Effective Date: July 25, 2026 | Last Updated: August 31, 2026 · Operator: Bushwookies United
This policy explains what data we collect when you use BWU Uplink, why we collect it, and your rights over it. We keep it plain — no legal jargon.
1. Who We Are
BWU Uplink is a private, self-hosted chat, voice, and video platform operated by Bushwookies United at bushwookiesunited.com. If you have questions about this policy, contact us at contact@bushwookiesunited.com.
2. What We Collect
When you create an account or use BWU Uplink, we collect:
Account information — email address, username, display name, date of birth, and password (stored as a secure hash — we never see your actual password).
Passkey credentials — if you set up a passkey, we store its public key and a device label. Passkeys use standard WebAuthn public-key cryptography; the private key never leaves your device and we cannot access it.
Messages and content — text messages, file attachments, images, GIFs, pinned messages, and reactions you send in channels or direct messages.
Profile data — avatar, banner image, bio, pronouns, and accent color if you choose to set them.
Voice and video — audio and video streams when you join a voice channel or call, including camera and screen share. These are transmitted in real time and are not recorded or stored by us. Direct-message calls between two people connect directly between your devices whenever possible; group calls, and direct-message calls that cannot connect directly, are relayed through media server software we built and run ourselves, on our own machine. No outside company is involved either way.
Presence and activity — your online status, when you were last active, and (if you use the desktop app and enable it) the name of a game you are currently playing.
Session information — active login sessions, including browser/device type, so you can review and revoke them.
Payment records — if you subscribe, we store your subscription status and a Stripe subscription identifier. We never see or store your card number — that is handled entirely by Stripe.
Technical data — your IP address and browser type appear in our server access logs, which exist so we can investigate abuse and attacks. These logs rotate automatically and old entries are discarded; we do not archive them. Your IP address is not saved into the database alongside your account. The one exception is described under "Investigations" below, and it does not apply unless we have credible evidence that your account is being used to commit a serious crime.
Visitor counts — we count how many people visit the public landing and about pages. To tell repeat visits apart without identifying anyone, your IP address and browser type are combined with a secret value that is regenerated every day and turned into an irreversible hash. Because the secret changes daily, the same visitor cannot be linked from one day to the next, and the hash cannot be turned back into an IP address. We store only that hash and a page name — no cookies, no profiles, no third-party analytics service.
3. AI Processing of Messages
BWU Uplink uses Claude AI by Anthropic to provide these features:
Content moderation — every message you send, in any channel or direct message, is automatically screened by Claude for Terms of Service violations before it is delivered. This applies platform-wide and does not depend on which server or conversation you're in. We do this to comply with our legal obligations under Section 10 and Section 11 of our Terms of Service — keeping the platform free of illegal activity — not to monitor ordinary conversation.
User reports — if you or someone else files a report on a message or user, Claude reviews the reported content, the reason given, and any additional details to decide whether to dismiss the report, remove the reported message, or escalate it for human review by the operator. This exists for the same legal-compliance reason as automated moderation above.
New-member screening — answers submitted at the welcome gate may be evaluated by Claude.
AI chat assistance — if you interact with the AI assistant, your messages are sent to Claude to generate responses.
By using BWU Uplink you acknowledge that your text messages may be processed by Claude AI. Under our commercial agreement with Anthropic, data sent through the Claude API is not used to train AI models. Voice, video, and screen share are never sent to Claude.
4. Payment Processing
BWU Uplink offers paid plans: a $5.99/month Premium subscription (unlocking uploads, GIFs, camera, screen share, and more) and a $49/year Self-Host License (a key to run your own BWU Uplink server). Payments are processed by Stripe, Inc.
Your card details are entered directly on Stripe's secure checkout and are never transmitted to or stored on our servers.
We store only your subscription status and Stripe's reference identifier so we can grant access and manage renewals and cancellations.
To operate the platform — delivering messages, maintaining your account, and providing voice/video calls.
To process payments and manage subscriptions and self-host licenses.
To keep the platform safe — detecting abuse, spam, and policy violations.
To verify your age — we collect date of birth to prevent under-13 users from registering, in accordance with COPPA.
To improve the service — reviewing aggregate usage patterns (never individual messages for this purpose).
We do not sell your data. We do not use your data for advertising.
6. Third Parties
Anthropic (Claude AI) — processes text messages for moderation and AI assistance. Anthropic Privacy Policy.
LiveKit — self-hosted voice/video software we run ourselves, kept as backup infrastructure. It is not currently used to carry calls; if it is ever active, it runs on our own server exactly as described below, and LiveKit the company still receives nothing. LiveKit Privacy Policy.
GIPHY — when you search for a GIF, your search term is sent to GIPHY to return results. The search is made by our server, not your browser, and the GIF images themselves are streamed through our server too, so GIPHY never sees your IP address — not when you search, and not when you scroll past a GIF someone else posted. GIPHY Privacy Policy.
Email delivery — transactional email (password resets, welcome emails, license key delivery, and bug-report confirmations) is sent via our SMTP email provider. Your email address and the email's content pass through that provider to reach your inbox.
Push notification services — if you turn on push notifications, delivery is handled by the push service belonging to your browser or device: Google for Chrome and Android, Apple for Safari, iPhone and iPad, Mozilla for Firefox. We cannot deliver a notification to your device without going through them. The contents of each notification are encrypted before they leave our server and cannot be read by that service, but it does necessarily see that a notification was sent to your device and when. Turning push notifications off stops this entirely.
No other third parties receive your personal data. We do not use analytics services, advertising networks, or trackers, and we do not load fonts, scripts, or other files from third-party servers — everything the site needs is served from our own machine, so no outside company sees your IP address simply because you opened the page.
7. Data Retention
Messages — stored indefinitely unless you delete them. Deleting a message also deletes its attachments from our storage.
After you delete your account — your personal details, avatar and banner are erased immediately. Messages you sent remain in other people's conversations, shown as "Deleted User", unless you chose to have them deleted on the way out — in which case they are removed 30 days later, along with their attachments and your reactions. Data under a legal preservation obligation (Section 9 of the Terms) is excluded and is kept. Note that a backup taken before a deletion can still contain the data until that backup ages out, which is described under Backups below.
Account data — retained while your account is active. Deleted within 30 days of account deletion.
Server logs — access logs containing IP addresses are held on the server in a fixed-size rolling buffer. Once it fills, the oldest entries are overwritten automatically, so how far back they reach depends on traffic rather than a fixed date — in practice a matter of weeks.
Archived logs — we keep a copy of those logs for up to 90 days so we can investigate abuse after the fact. Before anything is archived, every IP address is replaced with an irreversible identifier, and the archive is encrypted. That lets us see that a series of requests came from the same source without the archive containing anyone's actual address. The archive is never used to look up what a particular person did.
Sessions — login sessions inactive for 60 days are automatically purged.
Backups — we take nightly backups so the service can be rebuilt after a failure, and keep them for up to 30 days before they are deleted. This means that for up to 30 days after you delete a message or an account, a copy can still exist inside a backup. Backups are encrypted, are never used to restore individual messages, and are only ever opened to recover the service as a whole after a disaster.
Reports — if you file or are named in a report, we retain a record of it (including the reported message's content at the time of the report) to maintain a moderation history, even if the underlying message is later edited or deleted.
Blocked messages — when automated moderation blocks a message, we keep a record of it, including the text of the message itself, alongside the account and channel it came from. This is separate from the reports above: it happens without anyone filing anything. It exists so that a suspension can be justified and reviewed rather than taken on trust, and it is kept for as long as the account exists.
Investigations — our Terms commit us to reporting serious crime to law enforcement. If we have credible evidence that a specific account is being used that way, we can place that one account under a hold, which records the IP addresses it connects from and suspends it. This is deliberately narrow: we do not log everyone's IP address on the chance that one day one account is investigated, and a hold only captures connections made after it is placed — never anything from the past. Only the operator can place one, and doing so is written to the server log.
8. Your Rights
Depending on where you live, you may have the right to:
Access & Portability — download a complete copy of your data yourself, instantly, from Settings → Account → Download my data. It's a machine-readable JSON export of everything we hold about your account. No request or waiting required.
Correction — update inaccurate information (most can be done directly in your profile settings).
Deletion — request deletion of your account and associated data.
Objection — object to certain processing of your data.
If you purchase a Self-Host License and run your own BWU Uplink server, that server is under your control and this policy does not govern the data on it — you become the operator responsible for your own users' data. Your self-hosted server contacts our license authority periodically to validate your license key; these check-ins transmit only your key and a basic instance identifier, not your users' data.
10. Children's Privacy (COPPA)
BWU Uplink requires users to be at least 13 years old. We do not knowingly collect personal information from children under 13. If we become aware that a user is under 13, we will delete their account and data promptly. If you believe a child under 13 has registered, please contact us immediately.
11. Security
Passwords are hashed and never stored in plain text. Passkeys use device-bound public-key cryptography. All data is transmitted over encrypted HTTPS connections, and backups are encrypted as well, so a copy of your data is unreadable even to whoever is holding the drive it sits on. We apply server-level security measures including firewall rules, rate limiting on sign-in and account creation, and browser security headers that stop other sites from learning which channels you are reading. We support two-factor authentication and passkeys for account access. No system is perfectly secure — if you discover a vulnerability, please contact us responsibly.
12. Changes to This Policy
We may update this policy from time to time. When we do, we will update the effective date at the top. Continued use of BWU Uplink after changes are posted constitutes your acceptance of the revised policy.
August 31, 2026 — what changed. A genuine change in what we do, disclosed the same day it happened:
Group voice and video calls now run on media server software we built and operate ourselves, in place of the self-hosted LiveKit software previously used for that. LiveKit remains installed as backup infrastructure but is not currently carrying any calls. Either way, media has always stayed on our own machine and no outside company has ever received it — that does not change here. See "Voice and video" and "Third Parties" above.
July 25, 2026 — what changed. Most of this update corrects things the previous version got wrong or left out. One item — the log archive — is a genuine change in what we do, and is marked as such:
Push notification services (Google, Apple, Mozilla) are now listed under Third Parties. They were always involved in delivering notifications to your device, and the policy should have said so.
The claim that access logs are kept "up to 90 days" was not accurate — no automatic deletion was actually configured. Log rotation has now been set up, and the wording describes what genuinely happens.
Visitor counting on the public pages is now described. It was already built so that it cannot identify anyone, but it was not disclosed.
Backups are now described, including the fact that deleted content can survive in a backup for up to 30 days. Backups are also now encrypted.
The site previously loaded a font from Google, which revealed every visitor's IP address to Google. That font is now served from our own machine, so the "no other third parties" statement is true of page loads as well.
New: our Terms have always said we report serious crime to law enforcement, but there was previously no way to actually do it — no IP address was stored anywhere and accounts could not be frozen. Both now exist, built as narrowly as we could manage: a single named account can be placed under a hold, and only then is its IP recorded. Everyone else's address is still never stored. See "Investigations" above.
New: we now keep a 90-day archive of server logs so that abuse can be investigated after the fact — the live logs rotate away too quickly to be useful for that. Every IP address is replaced with an irreversible identifier before anything is archived, so the archive holds no personal data. An earlier draft of this policy said we never copy logs anywhere; that is why this is called out here rather than quietly reworded.