Privacy Policy
Last updated: July 31, 2026
The short version: Your message content is end-to-end encrypted. We cannot read your messages or files — not now, not ever. We collect only the minimum account information needed to operate the service.
1. Who we are
PrivaChat ("we", "us", "our") is an end-to-end encrypted messaging service. Our server is operated at api.privachat.io and the web application is available at app.privachat.io.
2. What data we collect
We collect the minimum amount of data required to operate the service:
- Email address — used for account verification and password reset. Never sold or shared with third parties for marketing.
- Handle (username) — your chosen display name within the app.
- Public encryption keys — your X25519 and Ed25519 public keys, used by other users to encrypt messages to you. Public keys are, by definition, not secret.
- Encrypted message metadata — sender ID, recipient ID, and timestamp of messages in transit. We do not store DM message content.
- Encrypted file blobs — files you send are stored server-side as opaque ciphertext we cannot decrypt. They are retained until the recipient downloads them.
- Encrypted channel messages — channel message history is stored as ciphertext on the server for history replay. The server cannot decrypt this content.
- IP address and basic server logs — retained for up to 30 days for security and abuse prevention.
3. What we cannot access
Due to the end-to-end encryption architecture, the following is mathematically inaccessible to us:
- Your private encryption keys (generated on your device, never transmitted)
- The plaintext content of any direct message
- The plaintext content of any channel message
- The plaintext content of any file or media attachment
- Your password (we store only a bcrypt hash)
4. How we use your data
- To operate and deliver the messaging service
- To send email verification and password reset emails via AWS SES
- To enforce account uniqueness (email and handle must be unique)
- To investigate abuse reports when legally required
We do not use your data for advertising, profiling, or sale to third parties.
5. Data storage and security
Data is stored on AWS infrastructure in the United States (us-west-2 region) on persistent encrypted EFS volumes. All data in transit is protected by TLS 1.2 or higher. Access to production systems is restricted to authorised administrators only.
6. Data retention
- Account data (email, handle, public keys) is retained until you request deletion.
- Direct messages are not stored server-side after delivery (or offline queue delivery on reconnect).
- Channel message history is stored until the channel or community is deleted.
- Server logs are retained for up to 30 days.
7. Third-party services
We use the following third-party services to operate PrivaChat:
- Amazon Web Services (AWS) — compute (ECS Fargate), storage (S3, EFS), CDN (CloudFront), and email delivery (SES). AWS is bound by their own privacy and security certifications.
No analytics, tracking, or advertising SDKs are included in PrivaChat.
8. Your rights
You have the right to:
- Request a copy of the personal data we hold about you
- Request deletion of your account and associated personal data
- Correct inaccurate data (e.g. email address)
To exercise these rights, contact us at privacy@privachat.io.
9. Children
PrivaChat is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has registered, please contact us and we will delete the account promptly.
10. Changes to this policy
We may update this policy from time to time. We will notify registered users of material changes via email. The "last updated" date at the top of this page reflects the most recent revision.
11. Contact
Questions about this policy: privacy@privachat.io