Private Rooms

Private, expiring conversations for sensitive handoffs

Ask a follow-up, confirm receipt, and close the room without leaving a permanent chat history. Use Private Rooms when one secret link is not enough and the exchange still needs to expire.

Two ways to start

Use an invite link when the recipient only needs the room surface. Use a direct room when participants already have Shhhs access and the room should appear in their workspace view.

  • Invite link for focused room access
  • Optional room passphrase
  • Direct participant room
  • Pro 1:1; Pro workspaces and Enterprise group rooms

Standalone room links

A room link opens only the room, not the full workspace console. Production invites use chat.shhhs.net so mobile recipients get a focused PWA-style surface instead of the whole product console.

  • Focused recipient screen
  • Private route noindex
  • Preview-safe by default
  • chat.shhhs.net room surface

Encrypted messages with clear service records

Room messages are encrypted before upload. The Worker stores encrypted messages plus records needed for timestamps, status, limits, and participant references; those records must not include message plaintext.

  • Message plaintext is not stored by the Worker
  • Admin views stay metadata-only
  • No AI processing on room messages
  • Passphrase unlock stays client-side

Limits are part of the product

Private Rooms are intentionally bounded. Pro is limited to 1:1 rooms, while Pro workspaces and Enterprise can create group rooms with explicit participant and message limits.

  • Pro: 10 active 1:1 rooms, 250 messages per room, 2 participants
  • Workspace: 50 active group rooms, 500 messages per room, 10 participants
  • Enterprise: 200 active group rooms, 1,000 messages per room, 25 participants

Where Private Rooms fit

Use Private Rooms when a credential handoff needs questions, confirmation, or short back-and-forth: a client sends access, an operator asks one follow-up, or an agent-assisted workflow needs a bounded place to coordinate.

  • Client credential clarification
  • Vendor onboarding
  • Password reset coordination
  • Incident access handoff
  • Agentic secret exchange

Mobile path before native apps

Standalone room links are the first mobile surface: a participant opens only the room on a phone, without the full console. Native apps can later build on the same temporary-room contract.

  • Open only the room surface
  • Temporary room handoff
  • PWA/deep-link friendly

Not a replacement for team chat

Slack, Teams, WhatsApp, and email are built for memory, search, previews, and forwards. Shhhs Private Rooms are for short sensitive exchanges that should expire.

  • Temporary encrypted chat
  • No permanent team history
  • No message previews
  • Designed for sensitive follow-up

FAQ

Is Shhhs Private Rooms a normal chat app?

No. It is a short-lived encrypted handoff room for secrets and operational context, not a permanent messenger.

Can Shhhs read room messages?

Room message content is encrypted locally before upload. The server stores ciphertext and service records only; optional room passphrases are used client-side to unlock the room key.

Can a recipient open only the room?

Yes. A standalone room link opens the room experience without loading the full Shhhs console.

When should I use a Private Room instead of Send?

Use Send for one-way delivery. Use a Private Room when the secret handoff needs short, temporary back-and-forth.