HoneyPot FAQ: Data, Discretion and What Cannot Be Proven
These answers cover three things: what HoneyPot necessarily receives when you chat, how to keep the visit invisible on a device other people use, and which claims about storage and handling cannot be checked by anyone outside the company. Terms are defined as they come up.
What the service receives
What does the company actually get when I send a message?
It gets the message itself, because a server has to read your words to write a reply. Alongside that it receives the ordinary technical details every website receives: an address that identifies your internet connection, the browser and device type, and the time of the request. This is standard for any hosted service, from a news site to a bank. The part that varies between companies is not what arrives but what is kept afterwards.
Does the site build a profile of me?
Some personalisation is unavoidable in a companion app, because remembering what you said last week is the feature people are paying for. That memory is a profile in the ordinary sense of the word. What you can influence is its size: switch off optional personalisation and marketing features, avoid feeding in details you would not want stored, and keep the account separate from your main email address.
Is the connection secure?
The link between your browser and the site is encrypted, which is what the padlock in the address bar indicates. It means nobody sharing your network, such as a household router or a public hotspot, can read your messages as they travel. It does not mean the operator cannot read them at the other end. Those two ideas get confused constantly, and the difference is the whole point of this page.
What cannot be verified from outside
Why will this site not tell me how long chats are stored?
Because we do not know, and inventing a number would be worse than admitting it. Retention periods, storage locations, which staff can look at what, and whether anything is shared with other companies are all internal matters. An outsider can read a stated policy and note whether it is specific or vague, but cannot confirm that practice matches the text. Any page giving you confident figures is guessing at best.
Would a certificate or an audit settle it?
Only partly, and only if you can see the document rather than a logo. Independent audits check that a company follows the processes it has written down; they do not promise that those processes are the ones you would have chosen. We make no claim here about whether this service holds any such certification, because we have no way to check one. The absence of proof is not evidence of misbehaviour, and it is not evidence of good behaviour either.
So what should I actually do with this uncertainty?
Reverse the question. Instead of asking how much a company can be trusted, decide what you would be relaxed about it holding, and keep your messages inside that boundary. Then handle the part you fully control: a separate email address, a private browser window, optional features switched off, and a cleanup afterwards. That approach survives a change of provider, a change of policy, and a change of mind.