playback is served through URLs we sign on request and that expire, and a public post exposes only the poster frame plus the clip you attached.

Be clear-eyed about the trade this makes. Because the clip is stored with us, we hold it: our storage provider has the bytes, and a lawful order could compel us to produce them, which was not true of a file that only ever sat on your disk. It is not end-to-end encrypted today. Two things follow, and both are choices you control: blur any block whose screen is not yours to hand over, and remember that you can delete any clip at any time, from the Library, from the player, or from your own card in the feed — the row and both stored objects go with it.

Blur

Blurring is applied to each frame, on your device, before the clip is encoded: the frame is reduced to a few dozen pixels across and blurred back up to size, which destroys the content rather than obscuring it. Shape and colour survive; text does not. There is no unblurred version of a blurred clip anywhere — not on your machine, not in our storage, not recoverable by us. Whether a block is blurred is your decision, made before it starts, and you can make blur the default in Settings.

Retention, and what it means now

An unpublished clip is kept for the retention window that applies to your account (see section 12), and is then deleted automatically. Because the clip is now the only recording of that session, that deletion is final: there is no local copy behind it. The Library shows a warning on any clip inside two weeks of expiry. Publishing a clip stops it ageing out, and the player offers Save a copy if you want the file on your own disk. Chamber is not a backup service, and you should not treat your cloud library as one.

Understand what publishing means. A published timelapse is visible to anyone who can see the Commons feed. Treat it as public, permanently, from the moment you post it — the internet copies things. Deleting a post removes it from Chamber and deletes the stored object; it cannot retrieve a copy someone else already made.

6. Camera, presence and the likeness check

The camera is optional on desktop and is used for presence in the browser tier. Two separate things can happen with it, and both happen locally:

We want to be exact rather than flattering about this: the likeness check is not biometric identification, it is not designed to identify you among strangers, and a photograph can defeat it. It is a speed bump against casual cheating. Because the signature never leaves your device and is never used to identify a person from a population, we do not operate it as a biometric identifier system — but if you are in a jurisdiction with a specific biometric statute and you would rather not run it at all, leave the camera off. Chamber still runs sessions on activity signals alone.

7. What is public

Your email address is your private login and is never shown to other users. The Commons shows only:

You choose the handle and can change it. If you want to be unidentifiable in the Commons, pick a handle and a display name that say nothing about you, and check what a timelapse actually shows before you attach it.

8. People other than you

A screen recording can capture people who never agreed to be recorded: a colleague on a video call, a client's document, an inbox full of other people's names. Chamber's local-first design means we do not see any of that — but you do, and when you publish a timelapse, so does everyone else.

You are responsible for the lawfulness of what you record and, especially, what you publish. Blur the block when the screen is not yours to share, get consent before recording a call, and follow your employer's rules. If a timelapse you published exposes someone else's information, delete the post and email us so we can purge the stored object.

9. Payments

Commons memberships are billed by Stripe. Your card details are entered on Stripe's own checkout, go directly to Stripe, and are never seen, handled or stored by Chamber. We keep only the identifiers and status we need to know whether your membership is active: Stripe customer ID, subscription ID, plan, status and renewal date. Stripe processes your payment data as an independent controller under its own privacy policy.

10. Cookies and local storage

Chamber sets no advertising cookies and no analytics cookies, because Chamber runs no advertising and no analytics.

The web app stores two things in your browser's local storage: your session token, so you stay signed in, and your own session history, so the app works. Both are strictly necessary for the service you asked for, both stay in your browser, and you can wipe them by clearing site data or signing out. Our API responses are sent no-store and set no tracking cookies.

One third-party request does leave your browser on our public pages: web fonts are loaded from Google Fonts, which means Google receives your IP address and user agent in order to serve the font files. No Chamber account data is involved in that request.

11. Who else touches the data

We use a small number of infrastructure providers, each bound to process data only on our instructions. We do not sell personal information, and we do not share it with anyone for their own marketing.

ProviderWhat forWhat they can see
VercelHosting and API functionsRequests to the site and API, including IP addresses in short-lived logs
NeonPostgres databaseAccount records, published hours, cheers, timelapse metadata
Cloudflare R2Object storageTimelapse clips and poster frames you uploaded
StripePaymentsYour payment details and billing history
Google FontsWeb fonts on public pagesIP address and user agent of the browser loading the page

We may also disclose data where we are legally required to, or where it is necessary to protect the rights and safety of Chamber or its users. If Chamber is ever acquired or merged, account data may transfer to the acquirer, who would remain bound by this policy or give you notice before changing it.

12. How long we keep things

13. Security

Passwords are stored as scrypt hashes, never in the clear. Session tokens and recovery codes are stored only as hashes, so a leak of the database does not hand anyone a working credential. All traffic runs over TLS. The storage bucket is private and reachable only through short-lived signed URLs. Sign-in and signup are rate limited, and the sign-in path is written not to reveal whether an email address is registered.

Whether a published hour was earned on the desktop or in a browser is decided by the server from the request origin, never from anything the client claims. That is an integrity measure rather than a privacy one, but it is the same principle: we do not take the client's word for things that matter.

No system is perfectly secure. If you find a vulnerability, please tell us at y@muamedia.com before telling anyone else, and we will work with you.

14. Your rights and how to use them

Depending on where you live, you have some or all of these rights: to access the personal data we hold about you, to correct it, to delete it, to restrict or object to our processing, to portability, and to withdraw consent at any time without affecting what came before.

Most of these you can exercise yourself, immediately, without asking us for anything: change your handle and display name, delete an individual published hour, delete a timelapse, sign out to revoke a session, and export your full local history as CSV from the Library.

Deleting your account is one of them. Settings → Community → Delete this account. It runs in one step and takes with it every hour you published, every cheer you gave or received, every timelapse held in our storage, your sign-in sessions and your email address. If you hold a membership it is cancelled in the same step, so you are not billed again. There is no waiting period and no grace period: it is immediate, and we cannot undo it or restore what it removed.

One thing deliberately survives it: Stripe keeps the billing record of payments you actually made, which tax and accounting law requires us to retain (see section 12). Your local session history — the stats, streak and XP held on your own machine — also stays, because it was never ours to take; delete it yourself from Settings if you want it gone. Everything else goes, timelapses included: deleting your account deletes every clip in your cloud library and the objects behind them, and since those are the only copies, save anything you want to keep before you do it.

If you would rather we did it, or you cannot get into the account, email y@muamedia.com from the address on the account. We will verify that it is you, act within 30 days, and tell you when it is done. There is no charge for any of this, and we will never make your experience worse for having asked.

If you are in the EEA or UK you also have the right to complain to your local data protection authority. We would rather you came to us first, but the right is yours either way.

15. US state privacy rights

If you are a resident of California, Colorado, Connecticut, Virginia or another state with a comprehensive privacy law, you have rights to know, delete, correct and obtain a portable copy of your personal information, and to be free from discrimination for exercising them. Use the same contact address above.

Two disclosures that these laws specifically require: in the past twelve months Chamber has not sold personal information and has not shared it for cross-context behavioural advertising, and we do not process personal information for targeted advertising or profiling that produces legal or similarly significant effects. Because we do not sell or share, there is no opt-out to offer — but if you send a Global Privacy Control signal, it changes nothing about our behaviour, because there was nothing to stop.

16. International transfers

Chamber is operated from the United States and our providers process data in the United States and other countries. If you are in the EEA or the UK, that means your personal data is transferred outside your region. Where a transfer requires a safeguard, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) as incorporated into our agreements with the providers listed in section 11.

17. Age

Chamber is for people 16 and over. We do not knowingly collect personal data from anyone under 16. Because Chamber records screens and can use a camera, this is a line we take seriously rather than a formality. If you believe someone under 16 has an account, write to y@muamedia.com and we will delete it.

18. Changes

When this policy changes we will update the date at the top of the page. If a change is material — new categories of data, a new purpose, a new recipient — we will tell account holders directly before it takes effect, and where the law requires consent we will ask for it rather than assume it. We will not retroactively apply a weaker policy to data we already hold.

19. Contact

Mua Media LLC
Privacy requests and questions: y@muamedia.com

A real person reads that address. If a policy on this page and the way the product behaves ever disagree, tell us — we would consider that a bug in one of the two.