Skip to article
Platform / Privacy

Privacy

What Emojisense stores, what it never stores, and why.

On this page

The short version

  • Most searches never leave the device.
  • Emojisense never logs or stores IP addresses or the identifiers of your users. API keys are stored only as a SHA-256 hash and their first 12 characters, and never logged.
  • Message text for reaction suggestions and images for photo to emoji are never stored.
  • Query text is normalized and cut to 64 characters. A query is named in analytics, or used by Emojisense’s own jobs, only after it was seen at least 5 times.
  • You can delete your dashboard account, and everything it owns, with one request.

Where each request goes

LayerWhat leaves the deviceWhat is kept
On-device dictionaryNothingNothing
Precomputed results (shards)A request for one static file, named by the first letters of the queryNothing. Static files are not logged or metered.
Worker searchThe query, normalized and cut to 64 charactersThe normalized query with cache status, latency and scores, without app, key or IP. For keyed calls, also daily counts per app (see below).
Reaction suggestionsThe message text, cut to 256 charactersNothing. The text is never logged or cached.
Photo to emojiA small, downscaled imageWith an image hash, a short caption cached by that hash for up to 7 days. The image itself is dropped after use.

What is kept, and for how long

DataWhereKept
Per app, UTC day and normalized query: the number of searches and of misses. Keyed /v1/search calls only.D1 query_dailyBy the plan of the account that owns the app: Free 7 days, Solo 7 days, Pro 30 days, Scale 1 year. A daily job deletes older rows.
Normalized query text of every search that reached the Worker, with cache status, latency and scores. No app.Cloudflare Analytics Engine3 months (the Analytics Engine retention)
Monthly call counts per app and metricD1 usage_monthlyUntil the account is deleted
Waitlist: email address, plan and the date of the first sign-upD1 waitlist12 months after the first sign-up. A daily job deletes older rows.
Our own log records: event names, error types and counts. No query or message text, keys, IP addresses or emails.Cloudflare Workers LogsUp to 7 days. Invocation logs (full request URLs) are turned off.

Anonymous calls and development keys never reach the per-app table. The dashboard shows analytics only on plans that include them. The source of truth is the privacy section of the HTTP API reference.

Deleting an account

In the dashboard, Settings → “Delete account” (or DELETE /api/me, signed in, with the account email as confirm) deletes the account and everything it owns: apps, API keys, usage, search analytics, tenants, custom emoji (rows and images), webhooks, team members and invites, memberships in other teams, sessions and the waitlist entry of its email. The HTTP API reference has the details. Analytics Engine records are not linked to an account, so they expire on their own after 3 months.

How Emojisense uses queries

A nightly job reads only the queries that were seen at least 5 times. Rare strings can be personal, so they are never used. The frequent queries become precomputed results and new aliases, which make search better for every app.

Rate limits without tracking

Rate limits need to tell callers apart. The Worker and the waitlist use the IP address only as an in-memory key for the limiter. It is never written to logs or storage.

This website

  • No cookies, no analytics and no third-party scripts. Fonts are served from this site.
  • The live demos use the Emojisense API like any app. They load the data packs and send unsure searches. They send message text or a photo only when you try those demos, under the rules above.
  • The waitlist form sends your email and the plan you chose to the dashboard. The address is used only to tell you when the plan opens, and it is deleted after 12 months.