Privacy Policy

This policy explains how the Messaging Platform Hub website, optional Platform account, and optional Google Drive backup handle data.

Effective: 2 September 2026. This policy applies to the Messaging Platform Hub at hmdevonline.com and its demos. It does not replace the privacy policies of applications built by other developers with the SDK.

What we collect for a Platform account

Creating a Platform account requires an email address, display name and password. If you choose Sign in with Google, we receive the basic identity information necessary to identify your Platform account, including your Google account subject identifier, email address and display name. We use this only to provide account sign-in, account recovery, and saved-channel features.

Your Platform account is separate from the Developer Portal account used for API keys. The SDK does not send account data from an app simply because that app uses the SDK.

Saved channels and private material

Saved-channel labels and connection metadata are stored in browser storage for the account currently signed in on that browser. Channel passwords and exported key material are protected locally. We do not upload your saved channels or channel secrets to our Platform account service.

You can remove saved channels, sign out, or clear browser data from the profile page. Clearing browser data can make locally saved material unrecoverable unless you have made an export or optional backup.

Google Drive backup is optional

If you explicitly choose Drive backup, your browser requests Google Drive's drive.appdata permission. It creates or reads one encrypted keyring file in your Google Drive app-specific folder. The browser receives the short-lived Google access token directly; we do not receive a Google Drive refresh token, operate a server-side Drive integration, or keep a credential that can open your Drive backup.

You can stop using Drive backup at any time and manage or revoke the permission in your Google account. Google handles information it receives under its own privacy policy.

Data shared with service providers

We use Google only when you choose Google sign-in or Drive backup. We do not sell personal information. We disclose data only when needed to provide the requested feature, comply with law, protect the service and its users, or as part of a business transfer if one occurs.

Retention and security

Account data is retained while the account is active and for as long as reasonably necessary to operate, secure, resolve disputes, or meet legal obligations. Browser-saved data remains on your device until you remove it. We use reasonable technical measures to protect data, but no online service or device storage can be guaranteed completely secure.

Your choices and requests

You can use most SDK demos without an account. You can choose not to use Google sign-in or Drive backup, sign out, remove locally saved channels, and control Google permissions in your Google account. For privacy questions or requests concerning a Platform account, contact the project operator through the Messaging Platform Hub project.

Demo measurement

Every demo on this site tells you the server does not see what you send. That claim is only worth something if the page measuring the demos collects less than the demos themselves. Here is the whole of it.

Four counters, no message content

The demo pages record four things, and nothing else. They exist to answer one question — how often a live session actually falls over — so that the work goes where the breakage is.

session_started
A demo connected to a channel.
host_lost
The person hosting the session went away and someone else was promoted.
reconnect_succeeded
A dropped connection came back, and on which attempt.
reconnect_failed
A dropped connection gave up.

Each one carries the name of the demo folder you are in (whiteboard, chorus), one of three words for the kind of device (phone, tablet, desktop), and a reference number generated in the page. Any other word the page tried to send would be discarded by the server, which keeps a fixed list of the four event names above and refuses everything else.

What is deliberately not collected

  • Not the channel name, and not the channel password.
  • Not your display name, or anyone else's in the room.
  • Not a single byte of what you draw, type, say or share — that never reaches the server in the first place.
  • Not your IP address, and not your browser's user-agent string.
  • No cookie, no fingerprint, no identifier that survives the tab. The reference number is made when the page loads and is never written to storage, so two visits cannot be joined together — not by us, not by anyone reading the table.

What comes back out is counts: how many sessions started, how many lost a host, broken down by demo and device class. Individual rows are never served. They are deleted after 90 days by a job that runs nightly.

The SDK itself sends no analytics

This applies to the demos on this site only. The published package, @messaging-platform/web-agent-js, contains none of this code and makes no call of its own. An SDK that phoned home from inside other people's applications would be indefensible, so it does not.

Turning demo measurement off

Do Not Track and Global Privacy Control are honoured before anything is queued — if your browser sends either, these pages have already recorded nothing. You can also switch it off here, on this device:

Checking…

That sets sdk_telemetry=off in this browser's local storage. Clearing site data clears the setting too, so it will need saying again. Nothing else about the demos changes — they connect, host and reconnect exactly as before.