AnonyID privacy notice
AnonyID is the account you use to sign in to Anony Labs apps, at account.anonylabs.com. It is pseudonymous, not anonymous: you are known by a username you choose rather than by your name, but the account belongs to you, so this notice describes personal data and your rights over it.
1. Who is responsible
- Controller
- Anony Labs
- Address
- Oude Apeldoornseweg 45-067, 7333 NR Apeldoorn, Netherlands
- Legal form
- AnonyID is run by Anony Labs, a Dutch sole proprietorship (eenmanszaak), at the business address above.
- Privacy contact
- privacy@anonychat.app
- Data protection officer
- None appointed. At its current size, AnonyID's core activity is not large-scale monitoring or large-scale processing of special categories of data (GDPR Art. 37). This is reviewed as it grows.
One AnonyID signs you in to every Anony Labs app; two apps are connected today, AnonyChat and AnonyVPN. Every app is open to every AnonyID, with no separate sign-up, and an app stores nothing about you until you first open it there. What an app keeps after that is described in that app's own privacy notice. This notice covers the AnonyID itself: account.anonylabs.com and the sign-in service behind it.
2. What AnonyID keeps
- Your account
- Your login username; your date of birth, which every AnonyID must have because Anony Labs apps are for adults (18 or older); your recovery e-mail address if you add one, and whether you confirmed it; and your password, stored only as an Argon2id hash. Kept until you delete your AnonyID. Settings shows your username, date of birth and recovery e-mail.
- Your sign-in methods
- For each passkey or security key you add: its public key and identifier, technical details of the authenticator (such as its model identifier and signature counter), its label and when it was added (a passkey created here is labelled with a masked form of your username, such as m•••o); the secret of your authenticator app, needed to check its codes; and your recovery code, stored only as a SHA-256 hash. Kept until you remove them or delete your AnonyID; a recovery code is replaced each time it is used.
- Sign-ins at account.anonylabs.com
- Each sign-in creates a session: when you signed in, which methods you used (for example a password and an authenticator code), how strong the sign-in was, and when it expires (after 30 days). The sign-in software we use (Ory Kratos) records an IP address and browser for every session; AnonyID never passes yours to it, so what it records is our own server's internal address and the fixed name “anony-account-ui”. Where our own app checked your second step (an authenticator or passkey carried over from AnonyChat, or a recovery code), we record which step it was for that session. A session stops working when you sign out, sign out everywhere or change your password (your other sessions), or after 30 days. Its record is deleted by a daily clean-up about a day after those 30 days, or at once when you sign out everywhere or delete your AnonyID. The record of your second step is kept until you sign out of that session, sign out everywhere or delete your AnonyID.
- The apps you use
- When you sign in to an app, the sign-in service (Ory Hydra) remembers this browser's sign-in for 30 days, so the app can sign you in again without asking, and keeps a record for each app you use with what it sent that app (section 3), encrypted. We also record the identifier of the sign-in session, so that “Sign out everywhere” can reach every app, and, for apps that hold a profile of yours, which app it is and when you first and last signed in to it — this last record stays even if you disconnect the app, because the app still holds your profile, and it is how we know which apps to ask when you delete your AnonyID. The app records are kept until you disconnect the app (Settings → Connected apps) or delete your AnonyID; the sign-in session records, including a remembered sign-in whose 30 days have passed, until you sign out everywhere or delete your AnonyID. The short-lived tokens handed to apps expire after 5 minutes (ID token) or 15 minutes (access token) and are deleted by a daily clean-up.
- Your AnonyChat avatar
- If you sign in to AnonyChat with your AnonyID and have set an avatar there, we keep a copy of it — a small image of about 128 × 128 pixels — to show it next to your username at account.anonylabs.com and in the header of anonylabs.com, and only to you while you are signed in. We ask AnonyChat for it a few seconds after you sign in to AnonyChat and at most once a day when you open your AnonyID home page, and replace our copy when your avatar changes. If you have no avatar in AnonyChat, nothing is kept and your initial is shown; we keep only when we last asked. The copy is deleted when you remove your avatar or your AnonyChat profile (at our next check), when you disconnect AnonyChat (Settings → Connected apps), and when you delete your AnonyID. We never ask for it if you have not signed in to AnonyChat with your AnonyID.
- Account e-mails
- If you add a recovery e-mail, we send it a code to confirm the address and, when you ask, a code to get back into your account. A copy of each message (the address and the text) is kept for 7 days after it is sent and then deleted by the daily clean-up. The codes themselves expire after 15 minutes.
- Accounts carried over from AnonyChat
- If your AnonyID was created from your existing AnonyChat account, AnonyChat gave us, encrypted, your login username, password hash, date of birth, recovery e-mail and whether it was confirmed, your authenticator secret, recovery-code hash and passkeys, and whether the account was a staff account. We keep your AnonyChat authenticator secret encrypted (AES-256-GCM) with a key held outside the database, and your AnonyChat passkeys (identifier, public key, signature counter, transports, when they were created and last used). We also keep which AnonyChat user ID your AnonyID belongs to, a checksum of the record we received, when it was carried over and activated, and whether the account had a second factor or was a staff account. All of it is kept until you delete your AnonyID; the AnonyChat authenticator is deleted when you set up a new one here.
- Security
- To slow down password guessing we count attempts per IP address and per username, in memory only, under a keyed hash (never the address or the name itself); the counts are never written down and are gone after 10 minutes to an hour, or when the app restarts. To stop an authenticator code being used twice we keep a keyed hash of each code you use for 2 minutes, and a passkey challenge for at most 5 minutes.
- Logs
- The web server in front of account.anonylabs.com keeps no access log: visits are not recorded. Errors go to the server's system log. Our own app's error lines name only the page and the error — never your IP address, username or anything you typed — and a deletion or an app's answer during one is logged only as its outcome. Errors in the sign-in protocol (Ory Hydra) are logged with the page asked for and the technical request headers, such as your browser's user-agent string, but without your IP address, cookies or the rest of the address, which it removes. The system log has no fixed time limit yet: its oldest entries are deleted once it reaches its size limit.
- Backups
- Every hour, the databases of AnonyID (accounts, sign-in methods, sessions, app records; the same backup also holds AnonyVPN's database) are copied and encrypted on our server with a key whose private half the operator keeps offline, so the server itself cannot read them. Each copy is kept on the server for up to 8 days and uploaded to Cloudflare R2 (section 4), where it cannot be deleted for 7 days; how long the R2 copies are kept after that is not yet stated. A deleted AnonyID therefore stays in backups made before the deletion until they are deleted.
There is no analytics, no advertising, no tracking and no profiling. No phone number is ever asked for.
3. What apps receive
- Every app
- A different identifier for you in every app (a “pairwise” identifier), so two apps cannot match you by it; when you signed in; how strongly (password only, or a second factor in the last 5 minutes) and which kinds of method you used (for example password, authenticator code, passkey, recovery code); and an identifier of the sign-in session, used when you sign out everywhere. Apps never receive your login username, recovery e-mail address, password or second factors when you sign in.
- AnonyChat
- In addition: whether you are 18 or older, and your date of birth, which AnonyChat uses for your AnonyChat profile when you first open it. If your AnonyID was carried over from AnonyChat, also your AnonyChat user ID with each sign-in, so that AnonyChat finds your existing profile.
- AnonyVPN
- Nothing beyond what every app receives.
- Your avatar
- To fetch your avatar (section 2), AnonyChat receives a signed request with your identifier at AnonyChat (and, for an account carried over from AnonyChat, your AnonyChat user ID), and answers with the image or with “none”. It learns nothing else from it.
- When you delete your AnonyID
- Each app you have used receives a signed request with your identifier at that app (and, for an account carried over from AnonyChat, your AnonyChat user ID): first to say what deleting would remove, then to delete it. What an app answers, such as your AnonyChat profile name, is shown to you and not kept.
- If AnonyChat stops using AnonyID
- Should AnonyChat have to go back to its own sign-in, the operator can give AnonyChat, encrypted, for each AnonyID created here that has signed in to AnonyChat: its identifier at AnonyChat, login username, password hash and creation time, so that you can keep signing in to AnonyChat with the same password.
4. Who processes it, and where
- InstantNode
- The server that runs AnonyID, and its databases, is rented from InstantNode — a sole trader registered in Germany (Ben Oliver Mallow, trading as InstantNode, Sickinger Straße 7, 55758 Sien, Germany) whose data centre is in the Netherlands. Both countries are in the EU.
- Cloudflare R2
- Stores the encrypted backups (section 2) in a bucket held in Cloudflare's EU jurisdiction. They are encrypted before they leave our server; Cloudflare cannot read them.
- Resend
- Resend, Inc. (United States) delivers the account e-mails (section 2) and receives the recipient address and the message, nothing else. Where Resend processes them, and the transfer basis if that is outside the EU, are not yet stated.
- Cloudflare Turnstile
- A check that tells people from bots, on the recovery forms, on the sign-in form after several failed attempts, and on sign-up. Its script and challenge load in your browser from challenges.cloudflare.com, where Cloudflare collects what it needs — browser and device signals and your IP address. Our server sends Cloudflare only a one-time token to check the result, never your IP address, and keeps neither. Cloudflare operates globally, so this data may be processed outside the EU, as described in the Turnstile privacy addendum and Cloudflare's privacy policy.
No other company receives AnonyID data. Apart from the Turnstile check, the fonts and scripts of account.anonylabs.com are served from our own server.
5. Why, and on what legal basis
These bases are the operator's own assessment; they have not been reviewed by a lawyer.
- Your account and signing in
- Keeping your account, sign-in methods and sessions, signing you in to the apps you open and sending them what section 3 lists, account e-mails, and deleting your profiles when you delete your AnonyID: performance of the contract you enter by using AnonyID (GDPR Art. 6(1)(b)).
- Your AnonyChat avatar
- Keeping a copy of your AnonyChat avatar to show your account the way you set it up there: legitimate interests (Art. 6(1)(f)). Disconnecting AnonyChat removes the copy.
- Age requirement
- A date of birth is required to keep Anony Labs apps for adults: legal obligation and legitimate interests.
- Security
- Rate limits, the Turnstile check, the code and challenge records, error logs and backups: legitimate interests in keeping accounts and the service secure and available (Art. 6(1)(f)).
- Accounts carried over from AnonyChat
- Moving existing AnonyChat accounts to AnonyID so that you keep your account, password and second factors, and handing sign-in data back to AnonyChat if it stops using AnonyID: legitimate interests (Art. 6(1)(f)).
- Legal obligations
- Where a law requires us to keep or hand over data: legal obligation (Art. 6(1)(c)).
6. Cookies
account.anonylabs.com sets only the cookies below. All of them are strictly necessary for signing in or for a choice you make, so they need no consent. There are no analytics or advertising cookies, and the site keeps nothing in your browser's local storage. The Turnstile check (section 4) runs in a frame from Cloudflare, under Cloudflare's own policy.
A name ending in * carries a different suffix for each form or sign-in request.
7. Signing out and deleting
- Sign out
- Ends your session on account.anonylabs.com in this browser only. Apps you are signed in to stay signed in.
- Sign out everywhere
- Settings → Sign out everywhere ends every AnonyID session and remembered sign-in, on every device, and tells the connected apps to sign you out.
- Delete your AnonyID
- Settings → Delete your AnonyID. You confirm it with a fresh sign-in (and your second factor, if you have one) and by typing your username. Deleting your AnonyID also deletes your profiles in the apps you have used — your AnonyChat profile, your AnonyVPN data — under each app's own rules: before you confirm, the page lists what each app will delete. Only when every app has confirmed do we delete your AnonyID: its sessions and remembered sign-ins everywhere, its app records, your account and sign-in methods, and our own records about it. If an app does not confirm, nothing is deleted and you can try again. An app may refuse: AnonyChat does not delete the profile of a staff member or of its owner this way while that role is assigned, and the page then says so. Backups keep a copy until they are deleted (section 2).
- Disconnecting an app
- Settings → Connected apps → Disconnect stops that app from signing you in without asking and deletes the copy of your AnonyChat avatar we keep (section 2). Your profile in the app stays.
- Removing only an app profile
- You can remove your profile inside an app (for example your AnonyChat profile) and keep your AnonyID. If you open that app again later, it starts a new, empty profile.
8. Your rights
Under the GDPR you can:
- Access
- Settings shows your username, date of birth, recovery e-mail, sign-in methods, where you are signed in and your connected apps. For a full copy of what is kept about you, write to privacy@anonychat.app.
- Rectification
- Change your password, recovery e-mail and sign-in methods in Settings. To correct your username or date of birth, write to the privacy contact.
- Erasure
- Delete your AnonyID in Settings (section 7), or write to the privacy contact if you cannot sign in.
- Restriction, objection and portability
- Write to the privacy contact. Processing based on legitimate interests can be objected to.
- Complain
- You may complain to a data protection supervisory authority: the Autoriteit Persoonsgegevens (the Dutch Data Protection Authority), autoriteitpersoonsgegevens.nl, or the supervisory authority in your own EU country.
9. Changes
Each version of this notice has a version number and an effective date.
- Version 2026-10-09.2: AnonyID now keeps a copy of your AnonyChat avatar to show it next to your username (section 2, section 3, section 5, section 7).
- Version 2026-10-09.1: First version of this notice.