Privacy policy
How secure-chat handles your information: what we collect, why, who it's shared with, how long it's kept, and your rights.
The short version
Your messages are end-to-end encrypted: they are locked on your device and only the people in the conversation can read them. We can't read them, and neither can our hosting providers. To run the service we do keep some account and technical information, such as your email address, your profile, who you talk to and when, and the devices you're signed in on. This page explains all of it.
1. Who we are
secure-chat (secure-chat.uk) is run by an independent developer based in the United Kingdom, who is the “controller” of your personal data under UK data protection law (the UK GDPR and the Data Protection Act 2018). For any privacy question, email [email protected].
2. What we collect
Your account
- Sign-up details: username, email address and a password. We store only a salted hash of the password (bcrypt), never the password itself.
- Profile: display name, avatar, banner, bio, status and social links, if you choose to add them. Other users can see your profile.
- Settings: your theme, language, privacy and notification choices, saved so they follow you between devices.
- Plan: whether your account is on the free or Pro plan.
- Encryption keys: your public keys, and your private keys in encrypted form. The private keys are locked with your password or PIN on your device before they are uploaded, so we can't use them.
Using secure-chat
- Messages and files: stored in encrypted form so they can be delivered and synced across your devices. Chat attachments are encrypted on your device before upload. The file name and size may be visible to us.
- Conversation information (metadata): who is in a chat or group, who sent a message to whom and when, message type, reactions, read state, friend lists, and call history (who called whom, when, and for how long). We need this to deliver messages and show your chat list.
- Profile images: avatars and banners are public, so they are not end-to-end encrypted. Images are resized and re-encoded when uploaded, which also strips embedded data such as location (EXIF).
- Presence: online status and “last seen”, which you can limit in Settings.
- Sign-in sessions: for each device you sign in on, we store the IP address, browser/device type and when it was last active. You can see and sign out of these in Settings → Security.
- Push notifications: if you turn them on, your browser's push address. Notifications say “New encrypted message” and never include what the message says.
- Support and reports: tickets you open, your messages to support, and reports you make about other users, along with any action moderators take.
Theatre and watch parties
A watch party (the video, queue, playback position and party chat) is kept in server memory only while people are in it, and is deleted shortly after the last person leaves. Pro users can save playlists, which are stored until deleted. YouTube searches go through our server, which caches results (not linked to you) to reduce calls to YouTube.
Calls
Voice and video calls, including screen sharing, are peer-to-peer and encrypted in transit (WebRTC, DTLS-SRTP). If a direct connection isn't possible, the encrypted stream is relayed through Cloudflare's TURN service, which can't decrypt it. We do not record calls.
Link previews
When you send a link, the app asks our server to fetch the page's title, description and image so it can show a preview. That means our server sees the link itself. The preview is cached by web address and is not linked to you or your conversation.
Technical and security data
Like every website, our servers and Cloudflare process your IP address and browser details to deliver pages, stop abuse (rate limiting, and a Cloudflare Turnstile check when you sign up or sign in) and fix errors. Server logs are kept for a short time.
3. What we can't see
4. Why we use it (lawful bases)
| Purpose | Lawful basis |
|---|---|
| Creating your account and delivering messages, calls, groups and watch parties | Contractwe need it to provide the service you signed up for |
| Sign-in security, rate limiting, bot checks, abuse reports and moderation | Legitimate interestskeeping users and the service safe |
| Account emails (verification codes, password resets) | Contract |
| Push notifications | Consentyou turn them on, and you can turn them off at any time |
| Support tickets | Contractand legitimate interests |
| Responding to lawful requests from authorities | Legal obligation |
We don't use your data for advertising or profiling, and we don't sell it.
5. Services we rely on
These providers process data for us, or are contacted by your browser when you use a feature:
| Provider | What for | What they receive |
|---|---|---|
| Cloudflare | Website hosting and CDN, bot checks (Turnstile), call relays (TURN), and cookieless, aggregate page analytics (Web Analytics) | IP address, browser details, pages requested; encrypted call traffic when relayed |
| one.com (Denmark, EU) | Hosting our servers, databases and sign-in service (a private server we run) | Everything we store, as described above (messages remain encrypted) |
| Resend | Sending account emails | Your email address and the email's content (e.g. a verification code) |
| Your browser's push service (Google, Apple, Mozilla or Microsoft) | Delivering push notifications | A push address and a notification that doesn't include message content |
| Klipy and GIPHY | GIF search and display | Your search terms and IP address, sent straight from your browser |
| YouTube (Google) | Playing videos in the Theatre, and thumbnails | Your IP address and viewing activity for the embedded player, under Google's privacy policy |
| DiceBear | Generated default avatars | A random seed (not your name) and your IP address |
| Flagpedia (flagcdn.com) | Flag icons in the language picker | Your IP address |
Some providers may process data outside the UK. Where they do, we rely on UK adequacy regulations or the UK International Data Transfer Agreement / Addendum.
6. How long we keep it
- Account and profile: until you delete your account.
- Messages and files: until you or the other person delete them, the conversation is cleared, or a disappearing-message timer runs out.
- Watch parties: deleted shortly after the last person leaves.
- Sign-in sessions: until you sign out, the session expires, or you remove it in Settings.
- Email verification codes: until used or expired.
- Support tickets and moderation records: as long as needed to handle them and keep the service safe.
- Backups: overwritten on a rolling basis.
7. On your device
We don't use cookies. The app stores these in your browser's local storage:
- your sign-in token;
- your settings, such as theme and language;
- your encryption keys, held in the browser's key store (IndexedDB);
- a cache of recent chats for faster loading.
Signing out clears the sign-in token. Clearing your browser's site data removes everything.
8. Your rights
Under UK data protection law you can ask to:
Email [email protected]. We'll reply within one month. If you're unhappy with how we handle your data, you can complain to the Information Commissioner's Office: ico.org.uk.
9. Security
Messages are encrypted using ECDH key agreement and AES-256-GCM. All traffic uses HTTPS, and passwords are hashed with bcrypt. No system is perfect: if a breach affects your data, we'll tell you and the ICO where the law requires it.
10. Children
secure-chat is not for children under 13. If you believe a child under 13 has an account, contact us and we'll delete it.
11. Changes
If we change this policy, we'll update the date at the top. If the change is significant, we'll also tell you in the app.
12. Contact
Questions about this policy or your data? We're happy to help.