Privacy policy
Your pictures stay yours.
Last updated 7 October 2026
The short version. Poof has no accounts, no database and no cookies. The photos it uses stay in the Zoom client on your own computer. Your stand-in clip is encrypted on your device before it is uploaded; our server only ever holds the encrypted file, cannot open it, and deletes it within 24 hours. Our technical logs contain no names, no images and no IP addresses. We count how Poof is used with anonymous, cookieless statistics that never include images, names or meeting content (section 6).
This policy explains what personal data Poof processes, why, on what legal basis, for how long, and what rights you have. It covers the website poof.website and the Zoom App Poof.
1. Who is responsible
Global Rising GbRVaubanallee 2
79100 Freiburg, Germany
shahar@nvcrising.org
We have not appointed a data protection officer, because the law does not require one for us. Write to the address above with any privacy question.
2. Using Poof in a Zoom meeting
What Poof uses. When you open Poof in a meeting, it uses the Zoom Apps SDK inside your Zoom client to:
- take photos with your camera when you ask it to: one of the empty room and, optionally, one of you. Zoom asks for your permission (Allow) before every photo;
- draw on top of your own video through Zoom's Camera Mode. Zoom composes the picture; Poof does not receive or record your live video stream;
- read your own in-meeting participant ID (so Zoom knows whose video to draw), whether your camera and microphone are on, and technical details of your Zoom client;
- mute your microphone while you step away, if you switch on Mute me while I'm away. Poof never hears or records audio.
Poof does not read other participants' names, video or audio, the chat, or the meeting's topic.
Why. To make you vanish into the empty room (the photo of you gives the effect your outline and colours) and to show your stand-in while you step away.
Where it is processed. On your computer, inside the Zoom client. The photos are not sent to our server, and we cannot see them.
What Poof remembers, and for how long. Poof keeps a small amount of data in the Zoom client's local app storage on your own computer:
| What | Contains | Kept |
|---|---|---|
| Empty room | The photo of the room without you | Until you capture it again |
| Photo of you | The photo of you and the outline Poof found in it | Until you retake or remove it |
| Stand-in | The ID of your encrypted clip and the key to open it | Until you record a new one or remove it |
| Settings | Your choices, such as vanish style, transition and loop | Until you change them |
What other participants see. Your video as Zoom sends it, with Poof's effect on top: you vanishing, or your stand-in clip instead of your live camera. Nothing else is shared with them.
Legal basis. Processing on your device runs the function you asked for (Art. 6(1)(b) GDPR).
3. Your stand-in clip
For Step away, Poof opens a recording page in your normal browser. With your browser's permission, it records a few seconds of you sitting in front of your camera. Then:
- The clip is encrypted on your device (AES-GCM, 256-bit key) before it leaves it. The key is part of the link's fragment (the part after
#), which browsers never send to a server. - Our server stores only the encrypted file, under a random ID. Without the key we cannot open it, and we never receive the key.
- Poof in your Zoom client downloads the encrypted file and decrypts it on your computer.
- The file is deleted automatically 24 hours after upload, or immediately when you click Remove in Poof.
To prevent abuse, the server limits how many clips can be uploaded from one IP address per hour. For this it holds IP addresses in memory for at most one hour; they are never written to disk or to logs. The recording page remembers which camera you chose in your browser's local storage, so you don't have to pick it again.
Legal basis: Art. 6(1)(b) GDPR (providing Step away, which you asked for); for the upload limit, Art. 6(1)(f) GDPR (our legitimate interest in protecting the service).
4. Adding Poof to Zoom
When you add Poof, Zoom redirects you to our server with a one-time authorization code. Poof does not use it: it is not exchanged for a token, not stored and not logged. Poof makes no calls to Zoom's APIs, does not request your Zoom profile, does not create an account for you, and receives no other data from Zoom.
5. Technical logs
To keep the service working and investigate faults, our server writes short technical log lines:
- Requests: the method, the page path without its query string and without clip IDs, the response status, the time taken, and whether the request came from the Zoom client.
- Clips: that a clip was stored, its size and length, and the first few characters of its random ID.
- Diagnostics from the app: your Zoom client and browser versions, the app's running context, which Zoom features are available, your camera resolution, the effect settings and how long effects took, and error messages. These never include names, images or meeting content.
Our logs do not record IP addresses, authorization codes or clip keys. They are kept for 30 days and then deleted automatically. Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in a secure, working service).
6. The website and usage statistics
This website sets no cookies and loads nothing from third parties: fonts, images and scripts are served from our own server. Requests to the site are logged as described in section 5.
Anonymous usage statistics. To learn which pages and features are used, so that we can improve them, the website and the app send usage events to PostHog, an analytics service. What is sent:
- On the website: which pages are viewed, which links are clicked, and the site you came from.
- In the app: which features are used (for example "vanish", "step away", "room captured" or "setting changed"), Poof's settings, whether effects worked or failed, Zoom error codes, and your Zoom client version.
- With every event: the type and version of your browser and operating system, screen size, language and time zone, and an approximate location (country and city) that PostHog derives from your IP address.
What is never sent: photos, video or audio, names or participant IDs, meeting IDs or topics, chat messages, or clip IDs and keys. The statistics have no user accounts or profiles, and we do not combine them with other data.
No cookies, nothing stored on your device. The statistics run in PostHog's cookieless mode. To count visitors without storing an identifier on your device, PostHog forms a one-way hash of your IP address, your browser's user agent and a secret value that it replaces every day, so visits on different days cannot be linked. Events pass through our own server, which does not log them.
Do Not Track. If your browser sends a Do Not Track signal, the website and the app send no usage events at all.
Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in understanding how Poof and its website are used, in order to improve them). You can object at any time (Art. 21 GDPR): switch on Do Not Track, or write to us. Usage statistics are deleted after 12 months.
7. Support requests
If you email us, we use what you send (your address, your message and anything you attach) to answer you and fix problems. Legal basis: Art. 6(1)(b) and (f) GDPR. We delete support emails 12 months after the request is resolved, or earlier on request.
8. Who else is involved
- Zoom Video Communications, Inc. (USA) runs the meeting platform that Poof works inside, and takes the photos when you allow them. Zoom's own privacy statement covers what Zoom processes. Transfers to Zoom are covered by the EU-US Data Privacy Framework, in which Zoom participates.
- Our hosting provider runs the server in Germany as our processor, under a data processing agreement. It stores the encrypted clips and the logs described above.
- PostHog, Inc. stores the usage statistics described in section 6 in its EU cloud in Germany, as our processor, under a data processing agreement.
We do not sell personal data or use it for advertising.
9. Retention at a glance
- Photos and settings: not stored by us. On your computer, until you replace or remove them.
- Stand-in clips (encrypted): 24 hours at most, or until you remove them.
- IP addresses for the upload limit: in memory only, at most one hour.
- Zoom authorization codes: not used or stored.
- Server logs: 30 days.
- Anonymous usage statistics: 12 months.
- Support emails: 12 months after the request is resolved.
10. Your rights
Under the GDPR you have the right to access your data (Art. 15), to have it corrected (Art. 16) or erased (Art. 17), to restrict processing (Art. 18), to data portability (Art. 20), and to object to processing based on our legitimate interests (Art. 21). To exercise them, email shahar@nvcrising.org. Because your photos stay on your computer and your clip is encrypted with a key only you hold, the quickest way to erase them is the Remove buttons in Poof.
You also have the right to complain to a data protection supervisory authority, for example the one where you live or the one responsible for us: the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg.
11. Removing Poof
You can remove Poof from your Zoom account at any time (see the user guide). We hold no account or profile about you to delete. Any stand-in clip is deleted from our server within 24 hours of recording at the latest.
12. Security
All traffic uses HTTPS (TLS 1.2 or 1.3). The server runs as an isolated, sandboxed service with no database and no network access of its own. Clips are encrypted end to end, so a breach of our server would not expose their content. Poof holds no Zoom credentials or tokens.
13. Children
Poof is not directed at children under 16.
14. Changes
If we change how Poof handles data, we will update this page and its date. For significant changes we will also note them on the support page.