Skip to article
Platform / Privacy

Privacy

What Emojisense stores, what it never stores, and why.

On this page

The short version

  • Most searches never leave the device.
  • Emojisense never logs or stores IP addresses or the identifiers of your users. API keys are stored only as a SHA-256 hash and their first 12 characters, and never logged.
  • Message text for reaction suggestions and images for photo to emoji are never stored.
  • Query text is cut to 64 characters and stored only in its normalized form. A query is named in analytics, or used by Emojisense’s own jobs, only after it was seen at least 5 times. It is published in the precomputed results only when apps of at least 3 different accounts searched it.
  • You can delete your dashboard account, and everything it owns, with one request.

Where each request goes

LayerWhat leaves the deviceWhat is kept
On-device dictionaryNothingNothing
Precomputed results (shards)A request for one public file, named by the first letters of the queryNothing. These requests are not logged or metered.
Worker searchThe query, lowercased and cut to 64 characters. Accents and punctuation stay, because the meaning model reads them.The normalized query with cache status, latency and scores, without app, key or IP. For keyed calls, also daily counts per app (see below).
Reaction suggestionsThe message text. The API reads only its first 256 characters.Nothing. The text is never logged or cached.
Photo to emojiA small, downscaled imageWith an image hash, the model’s label (caption, reaction, keywords and proposed emoji) cached by that hash for up to 7 days. The image itself is dropped after use.

What is kept, and for how long

DataWhereKept
Per app, UTC day and normalized query: the number of searches and of misses. Keyed /v1/search calls only.D1 query_dailyBy the plan of the account that owns the app: Free 7 days, Solo 7 days, Pro 30 days, Scale 1 year. A daily job deletes older rows.
Normalized query text of every search that reached the Worker, with cache status, latency and scores. No app.Cloudflare Analytics Engine3 months (the Analytics Engine retention)
Precomputed results: normalized query text and its emoji, for queries that pass the rules below. No app, account, day or count.Cloudflare R2 and edge cache, publicRebuilt every night. A query leaves with the first build after it no longer passes.
Monthly call counts per app and metricD1 usage_monthlyUntil the account is deleted
Custom emoji: shortcode, aliases, size, source and the imageD1 and R2Until the emoji, its tenant or the account is deleted. Edge caches can hold a copy of the image until it is evicted.
Tenants: your external id and optional name for each of your customersD1 tenantsUntil you delete the tenant or the account
Webhook deliveries: event type, HTTP status, duration and time. No body and no response.D1 webhook_deliveriesThe last 50 per webhook
Accounts (name and verified email), apps, keys (a hash and the first 12 characters), team members and webhooksD1Until the account is deleted. Revoked keys stay, marked as revoked. Sign-in sessions live at the sign-in provider; the dashboard stores none.
Waitlist: email address, plan and the date of the first sign-upD1 waitlist12 months after the first sign-up. A daily job deletes older rows.
Our own log records: event names, error types and counts. No query or message text, keys, IP addresses or emails.Cloudflare Workers LogsUp to 7 days. Invocation logs (full request URLs) are turned off.

Anonymous calls and development keys never reach the per-app table. The dashboard shows analytics only on plans that include them. The source of truth is the privacy section of the HTTP API reference.

Deleting an account

In the dashboard, Settings → “Delete account” (or DELETE /api/me, signed in, with the account email as confirm) deletes the account and everything it owns: apps, API keys, usage, search analytics, tenants, custom emoji (rows and images), webhooks, team members and invites, memberships in other teams and the waitlist entry of its email. Then the dashboard deletes the sign-in profile at Clerk, the sign-in provider. The HTTP API reference has the details. Analytics Engine records are not linked to an account, so they expire on their own after 3 months.

How Emojisense uses queries

Precomputed results: every night a job reads the per-app daily counts in aggregate. It publishes a query only when apps of at least 3 different accounts searched it at least 10 times in total over the last 6 full days, and only when it does not look like personal data: an email or web address, a phone, account or postal number, a user id or a long token. The public files hold the query text and its emoji, and nothing about apps, accounts, days or counts. Anonymous calls and development keys are never counted, so they cannot put a text there.

New aliases: a job reads only the queries that were seen at least 5 times. Rare strings can be personal, so they are never used. Both make search better for every app.

Rate limits without tracking

Rate limits need to tell callers apart. The Worker and the waitlist use the IP address only as an in-memory key for the limiter. It is never written to logs or storage.

This website

  • No cookies, no analytics and no third-party scripts. Fonts are served from this site.
  • The live demos use the Emojisense API like any app. They load the data packs and send unsure searches. They send message text or a photo only when you try those demos, under the rules above.
  • The waitlist form sends your email and the plan you chose to the dashboard. The address is used only to tell you when the plan opens, and it is deleted after 12 months.