A straightforward privacy note.

Totem is a free project by Vincent Pribble. This note describes the first Sites-hosted version, updated September 27, 2026.

What Totem stores

Your display name, random profile identifier, passkey credential identifier and public key, passkey counter and provider backup metadata, session records, paired contacts, private contact labels, pairing method, the date of an in-person confirmation, and check outcomes. Totem never receives your private key or biometric data. There is no address-book upload, phone number, microphone access, advertising, or analytics integration.

Optional camera scanning

If you choose to scan a pairing code, Totem asks for camera permission. QR codes are read on your device. Camera images are not recorded, uploaded, or stored. Only the invitation token is sent to Totem to continue pairing. The camera stops when a code is accepted, you leave the scanner, or you put Totem in the background.

Temporary words and invitations

QR pairing invitations last five minutes; shared invitation links last 24 hours. Each invitation can be accepted by one person. Pairing words are cleared when the invitation completes, is canceled, or expires. Check requests allow two minutes for approval, then a separate two minutes to compare words. Check phrases are available only to the two participants during comparison. They are erased when a check ends or its expiry is processed and never appear in history. Expiry blocks access immediately.

Storage and retention

Application data is stored in the site’s managed relational database. Development data is separate from production. A maintenance task runs at most hourly when the app receives traffic. It deletes outcomes older than 30 days, expired sessions, and invitations and challenges expired for more than a day. If no one uses the site, cleanup waits for the next request; expiry still blocks access immediately.

Session cookies are secure, HTTP-only, and valid for at most 30 days. Sign-out revokes your current session. A separate temporary cookie binds a passkey prompt to your browser. A pending invitation token may be held in your tab’s session storage while you sign in and is removed after it is claimed. A link you create is also held in that tab’s session storage so you can share it again while it remains open. Its local copy is removed when you view its completed, canceled, or expired state. Invitation tokens are stored as hashes on the server.

Optional notifications

If you enable alerts, Totem stores your browser’s push subscription address and encryption keys, linked to your profile and current session. Your browser’s push provider (such as Apple, Google, Mozilla, or Microsoft) delivers encrypted alerts. Alerts contain a check identifier and expiration time, never names, contact labels, or comparison words.

Turn off notifications in Settings to remove this device’s subscription. Sign-out removes subscriptions linked to that session; deleting your profile removes all of them. Expired sessions are excluded from delivery immediately and removed during cleanup. The home-screen app caches only public icons and an offline message, not your contacts, checks, or words.

Feedback

Feedback includes the category, message, optional reply email, and submission time. It is private and retained for up to 12 months, subject to the same traffic-triggered cleanup. A hash of the connection IP is used for short-lived rate limiting; feedback records do not contain that hash. Feedback is independent of your Totem profile.

Deleting your profile

Settings → Delete profile requires a fresh passkey approval. It removes your profile, credential registration, sessions, associated pairings, invitations, and checks. Your contacts lose access to the old pairing. Independently submitted feedback is not automatically linked or deleted.

Hosting and access

This site is publicly accessible through ChatGPT Sites. Your contacts and checks still require your Totem passkey and an authenticated session. The hosting provider also processes the technical data needed to deliver and protect the site. Totem’s server is trusted to validate credentials and manage checks; this is not server-independent verification.

Questions?

Use the feedback form. Don’t include passkeys, check phrases, or private information about another person.

Back to Totem