Version 2026-09-27
OmegleHub stores account username, password hash, self-reported gender, age/Terms/Privacy attestations, matching history, ratings, credit balances, payment order/capture identifiers, security logs, and approximate country information.
The service records the public IP address seen by the server for security, abuse prevention, account events, and country estimation. Raw IP addresses are encrypted before being written to the application database. A keyed one-way hash is also stored for abuse correlation. The current starter build retains IP logs for up to 90 days. If you use a VPN or proxy, the country may represent that service's exit location rather than your actual location.
A matched user can see your username, your live camera/audio, and an approximate country label when available. Your raw IP address is not intentionally displayed by OmegleHub. However, peer-to-peer WebRTC networking can expose network-address information to peers or networking infrastructure depending on browsers and connection method.
The application server does not intentionally record or archive webcam video or microphone audio. Signaling messages used to establish WebRTC connections are temporary. If a TURN relay is configured, media may pass through that relay without being intentionally recorded by this application. In regular random chat, supported browsers may run local on-device face-presence detection to end a chat when a face remains off camera; OmegleHub does not intentionally upload or store face images, biometric templates, or face-detection results from this feature. Paid gender matching and Dating Mode do not use this automatic face-presence stop.
When payments are enabled, PayPal processes payment credentials under its own privacy terms. OmegleHub stores order/capture identifiers and the purchased product/amount, but this starter build does not store card numbers or PayPal passwords.
When the site is behind a trusted provider such as Cloudflare, OmegleHub can use that provider's country header. The starter code does not silently send each user's IP address to a separate public geolocation API.
Account passwords are stored as password hashes. The database and encryption key are placed outside the web root by default and file permissions are restricted where the host allows. No system can promise perfect security. Match/signaling data is periodically cleaned up; certain payment, legal-consent, and security records may need longer retention.
Before public launch, add a working privacy contact and account-deletion/request process appropriate to the jurisdictions in which the service operates.