Privacy policy
What we keep, and why.
Last updated 23 August 2026. Dare is operated by Kudapara Pty Ltd, a company registered in South Africa (kudapara.com). This page lists the data Dare actually handles, in the order you’d run into it.
What we collect
- Your account
- Your name, email address, and password. The password is stored as a bcrypt hash, never in plain text. You can add an avatar picture.
- Your office
- The office name, who belongs to it and in what role, the floor layout, invite links (which expire after 14 days), and the AI assistants’ settings.
- Messages and files
- Text you post in chat rooms, nearby chat, and direct messages, plus any files or images you attach. These are stored so the people in your office can read them later. You can delete your own messages; office admins can delete any message.
- Where you are on the floor
- While you have the office open, your position and status (open, do-not-disturb, in a room) are sent in real time to the other people in your office so they can see you on the map. We don’t keep a history of your movements.
- Voice, video, and screen sharing
- These run peer-to-peer between browsers using WebRTC. Our server only exchanges the connection details needed to set up the call. We do not receive, record, or store the audio or video. Your browser may contact a public STUN server (Google’s) to discover your network address.
- Sessions and cookies
- A session cookie keeps you signed in. We record the IP address and browser user agent of each sign-in so you can spot a session you don’t recognise. We don’t use advertising or third-party analytics trackers.
- Push notifications
- If you turn on notifications, we store the push subscription your browser gives us so we can send them. Turn them off in your browser to remove it.
Who else sees your data
- Paystack
- Handles payment for office owners. Paystack receives your email address and card details directly; we receive a subscription reference and payment status. We never see your full card number. Paystack’s privacy policy applies to what they hold.
- OpenRouter and AI model providers
- When an AI assistant replies in a room, the most recent 24 messages from that room — including names of who said what — are sent to OpenRouter, which routes them to the model the office owner has chosen (by default, models from Anthropic and Nous Research). Messages in rooms where no assistant is a member are not sent anywhere. We don’t use your messages to train models.
- Hosting
- Dare runs on servers we rent, at dare.muchiround.com, over HTTPS. Files you upload are stored on those servers.
We don’t sell personal data and we don’t share it with anyone else, except if the law requires it.
How long we keep it
For as long as your account or office exists. If an owner cancels, the office and its content stay in place, locked, in case they come back. If you deactivate your account, your sessions, push subscriptions, and room memberships are removed and your email address is detached from the account so you can no longer be contacted or signed in. Messages you wrote stay in the rooms, attributed to your name, so other people’s conversations still make sense; ask us if you want them removed as well. Backups may hold copies for a short while after deletion.
Your rights
You can see and change your name, email, avatar, and password in your account settings. You can ask us for a copy of your data, or ask us to delete it, and we will do so. If you’re in a jurisdiction with specific data-protection rights (such as POPIA in South Africa or the GDPR in the EU), those rights apply and we will honour them.
Changes
If this policy changes in a way that matters, we will update the date at the top and tell office owners by email.
Contact
Privacy questions or requests: consulate@muchiround.com.