Last updated 12 August 2026

Privacy Policy

What AYChat collects, why, how long it is kept — and what we could not hand over even if someone demanded it.

The short version

Direct messages are end-to-end encrypted — our servers store ciphertext they cannot read. We never upload your phone's address book. Your location is only ever stored as a ~1.2 km area, never exact coordinates. There are no advertising or third-party analytics SDKs in the app. We do not sell your data to anyone, ever.

1Who we are

AYChat (“we”, “us”) operates the AYChat mobile application and the service at aychat.pro. For any privacy question or request, write to privacy@aychat.pro.

[Fill in: registered legal entity name, postal address, and the country whose data-protection law applies. Every app store asks for this.]

2What we collect and why

DataWhy we need itHow long
Username, display name, email, and phone number if you add one To create your account, sign you in, and let friends find you Until you delete your account
Profile photo, bio, country Shown on your profile, as much or as little as you choose Until you change or remove it
Password (Argon2id hash — never the password itself) and, if enabled, an encrypted two-factor secret To keep your account yours Until you delete your account
Devices and sessions: device id, app build, IP address, approximate login location, last-active time So you can see and revoke your own sessions, and so we can spot account takeover Until the session is revoked; login history is pruned periodically
Messages and their media To deliver your conversations and sync them across your devices Until you delete them — or automatically, for disappearing messages
Presence (online / last seen) To show availability, subject to your privacy settings Expires from cache within 60 seconds of going offline
Approximate location — only if you use Nearby To show people near you as distance bands Deleted when you turn Nearby off
Call records: who was in a call, when it started and ended Call history and abuse prevention Until you delete your account
Push tokenTo wake your phone for notifications Until you sign out or disable notifications
Reports you submit or that name you, and moderation actions Keeping people safe, and being able to review our own decisions Retained in our audit log

3End-to-end encryption

Direct chats are end-to-end encrypted. Messages are encrypted on your device and decrypted only on the recipients' devices. What our servers hold is opaque ciphertext — we cannot read the contents, and we cannot hand over something we do not have.

Metadata is a different matter, and honesty here matters more than marketing. To route a message we necessarily process who sent it, which conversation it belongs to, when it was sent, its approximate size, and whether it carries an attachment. Group and channel messages are stored server-side so new members and new devices can load history.

4Location and the Nearby feature

Nearby is off until you turn it on. When it is on, your coordinates are converted on the server into a geohash cell of roughly 1.2 km × 0.6 km — we store the cell, never the precise point. Other people only ever see a distance band such as “within 2 km”, never a number precise enough to triangulate where you are. Turning Nearby off deletes the stored cell.

5Calls

Calls use WebRTC and connect device-to-device wherever the network allows. Our server relays only the signalling needed to set the call up, and issues time-limited TURN credentials. When a direct connection is impossible — restrictive mobile NAT, corporate firewalls — media is relayed through our TURN server, which forwards encrypted packets without storing them.

Recording is consent-first: everyone is notified when it starts, a single objection stops it for everyone, and every consent decision is written to an audit log.

6Media and files

Photos, videos, voice notes and documents are stored in our object storage. The links handed to the app are short-lived and signed, and object keys are unguessable random values. Deleting a message removes its media.

7What we never do

8Third parties we rely on

ServiceWhat it receives
Google Firebase Cloud Messaging Your push token and the notification payload, so your phone can be woken. Notification previews can be switched off in Settings.
JioSaavn (music catalog) Search terms and track identifiers when you use the Music tab. Your identity is not sent.
GitHub Serves the app download and update files, and therefore sees the download request.
Our own servers — translation, search, media, TURN Run on infrastructure we control. Translation is self-hosted: your text is never sent to a third-party translation provider.

9Security

No system is perfectly secure. If you find a vulnerability, please write to security@aychat.pro before disclosing it publicly — we will work with you.

10Your rights

At any time you can:

We answer requests within 30 days.

11Children

AYChat is not for anyone under 13. If we learn an account belongs to a child under 13, we delete it. [If you distribute in the EU, raise this to 16 for the countries that require it.]

12Where your data lives

[Fill in: the country your servers run in. If people outside that country will sign up, say that data is transferred there and on what legal basis.]

13Changes to this policy

If we make a material change we will update the date at the top and tell you in the app before it takes effect. No quiet rewrites.

14Contact

Privacy requests — privacy@aychat.pro
Security reports — security@aychat.pro
General support — support@aychat.pro