This Privacy Policy describes how Vaultcast, Inc. (“Vaultcast,” “we”) handles information in connection with the ChimeChat service (the “Service”). It is part of the Terms of Service.
ChimeChat is designed so that the most sensitive information — the content of your conversations — never exists on our systems in readable form and is never stored on our systems in any form:
Everything below accounts for the limited information that does exist.
2.1 Transient operational data (while you use the Service).
| Data | Purpose | Storage | Retention |
|---|---|---|---|
| Connection data (IP address, WebSocket session, browser user-agent) | Delivering messages; abuse and rate limiting; basic security | Server memory | Life of the connection |
| Room state (room code, seat/device identifiers, encrypted queued payloads) | Operating the room | Server memory | Life of the room (≤ ~24h idle) |
| Coarse device/browser family (e.g., “iOS / Safari”) | Aggregate compatibility statistics | Aggregated only (see 2.2) | As in 2.2 |
Infrastructure note: the Service is hosted on Render; the host's edge infrastructure may maintain standard, short-lived network logs (including IP addresses) as described in its own policies.
2.2 Aggregate, content-free usage statistics. We keep counters that describe usage volumes, never content or identity — for example: rooms created, messages relayed (count only), files exchanged (count only), and feature toggles used. To count “unique” devices or repeated visits without storing identities, we store one-way salted hashes of device identifiers, IP addresses, room pairings, and (for memberships) email addresses. These hashes cannot be reversed into the original values, and they are used solely to compute counts. Coarse geography (country/region) is derived locally on our server from the IP address using an on-server database — the IP address is not sent to any third party for this purpose — and only the coarse result is kept in aggregate. We store daily aggregate rollups and the salted hashes described; we do not store names, message content, precise location, or raw IP addresses at rest.
2.3 Data your device keeps for itself (never sent to us). Your browser stores, locally on your device: a random device identifier (so the Service can recognize your seat in a room), your display name and optional profile photo for the current session, theme/text-size/sound preferences, and — for the life of a tab — room keys needed to rejoin a conversation. Profile photos are sent (encrypted) only to your conversation partner, never stored by us. You can clear all of this with your browser's site-data controls; doing so also permanently forfeits access to any active rooms. Device-local data does not synchronize between your devices — a name or photo you choose to keep on one device exists only there, because we hold no profile to sync it through. References to a “device” in this Policy mean your browser or device: each browser profile on a machine, including a private or incognito window, maintains its own separate storage and functions as its own device.
2.4 Terms-acceptance records. When you accept the Terms, we record: the Terms version, a timestamp, an age-screen pass flag, and a salted hash of your device identifier. We do not record your birth date, name, or any other identity data at acceptance.
2.5 Abuse reports (when you send one). If you report abuse, we receive what you choose to include — typically your description and your own copies (for example, screenshots) of the material — plus the reporting context. This is the one circumstance in which conversation content can reach us, provided voluntarily by a participant who holds it. We use it to evaluate the report, enforce the Terms, and meet legal obligations (Section 5), retain it as required by law (including the preservation required for CyberTipline report material under 18 U.S.C. §2258A(h)), and then delete it.
2.6 With paid memberships. A membership is not an identity profile: on our servers it is a salted hash of your email plus a subscription state. In full: (a) Your email address is used transiently — to send your sign-in link and any membership notices — and stored only as a one-way salted hash, which we cannot read back into an address (your own browser may remember the address locally to speed checkout). (b) Payment information is handled entirely by our merchant of record, which is the seller of record — we never receive or store card numbers; we receive subscription status, period dates, and non-reversible references used only to operate membership and enforce bans. (c) Codes and passes: we record which promo or guest codes a membership (by hash) redeems and when; a guest pass records, by hash, which membership created it — so allotments work and a misused pass can be cancelled. (d) Invitee conversion timing: if a device (by hash) first used ChimeChat as an invited guest and its person later becomes a member, we record the two timestamps and the hash linkage — counts and intervals, no identities. (e) Signed-in browsers: so that you can review and end your own sign-ins, we keep, per signed-in browser, the browser and platform family (for example, “Chrome on Mac”), the sign-in time, and a last-active time — shown to you in your membership account and removable there via “sign out other browsers.” If you email support, we have what you sent, kept as needed to help you.
Fonts and all page assets are served from our own servers — visiting ChimeChat does not send your address to any font or asset network.
We use a small number of infrastructure providers, and none of them process message content — none exists to process: Render (hosting; connection-level network data in transit per its policies); and, with paid memberships, a merchant of record (billing, under its own privacy policy) and a transactional email provider (sign-in links; email address and delivery metadata). This list is kept current on this page.
We respond to valid legal process. What we can produce is limited to what Section 2 describes — aggregate counters, salted hashes, transient operational data if captured at the moment of service, acceptance records, and (with paid memberships) billing status held by the merchant of record. We cannot produce message content; none is stored and none is readable by us. Where we obtain actual knowledge of apparent child sexual abuse material, we report to the National Center for Missing & Exploited Children as required by 18 U.S.C. §2258A and preserve report-related material as required. We may disclose information as necessary to protect life and safety, enforce our Terms, or defend legal claims — always within the limits of what actually exists.
End-to-end encryption (AES-GCM-256; per-room keys; device-to-device key handover for code joins); TLS for all transport; no content at rest; salted one-way hashing for the identifiers we count with; least-data design throughout. No system is perfectly secure: the residual risks that matter most are on the endpoints — your device, your browser, and the person you talk to (Terms, Section 2.2). If we learn of a breach of data we actually hold, we will notify affected users and authorities as applicable law requires; because we hold no content and no plaintext identifiers, the practical exposure of our servers is counters and hashes.
Everyone: use the Service without an account; clear device-local data via your browser; decline optional features (photos, location); stop using the Service at any time — nothing about your conversations remains with us either way.
California residents: we honor the rights the California Consumer Privacy Act provides (to know, delete, correct, and opt out of sale or sharing) — noting that we sell and share nothing, and most categories of personal information simply do not exist here. Do Not Track / Global Privacy Control: we do not track users across sites or over time, so there is nothing for these signals to opt out of; we treat a GPC signal as an opt-out of sale/sharing, which is our default state.
Other U.S. states: residents of states with comprehensive privacy laws have similar rights; the answer is the same — the data mostly does not exist.
International visitors: the Service is operated from and directed to the United States.
The Service is not directed to children and is not available to anyone under 18. We do not knowingly collect personal information from children under 13; if we learn we have, we will delete it. Our age screen is a neutral date-of-birth attestation and we retain no birth dates.
We will post changes on this page with a new version and effective date, and give reasonable advance notice of material changes (including by in-app notice). Contact: Vaultcast, Inc., Los Angeles, California — see the contact information in the footer of this page.