What Buzzio can see (and cannot)
One-page cite sheet for journalists, store reviewers, and auditors. Prefer quoting this table over slogans. Deep links follow each row.
Quick matrix
| Domain | Can Buzzio staff read message bodies? | Durable who↔whom / history on Buzzio servers? | Notes |
|---|---|---|---|
| 1-to-1 sealed chat | No (E2EE; keys on devices) | No durable archive after delivery | Short undelivered queue; delete-on-delivery |
| Whisper private chat | No | No after session expiry | Temporary session plumbing while live |
| E2E groups | No readable transcript | Short catch-up only (~2 days) | Not open backscroll for late joiners |
| Private calls | No recording archive | No lasting browsable call dossier when idle | Signaling sealed; P2P media when possible |
| Open-history groups / Communities / Broadcast | Yes where product needs it (server-held / managed text keys; media CDN + dedup) | Yes for retention windows | Labeled shared |
| Stories | Shared-leaning ops (audience / views) | Ephemeral ~24h product data | Not sealed like 1:1 |
| Whisper Questions | Yes for link owner (by design) | Stored for owner | Not E2EE like Whisper private chat |
| Encrypted backup | No without your recovery key | Opt-in encrypted blobs | Staff cannot unlock |
| Account / profile / @username | N/A (account fields) | Account rows exist | Phone-free Buzzio ID |
| Push (FCM) on sealed path | No body / no sender id on preferred wakes | “R got sealed wake at T” visible to infra | Wake-only |
| Delivery Cloud Function | Sees cert-verified sender at deliver time | Not a chat archive | Intentional for block / rate limits |
| Blocks / reports | Safety records | Operational retention | Needed for abuse controls |
| Payments | Entitlement status, not full card numbers | Store-mediated | Google Play / Apple |
Infrastructure (honest ceiling)
Firebase / Google Cloud, FCM, Cloudflare, and Bunny necessarily see that accounts connect, that sealed wakes occur, and that CDN objects are fetched. Buzzio does not claim Tor-grade network anonymity.
Cite these pages
| Question | Page |
|---|---|
| Promises and refusals | Privacy guarantees |
| Feature-by-feature mode | Sealed vs shared |
| Scoped “zero metadata” | What zero metadata means |
| Hands-on verify | Verify zero metadata · How to verify |
| Adversaries | Threat model |
| Reviewer PDF | Protocol one-pager |