Privacy Policy

LAST UPDATED: AUGUST 2026

This policy applies to: www.openedmic.com - the public website and live broadcasting service operated by OpenedMic. The domains openedmic.com, openedmic.app, and www.openedmic.app redirect to www.openedmic.com and are governed by this policy.

1. What OpenedMic Is

OpenedMic is a browser-based live audio and video broadcasting service. A broadcaster opens a room; listeners join by room code, QR scan, or direct link. No installation or registration is required to use the service.

The service consists of a public landing page at https://www.openedmic.com/ and a separate operational application at https://www.openedmic.com/app. The application is designed for browser-first use and is installable on supported devices as a home-screen web application, without requiring distribution through a native app store.

2. No Registration Required

OpenedMic does not require you to create an account, provide an email address, or submit any personal information to use the service. You can create and join live rooms without registration.

3. Data Excluded from Self-Hosted Analytics and Error Telemetry

OpenedMic's self-hosted SQLite analytics database, analytics exports, and structured client-error telemetry are designed not to contain the data listed below. This does not mean those data are never processed. Some are used temporarily to operate a live room, stored locally in your browser, handled by infrastructure providers, or submitted through the contact form, as described in Sections 4, 7, 10, and 12.

4. Session Data

When you use OpenedMic, the following data may be processed temporarily to operate and protect the service. Each item is discarded according to the lifetime described below and is not written to the self-hosted analytics database unless Section 5 explicitly says otherwise.

4a. Approved Guest Mic - Privacy Specifics

When a listener uses the Approved Guest Mic feature, the following privacy properties apply:

5. Self-Hosted Operational Analytics

OpenedMic operates a self-hosted, server-side analytics system backed by a local SQLite database. It stores fixed technical and operational fields to understand product usage, service health, and feature adoption. It is designed to exclude direct identifiers, pseudonymous client or session IDs, raw IP addresses, raw User-Agent strings, room codes and URLs, names, contact content, and free text. Technical event records can still qualify as personal data under some laws when they can be related to an identifiable person, so this policy does not describe them as legally anonymous.

What the analytics system stores:

For listener-funnel measurement, OpenedMic stores technical event rows when an inbound room-link page with a six-character room parameter is loaded; a join is attempted; a listener joins or leaves; a listener connection remains active for at least 10 or 60 seconds; a room receives its first listener; or a join fails for an allowlisted reason such as room_full. Reports aggregate those rows into counts and timing summaries. Depending on the event, a row may include a UTC timestamp, event type, coarse join-source category, language setting, broadcast mode, private/public status, listener count, elapsed time in whole seconds, coarse device, browser, and operating-system families, and server version. It does not include the room code or URL, password, display name, socket or listener ID, IP address, raw User-Agent string, media content, or any persistent or session identifier.

Self-hosted operational analytics are stored in the configured SQLite database. At application startup, if a positive retention period is configured, records older than that number of days are deleted. If the retention setting is zero or unset, no age-based deletion is performed, and records remain until they are manually deleted or the underlying database or storage is removed.

Raw User-Agent strings are never stored. Browser, OS, and device class are derived from the User-Agent at request time; the raw string is discarded immediately after derivation.

All analytics read and reporting endpoints - including the aggregate summary page /stats, the analytics API under /analytics/*, and the operations endpoints /logs, /ops, and /ops/snapshot - are access-controlled behind a bearer token and, in the production deployment, are additionally restricted to a separate operations hostname. None of these endpoints are publicly accessible.

6. Structured Client-Error Telemetry

The application includes a lightweight client-side error reporting mechanism. When a technical error occurs in the browser, the application may transmit telemetry limited to these fixed technical fields:

Free-text error messages, raw stack traces, request bodies, source file paths, and any content that could contain user-generated or identifying information are not transmitted and not stored. The client application strips all such fields before sending.

7. Contact Form

When you submit the contact form at openedmic.com/contact.html, your submission is sent to the OpenedMic server for validation. The server validates the format of your submission, records only a minimal anonymous operational signal (a count of successful submissions, with no content), and returns a response to your browser.

The submission content - including your name, email address, subject, and message - is forwarded once to a configured outbound delivery webhook so the service operator can receive and respond to your message, and is then discarded. It is not retained in any OpenedMic database, log file, or analytics system after that forward. The outbound webhook provider's own privacy policy applies to what they store at their end.

If the outbound delivery webhook is temporarily unavailable or has not been configured, the server still does not retain your message: the user interface offers a direct email fallback to hello@openedmic.com so you can reach the operator from your own mail client.

8. Third-Party Analytics

The public website and live application do not load third-party analytics tags or send product-usage events from your browser to an external analytics provider. The self-hosted operational analytics described in Section 5 remain in use.

9. Installable Web Application

OpenedMic supports installation as a home-screen web application on supported devices and browsers. When you install the application:

10. Cookies and Browser Storage

The public website and live application do not set analytics or advertising cookies. They use functional browser storage on your device:

The functional localStorage values restore preferences, suppress repeated install prompts, reuse the display name, or support continuity during an active session. Clearing site data in your browser removes these values. The access-controlled operations dashboard at ops.openedmic.com sets one strictly necessary, HttpOnly session cookie named openedmic_dash_sid only after an authorized operator signs in. The cookie uses Secure and SameSite=Strict, has a 30-minute sliding expiry, and is not used for public visitors, analytics, or advertising.

11. Local Recording

If you use the local recording feature during a broadcast, audio and/or video is captured directly in your browser using the MediaRecorder API and saved to your own device as a WebM file. Nothing is uploaded to any server. OpenedMic has no access to your recordings. You retain full control of any recording you create.

12. Infrastructure and Third-Party Services

Any browser connection to a hosting, font, CDN, STUN, or TURN provider necessarily exposes network metadata such as the request IP address to that provider. WebRTC peers and relay or discovery services may also process network-address metadata needed to establish the connection. Each provider's own terms, privacy policy, and retention practices apply.

13. No Advertising

OpenedMic does not display paid advertisements and does not use its self-hosted operational analytics to build advertising profiles.

14. Children

OpenedMic is intended only for users aged 18 and over, as stated in the Terms of Service. OpenedMic does not knowingly solicit personal information from children. The automatic technical, network, and self-hosted operational processing described in this policy may occur when someone visits the site or uses the service. If you believe a child has submitted personal information through the contact form or a live session, please contact OpenedMic so the issue can be reviewed.

15. Changes to This Policy

This policy may be updated when the service changes. The date at the top of this page reflects the most recent revision. Continued use of the service after updates constitutes acceptance of the revised policy.

16. Contact

If you have questions about this privacy policy, please use the contact page.