Privacy
Effective August 21, 2026
What is collected
To create a Ditty, the service receives your short message, optional sender name, selected feeling, a one-time anti-abuse token, and coarse request information needed for rate limiting. A recipient reaction or report is also stored when submitted.
How private content is stored
Message text and sender name are encrypted before being stored. Only a hash of each public share token and deletion token is stored for lookup. The synthetic voice file is stored under an unrelated opaque key.
Retention
A Ditty and its voice file expire after seven days. Deleting a Ditty removes the stored content sooner. Short-lived salted rate-limit records and report records may remain as needed to prevent abuse and review a safety report.
Providers
Cloudflare hosts the site, database, anti-abuse check, and voice inference. The browser creates the final instrumental mix locally. Ditty does not send your message to advertising networks and does not install third-party analytics on private listening pages.
Logs and analytics
Application code does not intentionally log message text, names, private share tokens, deletion tokens, or anti-abuse tokens. Aggregate infrastructure logs may contain standard request metadata for security and reliability.
Your controls
Use Delete on the creator result to remove a Ditty. Use Report on a received Ditty for privacy, harassment, hate, sexual-safety, or spam concerns. Because there is no account, the separate deletion token is the proof that you control a creation.
International use
The service is operated online and may process data in locations where Cloudflare provides its services. Do not submit highly sensitive information.