What “zero metadata” means (and does not)
Buzzio uses “zero metadata” in a scoped sense. This reference page prevents over-claiming.
Scoped meaning
1-to-1 chat and Whisper private chat are Buzzio’s zero-metadata conversation surfaces:
| Surface | When zero durable metadata applies |
|---|---|
| 1-to-1 chat | After nothing remains undelivered on the relay for that conversation |
| Whisper private chat | After the session expires and cleanup runs |
On those surfaces, Buzzio does not keep a durable server archive of:
- who privately talked to whom, and
- what they said
for that conversation. Readable history stays on participant devices.
Preferred sealed 1:1 delivery further avoids plaintext sender on the outer envelope and FCM wake.
Hands-on checklist: Verify zero metadata (1-to-1 & Whisper)
What still exists
| Data | Why |
|---|---|
| Account / Buzzio ID / profile | Product identity |
| FCM tokens | Wake devices |
| Undelivered sealed queues | Delivery before recipient online |
| “R got sealed wake at T” | Push/infrastructure visibility |
| CF sender knowledge at cert verify | Abuse / rate limits |
| Blocks / reports | Safety |
| Shared-mode history / operator-readable content | Communities, Broadcast, OHG, Stories ops, Whisper Questions; OHG / Community / Broadcast are TLS in transit and plaintext at rest |
| Analytics events | Operate the product (not sell ads) |
What we never mean
- Tor-grade network anonymity
- Absolute operator blindness on Firebase
- “Stores nothing at all”
- Shared rooms are sealed
Related: Privacy guarantees · Sealed vs shared · Sealed sender