Legal
Privacy
In effect from 21 August 2026
The short version.
We do not know who you are. There is no account, no password, no email address and no phone number — who you are in the app is a key your phone generates and keeps. Messages are deleted after 72 hours. We keep records of bans and reports for longer, because a safety record that deletes itself is not one.
The rest of this page is the same thing said exactly.
Who we are
ChatKiwi is made by Alcyon, a sole proprietorship registered in the Netherlands. Alcyon is the data controller for everything described here.
Write to us at legal@chatkiwi.app. For anything about a child's safety, use safety@chatkiwi.app, which is read first and separately.
What is live today
The app is not released. Today this website does one thing that touches your data: it takes an email address for the launch list. Everything under What the app collects below describes the service as it is built and as it will behave the day the app ships. It is here now because you are entitled to read it before you decide to be on a list, not because it is happening to you yet.
The launch list
If you give us your email address on this site, we store three things: the address, the moment you gave it, and a random token that identifies your row so you can have it deleted.
- We use it once, to tell you the app is out. There is no newsletter and no second email.
- We keep it for 365 days, or until you ask us to delete it, or until we send that one message — whichever comes first.
- It goes to no one else. It is not on a mailing platform, not enriched, not matched against anything, and not used to advertise.
- It is stored in its own database, kept apart from everything else here, precisely so that it cannot be handed over with anything else.
Every message we send carries a link that deletes your address. You can also ask at legal@chatkiwi.app.
We ask for an address and do not confirm it by mail, so somebody could type in an address that is not theirs. If you got a message from us you did not ask for, the link in it removes the address without you having to talk to us.
What the app collects
Your identity is a key, and the key never leaves your phone. When you first open the app it generates a keypair. It sends us the public half; we hash that into an identifier and that identifier is who you are to us. We cannot turn it back into anything about you, we never see the private half, and if you lose your phone that identity is gone — there is no recovery, because there is nothing to recover it from.
Here is everything the service keeps, where it lives, and for how long.
| What | How long |
|---|---|
| What you write. Message bodies, in a room and in a private conversation, and any image you send in a private conversation | 72 hours |
| Your identifier and the name you picked. The hash of your key, the nickname you wear and the number after it | Until you delete it. The nickname is released back to the pool |
| Who you talked to. That two devices had a conversation, who asked, and when it was last used — not what was said | 30 days after the last message. An unanswered request goes in 7 days |
| Your connections. Your identifier, the IP address a connection came from, and when it opened and closed. No message content | 90 days |
| Notifications. One delivery credential per device, from Apple or Google, if you turn notifications on | 60 days after the app last refreshed it |
| Reports. A report somebody filed, and the copy of the reported message we took when it arrived — including who wrote it | 180 days from the report |
| What we did and why. If we act against you, the statement of reasons telling you what we did and on what ground | 180 days from the notice |
| Safety records. Bans, blocks, report history, and the date a device first registered | Indefinitely. A ban that expires is a ban that stops working |
| An age band. Whether your app store told us you are over or under 18, and nothing more — no date of birth. Most devices have no such record at all | Indefinitely |
| Preserved evidence. If we are legally required to keep a conversation for the authorities, a copy of it and the account of who authorised that | 90 days, or 1 year where a report to child-protection authorities requires it |
What we do not collect
This list is as much of the policy as the one above, so it is stated rather than implied.
- No name, email address or phone number for using the app. The app never asks and there is nowhere to put one.
- No contacts, no address book, no photo library scan. An image is only ever one you chose to send.
- No location. We read the country an IP address is in to know whether we may serve you at all, and we do not store the country against you — only a running count per country.
- No advertising, no advertising identifier, no tracking. There is no ad SDK in the app and nothing here is used to profile you or follow you between apps.
- No analytics SDK and no session recording. We count how many launches reached each step of first setup, in whole numbers, on our own servers. Those counts are not attached to anyone.
- No crash-reporting SDK. Crash reports reach us through Apple's and Google's own developer tools, under the setting you control in your phone's settings, and carry nothing of ours.
- No cookies on this website beyond the one that makes the form on the front page work, which carries no identifier and follows you nowhere.
Why we are allowed to keep it
Under the GDPR, each of the things above rests on one of these grounds.
- Because you asked us to. Your consent, for the launch list. You can withdraw it at any time and the link in our message is how.
- Because it is the service. Delivering a message, holding a room's recent history, reaching your phone with a notification — none of that is possible without doing it.
- Because a chat service that cannot act on abuse is not safe to run. Bans, blocks, reports, connection records, and the moderation decisions behind them. This is our legitimate interest and yours, and it is why the safety records outlive the messages.
- Because the law requires it. Preserving material for child-protection and law-enforcement processes, telling you why we acted against you, and keeping minors off the service.
Who else sees it
We do not sell your data and we do not share it for advertising. There are exactly three ways anything leaves us.
- Our host. The service runs on Fly.io, on machines in Amsterdam. Fly.io stores what we store and does nothing else with it.
- Your phone's notification service. If you turn notifications on, Apple or Google delivers them. They are told a notification is due; the message itself is not in it.
- Authorities, when we must. A valid legal request, or a report of child sexual abuse material, which we are obliged to make and do make. We give what the request reaches and no more — our records are kept in separate stores so that a request for connection records cannot come back carrying what people wrote.
Under 18s
ChatKiwi is for adults. If your app store tells us you are under 18, the app refuses to register and there is nothing to opt out of. If you believe a child is using the service, write to safety@chatkiwi.app.
Your rights
You have the right to see what we hold about you, to correct it, to have it deleted, to object to how we use it, and to take it elsewhere.
How you use them here is unusual, and it is a consequence of the design. We cannot identify you from an email, because we have never had one. So the app itself carries the door: it asks us to delete everything held under your identifier and proves the request is yours by signing it with the key on your phone. Nobody else can make that request about you, and we cannot make it on your behalf.
For an address on the launch list, the unsubscribe link is the same door — the token in it is the proof, because there is nothing else about you to prove.
Two things survive a deletion request, and we would rather say so here than surprise you.
- A ban stays enforceable. We keep an irreversible hash rather than your identifier — enough to recognise the ban if the same device returns, not enough to identify you or to find you in anything else.
- Material under a legal hold stays until the hold expires. If we have been required to preserve something, deleting it on request is not ours to do.
Everything else goes. If you want to exercise a right and the door in the app does not fit what you are asking, write to legal@chatkiwi.app and we will answer within a month.
If you think we have got this wrong, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens. We would rather you told us first, but you do not have to.
Where it is kept, and how
In Amsterdam, in the European Union. Everything travels encrypted. Message bodies live in a store that deletes them on a timer rather than in a database we sweep later, which is why the 72 hours is a property of the store rather than a promise about our diligence.
Images are the one exception worth stating exactly, because an image store has no timer of its own. At 72 hours an image stops being reachable — no link to it will open, whatever else is running — and the bytes themselves are erased by a sweep that passes every few hours after that.
Only two people can look at preserved material, and it takes both of them: one to ask and a second to approve. Every such look is written to a log that cannot be edited and that outlives the material it describes.
When this changes
The date at the top is the date this version took effect. If we change something that matters — a new kind of data, a longer clock, a new recipient — we will change that date and say what moved. If you are on the launch list when it happens, that is not what your one message will be about; you will find it here.