lkjparty0.4.0 · Privacy policy

Privacy policy

Effective date: September 30, 2026 · Version 0.4.0

lkjparty lets friends share selected web pages, coordinate media and optional application state, and chat in invitation-only rooms. Maintainer: lkjsxc. This policy describes the extension and its configured room service. No lkjparty account is needed. Nicknames are chosen by users and are not verified identities; using a nickname does not make you anonymous.

Data shared in a room

Creating or joining a room sends your nickname to the room server. The server and other participants receive the selected page URL, enabled media position/playback/rate and scroll state, connection and readiness status, chat, and reactions. Pointer coordinates and application-defined state are shared only when their options are enabled. These are used to deliver the room, synchronize the enabled parts of the selected page, and show participants and conversation.

An invite bearer grants membership. A separate resume bearer lets the extension reconnect as the same member. The resume bearer is sent only to the room server for membership and is never broadcast to participants. The host can rotate invite links or lock the room to new guests. Share invitations only with people you trust.

Voluntary freeform chat can contain content you choose to enter. lkjparty does not request or track bank information, health information, or precise location. Avoid sharing sensitive information in nicknames or chat.

Data handled locally in your browser

Your nickname is saved in extension storage.local until replaced or the extension is removed. Session information, including the resume bearer and bound page tab/document and synchronization preferences, is kept in storage.session across background worker restarts, until you leave or the browser session ends. Chat drafts, unread markers and the selected panel view are saved in trusted extension session storage. Drafts are sent to the room only when submitted. Your all-site or individual-site access choice is kept in extension local storage; actual grants are managed by your browser. A pending invitation may also be held in session storage until used or replaced; it is not a long-term preference.

The extension inspects the selected tab URL and title locally. Page titles stay local. Clicking the toolbar grants temporary active-tab access; choosing to share or connect requests all-site or individual-site access, according to your choice. Scroll, pointer and application-state sharing are off by default. A grant may remain in the browser until you revoke it, but lkjparty injects its sync engine only into the chosen tab. It reads accessible media and scroll state there, including open shadow roots and same-origin frames. It does not record browsing history from unrelated tabs. Volume, subtitles, and quality stay local. Full selected page URLs, including non-sensitive query strings and fragments, are visible to the room. Avoid sharing private URLs.

Automatic form-input, keystroke and click mirroring is not implemented. Optional application integrations choose which bounded JSON fields to publish; their developers must exclude secrets and validate received state. Enable application-state sharing only for an integration you trust. Turning it off stops new sharing but cannot erase data already received by others.

lkjparty does not request browser access to provider passwords or cookies, media streams, or downloads. Each participant uses their own access to the official video service. lkjparty does not skip ads.

Delivery, protection, and retention

The room server and reverse proxy/platform handle IP addresses, socket connections, and ordinary HTTP routing metadata to deliver requests and prevent abuse. The server uses bounded in-memory rate counters: request and upgrade counters expire after one minute, and room-creation counters after one hour. These maps are limited to 4,096 entries each and swept regularly. Reverse proxy/platform HTTP logging is separate and may retain ordinary request metadata beyond the room process lifetime; this policy does not claim that infrastructure logging is disabled.

The Coder hosting gateway may set an essential, short-lived HttpOnly/Secure cookie to route access to this application. This is not a video-provider cookie, an advertising identifier, or a lkjparty account. The extension does not request the browser cookies permission.

The public HTTPS service uses TLS transport encryption. The server operator and room participants can read room data; messages are not end-to-end encrypted.

Rooms have a maximum life of 6 hours. Room state and up to 80 recent chat/reaction entries are kept only in the server process memory, with a 96 KiB serialized history cap that may retain fewer entries. Entries disappear on pruning, room expiry, or server restart. There is no persistent room database.

Leaving clears your local resume bearer and revokes connected membership. If you leave while offline, the server-side session expires after the bounded disconnect grace (60 seconds). Leaving does not delete your already authored chat from an ongoing room; it remains until pruning, expiry, or restart. Empty rooms are removed when their last membership leaves or expires. Other participants may retain their own copies of anything shared with them.

Purpose, Limited Use, and third parties

lkjparty uses and transfers user data only as permitted by the Chrome Web Store User Data Policy, including its Limited Use requirements. Data is used for the disclosed selected-tab sharing features and their security, not for unrelated purposes.

Room participants receive the messages you choose to share with them. Human access by the operator is limited to your consent to review specific data for support, necessary security or abuse investigations, applicable legal obligations, or aggregated and anonymized internal operations. Technical access to the server is not permission to browse private conversations.

lkjparty does not use room data for advertising, analytics, AI processing, profiling, sale, or unrelated purposes. It does not embed advertising or analytics services. Your video provider and hosting platform operate under their own privacy practices.

If you send a support message through the Chrome Web Store after publication, that message goes to Google and is subject to Google’s privacy policy. Include only the information needed to describe your issue.

For help or privacy questions, read Support. This bundled policy can be read offline in the extension; external links require a connection.