bespoke.
Legal · Effective 11 Sep 2026

Privacy Policy

What bespoke collects, why it collects it, how long it stays, and the controls you have. Questions: abuse@bespoke.talk.

The short version

  • bespoke works without knowing who you are. People who open a chat give no name, no email, and no account.
  • What's stored is what the service runs on: messages, connection records (IP addresses), link metadata, and, only if you created one, your account email.
  • Chat pages carry no analytics and no ad trackers. Marketing pages use aggregate counts.
  • Nothing is sold, ever, and no ads run against your data.
  • Deleting a conversation removes it from the live service. Backups and logs can hold copies until they cycle out; we don't bring deleted conversations back.
01

Who this covers

This policy applies to everyone who uses bespoke: account holders, and people who open a chat through a link without an account. It's written in plain language, and it goes with the Terms of Service.

02

What we collect

Messages
What's sent in a conversation, with timestamps, so the account holder's inbox keeps it until they delete it.
Connection records
For security and abuse handling: the IP addresses that connected to a chat, and when. Kept for the conversation's lifetime, deleted with it.
Link metadata
Labels, creation and revocation times, view and chat counters.
Account data
An email address, only if you add one. Credentials are stored only in hashed or encrypted form; your dashboard link is stored as a one-way hash.
Notification settings
If you turn on Notify me in a chat, the push endpoint and keys needed to reach your device. Deleted with the conversation.
Operational logs
Standard server logs, which can include IP addresses, request times, and details about message delivery, kept to run and secure the service.
Backups
Copies of the service's data, kept so hardware failures and mistakes don't lose your conversations. They cycle out of rotation over time.

People who open a chat are never asked for a name, email, phone number, or payment details. There's nothing else to collect.

03

Why we collect it

  • To deliver the service: routing messages, keeping the account holder's inbox, resuming a chat with a one-time link.
  • To prevent abuse: rate limits, signup challenges, and investigating reports.
  • To meet legal duties: preserving and disclosing records when the law requires (see Terms, section 8).
  • To understand usage: aggregate counts of page views and chats per link. Not user profiles.
04

Cookies

One cookie, one purpose: a session cookie (snkrdrop_session) keeps account holders signed in. It goes away when you sign out. There are no advertising cookies and no cross-site trackers on chat pages.

05

Analytics and trackers

Marketing and account pages (the landing page, campaign pages, sign-up and log-in forms) use self-hosted, aggregate analytics: page counts with no visitor profiles. The landing and register pages also load Reddit's ad-measurement script, because we advertise on Reddit.

Chat pages, and the dashboard and inbox after you sign in, load none of this. Pages behind secret links are never tracked.

06

Where messages live

Chats are delivered over XMPP, an open messaging standard, through the messaging server that powers bespoke. That server processes messages as part of delivery. bespoke stores them so the account holder's inbox keeps the conversation. Files shared in a chat pass through the messaging server's file transfer, which keeps its own copy until it expires under that server's rules.

07

Retention and deletion

Conversation records (messages, connection records, notification settings) live exactly as long as the conversation does. When the account holder deletes a conversation, it's removed from the live service, not hidden. Two honest caveats: backups can hold a copy until they cycle out of rotation, and operational logs are kept for their own limited window. We don't use backups or logs to bring a deleted conversation back. Revoking a link stops new chats but keeps existing conversations until they're deleted.

Account data (email, hashed credentials) lives while the account does.

08

Sharing

  • We don't sell your data, and we don't run ads against it.
  • Service delivery: the messaging infrastructure that powers bespoke processes messages to deliver them. That's its job; it's not used for anything else.
  • Legal process: records are disclosed when we receive a valid subpoena, court order, or warrant (Terms, section 8).
  • Abuse handling: records connected to a credible abuse report may be reviewed and preserved while we act on it.
09

Your choices

  • Account holders: revoke any link, mute or delete any conversation, regenerate your dashboard URL, at any time.
  • People who open a chat: close the tab and you're out; keep the one-time return link if you want a way back; turn notifications on or off whenever you like.
10

Your rights

bespoke is operated in Singapore, and we handle personal data in line with Singapore's Personal Data Protection Act. You can ask to access or correct the data connected to you by emailing abuse@bespoke.talk. Include the chat link or account details that identify the record; we'll help where the request is specific enough to find it. Deleting data you can delete yourself (a conversation, a link, your account) is always faster through the product.

11

Children

bespoke isn't for anyone under 13, or under the higher minimum your local law sets. If we learn an account belongs to a child, we close it.

12

Changes to this policy

We may update this policy. The effective date at the top changes with each update, and material changes get a note on the changelog. If you keep using bespoke after an update takes effect, the updated policy applies.

13

Contact

Privacy questions, access or correction requests, and anything else go to abuse@bespoke.talk.