Legal

Privacy

In effect from 21 August 2026

The short version.

We do not know who you are. There is no account, no password, no email address and no phone number — who you are in the app is a key your phone generates and keeps. Messages are deleted after 72 hours. We keep records of bans and reports for longer, because a safety record that deletes itself is not one.

The rest of this page is the same thing said exactly.

Who we are

ChatKiwi is made by Alcyon Internet Solutions, a sole proprietorship registered in the Netherlands under KvK number 32068352. Alcyon Internet Solutions is the data controller for everything described here.

Write to us at legal@chatkiwi.app. For anything about a child's safety, use safety@chatkiwi.app, which is read first and separately.

What is live today

The app is not released. Today this website does one thing that touches your data: it takes an email address for the launch list. Everything under What the app collects below describes the service as it is built and as it will behave the day the app ships. It is here now because you are entitled to read it before you decide to be on a list, not because it is happening to you yet.

Some of what is described below is not running yet, and each thing that is not is marked where it appears. A list you join today should not be joined on a sentence we already know is not true of the app you are waiting for. Here they are together.

The launch list

If you give us your email address on this site, we store three things: the address, the moment you gave it, and a random token that identifies your row so you can have it deleted.

Every message we send carries a link that deletes your address. You can also ask at legal@chatkiwi.app.

We ask for an address and do not confirm it by mail, so somebody could type in an address that is not theirs. If you got a message from us you did not ask for, the link in it removes the address without you having to talk to us.

What the app collects

Your identity is a key, and the key never leaves your phone. When you first open the app it generates a keypair. It sends us the public half; we hash that into an identifier and that identifier is who you are to us. We cannot turn it back into anything about you, we never see the private half, and if you lose your phone that identity is gone — there is no recovery, because there is nothing to recover it from.

Here is everything the service keeps, where it lives, and for how long.

What How long
What you write. Message bodies, in a room and in a private conversation, and any image you send in a private conversation. No image can be sent yet — the clocks beside this row are what will hold when one can 72 hours After 72 hours no new link to an image is issued, and any link already issued expires within five minutes; the bytes are erased within 78. Why there are two numbers is below.
Your identifier and the name you picked. The hash of your key, the nickname you wear and the number after it Until you delete it. The nickname is released back to the pool
Who you talked to. That two devices had a conversation, who asked, and when it was last used — not what was said 30 days after the last message. An unanswered request goes in 7 days
Your connections. Your identifier, the IP address a connection came from, and when it opened and closed. No message content 90 days
Notifications. One delivery credential per device, from Apple or Google, if you turn notifications on 60 days after the app last refreshed it
Your avatar. If you set one: the face you picked, your gender, the age you entered and your bio. Everyone in the rooms you are in can see them. We do not use the age your app store may share with us for this 7 days after the app last signed in, or until you delete it. Your phone keeps its own copy and sends it again when it signs in
Reports. A report somebody filed, and the copy of the reported message we took when it arrived — including who wrote it, and their avatar's face and bio at that moment 180 days from the report
Safety training data. Where a reviewer has judged a reported message, we keep the message and what they judged it to be, so that the automated check that reads what people write can be trained and corrected. Nothing in this copy says who wrote it — not your identifier, and not a hash of it. That check is not running yet — this copy is taken so that it can be corrected on the day it does, and a check trained on nothing is the reason it is taken now rather than then 24 months from the day we copy it
What we did and why. If we act against you, the statement of reasons telling you what we did and on what ground 180 days from the notice
Safety records. Bans, blocks, report history, and the date a device first registered Indefinitely. A ban that expires is a ban that stops working
An age band. Whether your app store told us you are over or under 18, and nothing more — no date of birth. Most devices have no such record at all Indefinitely
Preserved evidence. If we are legally required to keep a conversation for the authorities, a copy of it and the account of who authorised that 90 days, or 1 year where a report to child-protection authorities requires it

What we do not collect

This list is as much of the policy as the one above, so it is stated rather than implied.

Why we are allowed to keep it

Under the GDPR, each of the things above rests on one of these grounds.

Who else sees it

We do not sell your data. Today nothing about you leaves us for advertising, and there are exactly three ways anything leaves us at all. The advertising above adds a fourth the day it ships: an ad network is told enough to put an ad on a screen, which is an identifier for a phone and never what you wrote. Every network we use will be named here before it serves anything.

Under 18s

ChatKiwi is for adults. If your app store tells us you are under 18, the app refuses to register and there is nothing to opt out of. If you believe a child is using the service, write to safety@chatkiwi.app.

Your rights

You have the right to see what we hold about you, to correct it, to have it deleted, to object to how we use it, and to take it elsewhere.

How you use them here is unusual, and it is a consequence of the design. We cannot identify you from an email, because we have never had one. So the app itself carries the door: it asks us to delete everything held under your identifier and proves the request is yours by signing it with the key on your phone. Nobody else can make that request about you, and we cannot make it on your behalf.

In the app, it's the last item on your profile: Delete my data. If you've removed the app from an iPhone, install it again: it comes back as the same person, and you can delete from there. On Android the key is removed with the app, so nothing can prove a request is yours any more. What we held under it is then deleted by the clocks above.

For an address on the launch list, the unsubscribe link is the same door — the token in it is the proof, because there is nothing else about you to prove.

Some things survive a deletion request, and we would rather say so here than surprise you.

Everything else goes. If you want to exercise a right and the door in the app does not fit what you are asking, write to legal@chatkiwi.app and we will answer within a month.

If you think we have got this wrong, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens. We would rather you told us first, but you do not have to.

Where it is kept, and how

In Amsterdam, in the European Union. Everything travels encrypted. Message bodies live in a store that deletes them on a timer rather than in a database we sweep later, which is why the 72 hours is a property of the store rather than a promise about our diligence.

Images are the one exception worth stating exactly, because an image store has no timer of its own. At 72 hours we stop issuing links to an image — no new one is handed out past that point, whatever else is running — and any link already handed out expires within five minutes. The bytes themselves are erased by a sweep that passes every six hours after that, so an image is erased within 78 hours of being sent. We state both numbers because only the first is a property of the store; the second is a property of a job we run, and a job can be late.

Only two people can look at preserved material, and it takes both of them: one to ask and a second to approve. Every such look is written to a log that cannot be edited and that outlives the material it describes.

When this changes

The date at the top is the date this version took effect. If we change something that matters — a new kind of data, a longer clock, a new recipient — we will change that date and say what moved. If you are on the launch list when it happens, that is not what your one message will be about; you will find it here.