Last updated 2026-09-26
Effective Date: 2026-09-07
Website: https://onlyus2.com
Operator: Dayle Stueven, Australia
Contact: [email protected]
Do I need an account? No. Nothing to sign up for, nothing to remember.
Can you read my messages? No. We only ever see locked data we can't unlock ourselves.
What if I lose my phone? Messages are encrypted with keys that exist only on your devices, and the decryption keys are never sent to our servers. Whoever picks the phone up is asked for the app passcode before anything is shown — and you can wipe everything from the app if you're worried. Someone technically able to read this browser's stored data directly, without going through the app, is outside what a passcode can protect.
Is it free? Yes. No ads, no subscriptions.
What if the other person screenshots it? Any app can be screenshotted by whoever you're talking to — that's true everywhere, not just here. No technology can prevent that.
For the real technical detail behind these answers, see how this actually works. The full formal policy follows below.
Only Us Two (“Only Us Two”, “we”, “us”, or “our”) is a free, browser-based messaging service designed to provide a private communication channel between exactly two people at a time.
The service is designed around minimal data collection. There are no user accounts, usernames, passwords, advertising profiles, behavioural tracking systems, or marketing databases.
This Privacy Policy explains what information is technically involved in providing the service, what remains on your device, what third-party infrastructure is involved, and what information we do not collect.
Only Us Two does not collect, store, or request:
We do not sell personal information or share information with advertisers.
There are no advertising networks, affiliate programmes, or data brokers associated with the service.
The Only Us Two backend uses a Cloudflare Worker and Cloudflare KV key-value storage.
The service technically stores only the minimum information necessary for its messaging operation:
Messages are encrypted on users' devices before being transmitted to the backend.
The backend receives and stores ciphertext rather than readable message content.
The encryption and decryption keys remain on the users' devices. The decryption keys do not leave the devices and are not transmitted to or stored by the server.
Accordingly, the operator cannot decrypt or read the message content through the backend.
Each pairing has a randomly generated room ID.
The room ID is not tied to a person's name, email address, telephone number, account, or other identity.
The service stores message timestamps and a padded/bucketed approximate message size.
Exact message size is deliberately obscured through padding and size buckets.
The encrypted message data, room information, timestamps, and associated approximate-size information are automatically deleted according to the service's configured retention behaviour.
A user may configure disappearing messages to:
If the user does not configure a disappearing-message period, no automatic deletion period is set. Encrypted messages then remain stored until they are deleted individually through the burn-after-delivery function, until the conversation itself is deleted, or until the underlying encrypted data is removed.
Automatic deletion is part of the service design. Users should nevertheless understand that deletion from the application's backend does not necessarily mean that copies could not exist elsewhere outside the application's control, such as information retained independently by a user or another service.
Certain information required for the operation of an encrypted conversation is stored locally in your own browser.
This consists of:
This information is stored in your browser's local storage and is not transmitted to the Only Us Two server.
Local information is cleared if you clear your browser's site data. You may also manually remove it using the in-app “wipe” feature.
Because encryption keys are intentionally kept on the user's device, Only Us Two does not maintain a server-side account or recovery mechanism that can restore them.
Only Us Two does not have user accounts or a server-side account recovery system.
If encryption key material or pairing information is lost—for example, because browser site data is cleared—the operator cannot recover the lost conversation or encryption keys.
This limitation is intentional and forms part of the service's privacy and security design.
Only Us Two's own application code does not log, store, or have access to incoming users' IP addresses.
However, the service uses Cloudflare for hosting, CDN, and backend infrastructure. Like other internet infrastructure providers, Cloudflare may inherently receive an IP address when a request is made to infrastructure it operates, because IP addressing is necessary for internet communications.
It is worth being specific about what that infrastructure layer can see, because end-to-end encryption does not extend to it. Each request carries the sender's IP address and a URL path, and for this service the path contains the conversation's identifier. That means the hosting provider is in a position to associate an IP address, a conversation identifier, and a timestamp for every message sent.
The consequence: the contents of your messages are unreadable to the service operator, but the who, when, and which conversation are not. Only Us Two is not an anonymous communication service and does not claim to be one. It hides the words, not the fact that a conversation happened or who was on either end of it.
This is infrastructure-level processing by the hosting/CDN provider and is not application-level IP logging by Only Us Two.
For information about processing performed by Cloudflare, users should consult Cloudflare's own applicable privacy documentation.
Only Us Two uses end-to-end encryption intended to prevent the service operator from reading message content.
The stated encryption design includes:
The authentication design is intended so that neither participant can subsequently use the cryptographic authentication mechanism to prove to a third party which participant sent a particular message.
The encryption implementation has not undergone a formal independent or external security review.
Accordingly, while the service is designed to provide end-to-end encryption, no representation is made that the implementation is free from security vulnerabilities.
The initial key exchange uses classical, non-post-quantum cryptography. This means the system does not currently provide post-quantum cryptographic protection.
Users should consider these limitations when deciding whether the service is appropriate for their communications.
Only Us Two uses the following third-party services:
Cloudflare provides hosting, CDN, and backend infrastructure for the service.
Only Us Two provides an optional PayPal donation link.
Donations are not required to use the service. Donations may be one-time or recurring at the donor's discretion.
Only Us Two does not operate its own payment processor, subscription system, or in-app purchasing system.
Information submitted directly to PayPal in connection with a donation is handled by PayPal under its own terms and privacy practices.
Only Us Two does not use third-party tracking cookies, advertising identifiers, analytics, or behavioural tracking systems.
Browser local storage is used for encryption key material and pairing state as described in this Privacy Policy. This local storage is part of the application's operation and is not used as a behavioural tracking mechanism.
Only Us Two does not:
There is no newsletter or email marketing system.
Only Us Two is intended for a general and international audience.
Where privacy legislation such as the EU General Data Protection Regulation (“GDPR”), UK GDPR, or comparable legislation applies, the legal basis for processing must be considered in light of the actual technical operation of the service and the particular circumstances of the processing.
The service is deliberately designed so that very little information capable of identifying a person is available to the operator.
Where applicable law provides these rights, individuals may have rights including:
In practice, many such requests may have little or nothing to act upon because Only Us Two does not maintain user accounts or store names, email addresses, telephone numbers, or other personally identifying information.
For example, the operator generally cannot identify which stored room or ciphertext belongs to a particular individual based on their identity because the service is not designed to associate that information with an identity.
Requests may be submitted to:
Where the California Consumer Privacy Act (“CCPA”), as amended, or another applicable California privacy law applies, California residents may have rights that can include rights to:
Only Us Two does not sell personal information.
Only Us Two also does not use personal information for targeted advertising or operate an advertising data-sharing system.
Because the service is intentionally designed not to collect or maintain identifying information, many rights requests may be moot or technically impossible to fulfil beyond confirming that the requested information is not held.
Only Us Two is not directed specifically at children.
The service does not knowingly collect names, email addresses, telephone numbers, accounts, passwords, or other personally identifying information from children or adults.
Because the service is deliberately designed not to collect such information, it does not maintain a database of children's personal information.
Parents or guardians who have a privacy concern may contact:
Only Us Two's application-level stored data is deleted according to the disappearing-message setting selected by users. Where a user selects no period, the application sets no automatic deletion period, and stored data remains until it is deleted by the user — by burning an individual message after delivery, by deleting the conversation, or by wiping the data held on the device. Unopened pairing links are set to expire after 24 hours.
Choosing no period therefore means no automatic server-side expiry: the encrypted messages are retained until the deletion steps above are used. Users who would rather not have a conversation retained indefinitely should select a period.
Local encryption keys and pairing state remain in the user's browser until browser site data is cleared or the user uses the in-app “wipe” function.
Infrastructure-level processing performed by third-party providers such as Cloudflare is governed by those providers' own systems, policies, and applicable legal obligations.
We design the service to minimise the amount of information available to the operator and to keep encryption keys on users' devices.
However, no internet service or cryptographic implementation can be guaranteed to be completely secure.
In particular, the encryption implementation has not received a formal independent security audit.
Users should therefore understand that use of the service involves security risks inherent in internet communications, browsers, devices, third-party infrastructure, and unaudited software.
If this Privacy Policy changes, the updated version will be published on the Only Us Two website with an updated effective date.
Privacy questions or requests may be directed to:
Dayle Stueven
Australia
[email protected]
This Privacy Policy is a product/privacy-policy draft based on the stated technical and business characteristics of Only Us Two.
It is not a substitute for advice from a qualified lawyer.
Before publication, legal counsel should review, in particular: