What Buzzio can see (and cannot)
One-page cite sheet for journalists, store reviewers, and auditors. Prefer quoting this table over slogans. Deep links follow each row.
Quick matrix
| Domain | Can Buzzio staff read message bodies? | Durable who↔whom / history on Buzzio servers? | Notes |
|---|---|---|---|
| 1-to-1 sealed chat | No (E2EE; keys on devices) | No durable archive after delivery | Short undelivered queue; delete-on-delivery |
| Whisper private chat | No | No after session expiry | Temporary session plumbing while live |
| E2E groups | No readable transcript | Short catch-up only (~2 days) | Not open backscroll for late joiners |
| Private calls | No recording archive | No lasting browsable call dossier when idle | Signaling sealed; P2P media when possible |
| Open-history groups / Communities / Broadcast | Yes — text is plaintext at rest; media is stored as CDN bytes | Yes for retention windows | TLS in transit only; no at-rest / server-held DEK privacy model |
| Stories | Shared-leaning ops (audience / views) | Ephemeral ~24h product data | Not sealed like 1:1 |
| Whisper Questions | Yes for link owner (by design) | Stored for owner | Not E2EE like Whisper private chat |
| Service bots / Forge | Yes — Buzzio and the bot developer can receive text | Text ~7 days; additional operational windows apply | User→bot files up to 2 MB may be stored ~7 days |
| Encrypted backup | No without your phrase-derived account key or separate recovery key | Opt-in encrypted blobs | Random file key; locally wrapped before upload |
| Private Vault | No without your phrase-derived account key or separate Vault recovery key | Opt-in encrypted files and metadata | Dedicated seed derivation label; separate from backup |
| Note to Self | No (device keys / NRK) | No durable vault; ≤3-day mailbox ciphertext only | Device-first; linked web is notes-only |
| Saved Messages | No (device keys / SMRK) | Yes — durable ciphertext + media ciphertext; 200 MB pool | Premium write; operators see store metadata, not bodies |
| Account / profile / @username | N/A (account fields) | Account rows exist | Phone-free Buzzio ID |
| Push (FCM) on sealed path | No body / no sender id on preferred wakes | “R got sealed wake at T” visible to infra | Wake-only |
| Delivery Cloud Function | Sees cert-verified sender at deliver time | Not a chat archive | Intentional for block / rate limits |
| Blocks / reports | Safety records | Operational retention | Needed for abuse controls |
| Payments | Entitlement status, not full card numbers | Store-mediated | Google Play / Apple |
Infrastructure (honest ceiling)
Firebase / Google Cloud, FCM, Cloudflare, and Bunny necessarily see that accounts connect, that sealed wakes occur, and that CDN objects are fetched. Buzzio does not claim Tor-grade network anonymity.
Cite these pages
| Question | Page |
|---|---|
| Promises and refusals | Privacy guarantees |
| Feature-by-feature mode | Sealed vs shared |
| Scoped “zero metadata” | What zero metadata means |
| Hands-on verify | Verify zero metadata · How to verify |
| Adversaries | Threat model |
| Reviewer PDF | Protocol one-pager |