Legal
Privacy
In effect from 21 August 2026
The short version.
We do not know who you are. There is no account, no password, no email address and no phone number — who you are in the app is a key your phone generates and keeps. Messages are deleted after 72 hours. We keep records of bans and reports for longer, because a safety record that deletes itself is not one.
The rest of this page is the same thing said exactly.
Who we are
ChatKiwi is made by Alcyon Internet Solutions, a sole proprietorship registered in the Netherlands under KvK number 32068352. Alcyon Internet Solutions is the data controller for everything described here.
Write to us at legal@chatkiwi.app. For anything about a child's safety, use safety@chatkiwi.app, which is read first and separately.
What is live today
The app is not released. Today this website does one thing that touches your data: it takes an email address for the launch list. Everything under What the app collects below describes the service as it is built and as it will behave the day the app ships. It is here now because you are entitled to read it before you decide to be on a list, not because it is happening to you yet.
Some of what is described below is not running yet, and each thing that is not is marked where it appears. A list you join today should not be joined on a sentence we already know is not true of the app you are waiting for. Here they are together.
- Advertising is the one we know we are going to build, and it is the one that makes a line below stop being true rather than start.
- Images in private conversations. No image can be sent on this server, and none will be until every image can be checked against known child sexual abuse material first. That check needs a hash-sharing programme to admit us, which is not our decision to make.
- The automated check that reads what people write. It is built and it is switched off. Turning it on needs a prior consultation with the Autoriteit Persoonsgegevens, and what it may read is part of what that consultation decides — so this page does not yet say which conversations it covers, because we do not yet know.
The launch list
If you give us your email address on this site, we store three things: the address, the moment you gave it, and a random token that identifies your row so you can have it deleted.
- We use it once, to tell you the app is out. There is no newsletter and no second email.
- We keep it for 365 days, or until you ask us to delete it, or until we send that one message — whichever comes first.
- It goes to no one else. It is not on a mailing platform, not enriched, not matched against anything, and not used to advertise.
- It is kept in its own part of our database, apart from everything the app stores, so that a request about one does not have to reach into the other. That is a separation we keep rather than one a machine enforces, and it is the same kind every other sort of record here has — this list is not walled off, it is just never mixed in.
Every message we send carries a link that deletes your address. You can also ask at legal@chatkiwi.app.
We ask for an address and do not confirm it by mail, so somebody could type in an address that is not theirs. If you got a message from us you did not ask for, the link in it removes the address without you having to talk to us.
What the app collects
Your identity is a key, and the key never leaves your phone. When you first open the app it generates a keypair. It sends us the public half; we hash that into an identifier and that identifier is who you are to us. We cannot turn it back into anything about you, we never see the private half, and if you lose your phone that identity is gone — there is no recovery, because there is nothing to recover it from.
Here is everything the service keeps, where it lives, and for how long.
| What | How long |
|---|---|
| What you write. Message bodies, in a room and in a private conversation, and any image you send in a private conversation. No image can be sent yet — the clocks beside this row are what will hold when one can | 72 hours After 72 hours no new link to an image is issued, and any link already issued expires within five minutes; the bytes are erased within 78. Why there are two numbers is below. |
| Your identifier and the name you picked. The hash of your key, the nickname you wear and the number after it | Until you delete it. The nickname is released back to the pool |
| Who you talked to. That two devices had a conversation, who asked, and when it was last used — not what was said | 30 days after the last message. An unanswered request goes in 7 days |
| Your connections. Your identifier, the IP address a connection came from, and when it opened and closed. No message content | 90 days |
| Notifications. One delivery credential per device, from Apple or Google, if you turn notifications on | 60 days after the app last refreshed it |
| Your avatar. If you set one: the face you picked, your gender, the age you entered and your bio. Everyone in the rooms you are in can see them. We do not use the age your app store may share with us for this | 7 days after the app last signed in, or until you delete it. Your phone keeps its own copy and sends it again when it signs in |
| Reports. A report somebody filed, and the copy of the reported message we took when it arrived — including who wrote it, and their avatar's face and bio at that moment | 180 days from the report |
| Safety training data. Where a reviewer has judged a reported message, we keep the message and what they judged it to be, so that the automated check that reads what people write can be trained and corrected. Nothing in this copy says who wrote it — not your identifier, and not a hash of it. That check is not running yet — this copy is taken so that it can be corrected on the day it does, and a check trained on nothing is the reason it is taken now rather than then | 24 months from the day we copy it |
| What we did and why. If we act against you, the statement of reasons telling you what we did and on what ground | 180 days from the notice |
| Safety records. Bans, blocks, report history, and the date a device first registered | Indefinitely. A ban that expires is a ban that stops working |
| An age band. Whether your app store told us you are over or under 18, and nothing more — no date of birth. Most devices have no such record at all | Indefinitely |
| Preserved evidence. If we are legally required to keep a conversation for the authorities, a copy of it and the account of who authorised that | 90 days, or 1 year where a report to child-protection authorities requires it |
What we do not collect
This list is as much of the policy as the one above, so it is stated rather than implied.
- No name, email address or phone number for using the app. The app never asks and there is nowhere to put one.
- No contacts, no address book, no photo library scan. An image is only ever one you chose to send.
- No location. We read the country an IP address is in to know whether we may serve you at all, and we do not store the country against you — only a running count per country.
- No advertising identifier and no tracking — today. There is no ad SDK in the app and nothing here is used to profile you or follow you between apps. This is the one line in this list that is not also true of the released app, so it is said here rather than left for you to discover: the free app will carry advertising. Never in a direct message and never interrupting a conversation — a banner in the room list and one below the message composer, and a paid tier that removes them. When that ships, an advertising identifier and the tracking that comes with it become true of the app; nothing will be personalised to you unless you say yes when we ask, and this page will say so before the app does it.
- No analytics SDK and no session recording. We count how many launches reached each step of first setup, in whole numbers, on our own servers. Those counts are not attached to anyone.
- No crash-reporting SDK. Crash reports reach us through Apple's and Google's own developer tools, under the setting you control in your phone's settings, and carry nothing of ours.
- No cookies on this website beyond the one that makes our two forms work — the waitlist form on the front page, and the unsubscribe form the link in our email leads to. Reading this policy sets nothing at all. That cookie carries no identifier, follows you nowhere, and is gone when you close the browser.
Why we are allowed to keep it
Under the GDPR, each of the things above rests on one of these grounds.
- Because you asked us to. Your consent, for the launch list. You can withdraw it at any time and the link in our message is how.
- Because it is the service. Delivering a message, holding a room's recent history, reaching your phone with a notification — none of that is possible without doing it.
- Because a chat service that cannot act on abuse is not safe to run. Bans, blocks, reports, connection records, and the moderation decisions behind them. This is our legitimate interest and yours, and it is why the safety records outlive the messages.
- Because the law requires it. Preserving material for child-protection and law-enforcement processes, telling you why we acted against you, and keeping minors off the service.
Who else sees it
We do not sell your data. Today nothing about you leaves us for advertising, and there are exactly three ways anything leaves us at all. The advertising above adds a fourth the day it ships: an ad network is told enough to put an ad on a screen, which is an identifier for a phone and never what you wrote. Every network we use will be named here before it serves anything.
- Our host. The service runs on Fly.io, on machines in Amsterdam. Fly.io stores what we store and does nothing else with it.
- Your phone's notification service. If you turn notifications on, Apple or Google delivers them. They are told a notification is due; the message itself is not in it.
- Authorities, when we must. A valid legal request, or a report of child sexual abuse material, which we are obliged to make and do make. We give what the request reaches and no more — our records are kept in separate stores so that a request for connection records cannot come back carrying what people wrote.
Under 18s
ChatKiwi is for adults. If your app store tells us you are under 18, the app refuses to register and there is nothing to opt out of. If you believe a child is using the service, write to safety@chatkiwi.app.
Your rights
You have the right to see what we hold about you, to correct it, to have it deleted, to object to how we use it, and to take it elsewhere.
How you use them here is unusual, and it is a consequence of the design. We cannot identify you from an email, because we have never had one. So the app itself carries the door: it asks us to delete everything held under your identifier and proves the request is yours by signing it with the key on your phone. Nobody else can make that request about you, and we cannot make it on your behalf.
In the app, it's the last item on your profile: Delete my data. If you've removed the app from an iPhone, install it again: it comes back as the same person, and you can delete from there. On Android the key is removed with the app, so nothing can prove a request is yours any more. What we held under it is then deleted by the clocks above.
For an address on the launch list, the unsubscribe link is the same door — the token in it is the proof, because there is nothing else about you to prove.
Some things survive a deletion request, and we would rather say so here than surprise you.
- A ban stays enforceable. We keep an irreversible hash rather than your identifier — enough to recognise the ban if the same device returns, not enough to identify you or to find you in anything else.
- A moderator's decisions about you, and your appeals, stay. They are our account of what we did and why, so they are kept with your identifier replaced by a hash. What you wrote in an appeal is deleted.
- Reports you made stay. A report is a statement about somebody else, so it is kept with your identifier replaced by a hash. What you wrote in it is deleted.
- Your messages that somebody reported stay, for up to 180 days. They are the evidence in that report, with your identifier replaced by a hash. If a deletion request could remove them, it would be a way to destroy the evidence against you.
- Blocks other people placed on you stay. They are kept with your identifier replaced by a hash, so that deleting your data is not a way back into somebody's messages.
- Material under a legal hold stays until the hold expires. If we have been required to preserve something, deleting it on request is not ours to do.
- A message already copied into our safety training data stays. The copy carries no identifier — not yours, not a hash of it — so there is nothing in it for us to match your request against, and no way for us to find which rows were yours. It goes on its own 24-month clock instead.
Everything else goes. If you want to exercise a right and the door in the app does not fit what you are asking, write to legal@chatkiwi.app and we will answer within a month.
If you think we have got this wrong, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens. We would rather you told us first, but you do not have to.
Where it is kept, and how
In Amsterdam, in the European Union. Everything travels encrypted. Message bodies live in a store that deletes them on a timer rather than in a database we sweep later, which is why the 72 hours is a property of the store rather than a promise about our diligence.
Images are the one exception worth stating exactly, because an image store has no timer of its own. At 72 hours we stop issuing links to an image — no new one is handed out past that point, whatever else is running — and any link already handed out expires within five minutes. The bytes themselves are erased by a sweep that passes every six hours after that, so an image is erased within 78 hours of being sent. We state both numbers because only the first is a property of the store; the second is a property of a job we run, and a job can be late.
Only two people can look at preserved material, and it takes both of them: one to ask and a second to approve. Every such look is written to a log that cannot be edited and that outlives the material it describes.
When this changes
The date at the top is the date this version took effect. If we change something that matters — a new kind of data, a longer clock, a new recipient — we will change that date and say what moved. If you are on the launch list when it happens, that is not what your one message will be about; you will find it here.