Privacy Policy

Last Updated: September 21, 2026

This Privacy Policy explains how the individual maintainers and developers of Chatr (“Chatr,” “we,” “us,” or “our”) collect, use, process, and protect your information when you access or use the Chatr applications, websites, APIs, and relay services (collectively, the “Services”).

Chatr is built on privacy by design and zero-knowledge architecture. Our core principle is simple: what you say, send, and store in Chatr is private to you. We do not monetize your personal data, we do not sell your information to advertisers, and our servers are cryptographically blinded from reading your communications.


1. Information We Do NOT Collect (Zero-Knowledge Architecture)

Chatr’s architecture is designed so that we physically cannot access or collect your private communications:

  • No Plaintext Messages or Captions: Direct messages, message edits, and media captions are end-to-end encrypted on your device using open, peer-reviewed cryptographic protocols (including the Double Ratchet Algorithm and Extended Triple Diffie-Hellman / X3DH standards). We do not hold your private encryption keys and cannot decrypt your conversations.
  • No Unencrypted Media Attachments: Photos, videos, and files sent between users are encrypted with unique cryptographic keys on the sender’s device before being uploaded. Keys are transmitted only inside the end-to-end encrypted message payload. Our media storage servers hold only opaque ciphertext blobs.
  • No Server-Side Message History: Decrypted chat history and message records reside exclusively in encrypted local storage on your physical device. We do not store conversational histories or message archives on our servers.
  • No Address Book Uploads: Chatr does not scan, upload, or sync your phone’s address book or contact lists. Contacts are added only through explicit, mutual handle search and user-initiated friend requests.
  • No Behavioral or Advertising Tracking: We do not track your activity across third-party websites or apps. We do not use advertising trackers, marketing analytics SDKs, or third-party data brokers.

2. Information We Collect and Process

To route messages, authenticate accounts, and maintain platform security, we process a minimal set of account and technical data:

A. Account Information You Provide

  1. Registration Information:
    • Email Address: Used solely to deliver one-time verification codes (OTP) during sign-in. We do not use your email address for marketing, newsletters, or promotional campaigns.
    • Handle: A unique username you choose (e.g., @alex) that allows other users to find you and send you friend requests.
  2. Profile Avatar (Optional):
    • If you choose to upload a profile avatar, it is stored in secure object storage to be displayed to your accepted contacts. Your profile avatar is public metadata accessible to users who look up your handle.

B. Cryptographic & Device Directory Information

  1. Public Prekey Bundles: To enable asynchronous end-to-end encryption (allowing contacts to send you messages even when your device is offline), your client publishes public identity keys and prekey bundles to our directory. Your private keys never leave your device.
  2. Device Identifiers: We associate cryptographic device keys and device identifiers with your account so that incoming encrypted messages are routed correctly to your paired devices.

C. Operational & In-Transit Data

  1. Temporary Mailbox Envelopes: When a message is sent to a device that is temporarily offline, our servers hold the opaque ciphertext envelope in a temporary queue for store-and-forward delivery. Envelopes are retained for a maximum of thirty (30) days, after which they are permanently and automatically purged.
  2. Realtime Presence & Typing (Ephemeral): Online presence and typing indicators are transient, real-time network signals. They are held temporarily in memory and are never written to persistent databases or access logs.
  3. Session Tokens & Operational Headers: We process technical connection data (such as IP addresses, user-agent details, and authentication tokens) solely to maintain active connections, protect against denial-of-service (DDoS) attacks, and enforce authentication rate limits.

3. How We Use Your Information

We use the minimal data collected strictly for the following purposes:

  1. Core Service Delivery: Authenticating your account, routing opaque ciphertext envelopes to your devices, and syncing delivery receipts.
  2. Security & Abuse Mitigation: Enforcing rate limits to prevent brute-force attacks, protecting server infrastructure from spam and volumetric attacks, and investigating reports of abusive handles or terms violations.
  3. Software Updates: Verifying client application versions and delivering cryptographically signed updates.

4. Third-Party Service Providers

We work with a minimal set of trusted infrastructure providers to deliver our backend services. These providers process data strictly on our behalf under confidentiality and data protection obligations:

Provider Purpose Data Handled Privacy Reference
Resend Inc. Transactional Email Delivery Destination email address and one-time verification code (OTP). Resend Privacy Policy
Cloudflare Inc. Edge Ingress, Network Security & Cloud Object Storage Connection IP address, encrypted media ciphertext blobs, and public avatar images. Cloudflare Privacy Policy
Google Play (Google LLC) Android Application Distribution & Updates Standard download and installation technical metrics managed by Google Play. Google Privacy Policy

We do not sell, rent, or trade your personal data to any third parties.


5. Disclosures Required by Law

Because of our zero-knowledge, crypto-blind architecture, we cannot decrypt, intercept, or disclose the plaintext contents of your messages or private files, as we do not possess the cryptographic keys.

We may disclose the limited account metadata we hold (such as account creation date, registered email address, handle, or connection logs, if available) only if:

  1. Required by a lawful subpoena, court order, or binding legal process from a court of competent jurisdiction;
  2. Necessary to investigate or enforce violations of our Terms of Service;
  3. Required to protect the safety, security, or legal rights of our users or the public; or
  4. Required to report suspected Child Sexual Abuse Material (CSAM) or severe exploitation to child protection organizations and law enforcement authorities.

6. Account Deletion & Data Retention

A. How to Delete Your Account

We believe you should have complete control over your data. We provide two methods to delete your account:

  1. In-App Self-Serve Deletion (Primary Method):
    You can permanently delete your account and all associated server-side data directly inside the Chatr application at any time. Simply navigate to:
    Settings > Account > Delete Account
    Confirming account deletion immediately initiates the permanent deletion of your account from our servers.

  2. Account Deletion Request (For Users Without the App Installed):
    If you have uninstalled the application, lost your device, or cannot access the app interface, you can submit an account deletion request by emailing support@chatr.xerosf.dev from the email address registered to your account with the subject line:
    “Account Deletion Request: @yourhandle”
    We will verify your request and permanently delete your account within thirty (30) days.

B. What Gets Deleted

When your account is deleted:

  • Your registered email address, authentication sessions, and handle are permanently removed.
  • Your cryptographic device directory bundles and public prekeys are purged.
  • Your profile avatar and any pending undelivered envelopes in our relay queues are permanently deleted.

C. Local On-Device Data Notice

Deleting your account on the server removes your data from our infrastructure. However, because Chatr stores your conversation history and private keys locally on your device, server deletion cannot remotely alter your local device storage. To remove all local conversation history and encryption keys, simply uninstall the Chatr application or clear the application’s storage data on your device.


7. International Data Transfers & Governing Law

Chatr is maintained by individual developers based in Sri Lanka, utilizing distributed cloud infrastructure (such as Cloudflare edge locations). If you access Chatr from outside Sri Lanka, your connection data and encrypted packets may be transferred to and processed in data centers internationally.

By using the Services, you consent to the processing and transfer of your data as described in this Privacy Policy. This Privacy Policy shall be governed by and construed in accordance with the laws of the Democratic Socialist Republic of Sri Lanka, including the Personal Data Protection Act No. 9 of 2022 (PDPA), subject to applicable mandatory consumer protection laws in your jurisdiction.


8. Children’s Privacy (COPPA & GDPR)

Chatr is intended for individuals who are at least 13 years old (or the minimum legal age required in your country to consent to digital services without parental approval, such as 16 in certain European Union member states). We do not knowingly collect personal data from children under 13. If we discover that a user under 13 has created an account, we will promptly delete the account and associated server records.


9. Your Data Protection Rights

Depending on your country of residence, you may have specific statutory rights under data protection laws, including:

  • Right to Access: The right to obtain confirmation of the data we hold associated with your account.
  • Right to Erasure: The right to permanently delete your account and server data (via our in-app deletion tool or by email request).
  • Right to Rectification: The right to update or correct your registered handle or email.
  • Right to Withdraw Consent: The right to discontinue use and delete your account at any time.

To exercise any of these rights, use the in-app account tools or contact us at support@chatr.xerosf.dev.


10. Security Safeguards

We implement modern administrative and technical safeguards to protect server integrity:

  • Transport Encryption: All network traffic between your client and our servers is secured using modern TLS encryption (HTTPS and WSS).
  • End-to-End Payload Encryption: Messages and media files are encrypted on the sender’s device and can only be decrypted by the intended recipient.
  • Local Storage Protection: Decrypted conversation history and cryptographic keys are stored on your device using operating system secure storage mechanisms.
  • Authentication Rate-Limiting: Verification codes are hashed, rate-limited, and expire after a short duration to prevent brute-force attacks.

11. Changes to this Privacy Policy

We may revise this Privacy Policy periodically. When updates occur, we will update the “Last Updated” date at the top of this page. Your continued use of Chatr after revisions take effect confirms your acceptance of the updated policy.


12. Contact Information

If you have questions, privacy inquiries, or data deletion requests, contact us at: