ChimeChat™ · Terms · Privacy · Billing · Report abuse

Privacy Policy

Version 1.9Effective August 19, 2026VAULTCAST, INC.

In plain words

This Privacy Policy describes how VAULTCAST, INC. (“VAULTCAST,” “we”) handles information in connection with the ChimeChat service (the “Service”). It is part of the Terms of Service.

1.The Architecture Comes First

ChimeChat is designed so that the most sensitive information — the content of your conversations — never exists on our systems in readable form and is never stored on our systems in any form:

Everything below accounts for the limited information that does exist.

2.Information We Process

2.1 Transient operational data (while you use the Service).

DataPurposeStorageRetention
Connection data (IP address, WebSocket session, browser user-agent)Delivering messages; abuse and rate limiting; basic securityServer memoryLife of the connection
Room state (room code, seat/device identifiers, encrypted queued payloads)Operating the roomServer memoryLife of the room (≤ ~24h idle)
Scheduled-room record (room code, opening time, creation time, and the inviter's display name encrypted with the room's key)Reopening a room someone scheduled for a future time, so a restart does not cancel it; and telling the person invited who invited them, before they joinServer diskUntil the room opens and ends — in any case no more than ~24h past its opening time
Access record for a gated area of the site (time, salted hash of the IP address, browser and device family, place name)Seeing who is getting in during a closed or limited-access period; abuse and securityServer diskKept as a rolling security log
Operator action record (time, the opaque room id shown in our admin panel, the grounds, an optional operator note)Accountability for anything we change or close ourselvesServer diskKept as a rolling record
Coarse device/browser family (e.g., “iOS / Safari”)Aggregate compatibility statisticsAggregated only (see 2.2)As in 2.2

Infrastructure note: the Service is hosted on Render; the host's edge infrastructure may maintain standard, short-lived network logs (including IP addresses) as described in its own policies.

2.2 Aggregate, content-free usage statistics. We keep counters that describe usage volumes, never content or identity — for example: rooms created, messages relayed (count only), files exchanged (count only), and feature toggles used. To count “unique” devices or repeated visits without storing identities, we store one-way salted hashes of device identifiers, IP addresses, room pairings, and (for memberships) email addresses. These hashes cannot be reversed into the original values, and they are used solely to compute counts. Coarse geography is derived locally on our server from the IP address using an on-server database — the IP address is not sent to any third party for this purpose. What we keep is the country, region and city that database returns, plus that place’s own centre-point coordinate from the same database: the location of the place, not of you or your device, and kept only as a daily count per place. We store daily aggregate rollups and the salted hashes described; these statistics contain no names, no message content, no precise location, and no raw IP addresses. (Membership registration details are a separate record, described in Section 2.6, and are never joined to these statistics.)

2.3 Data your device keeps for itself (never sent to us). Your browser stores, locally on your device: a random device identifier (so the Service can recognize your seat in a room), your display name and optional profile photo for the current session, theme/text-size/sound preferences, and — so you can step back into a conversation you are already in — a small “resume” record for each active room: the room code, the other participant's display name, and the room's encryption key. On your own device this resume record is kept until the room ends, you leave it, or roughly 24 hours pass, so that accidentally closing a tab, window, or the browser does not lose your place; on a computer you mark as “shared” when logging in, the encryption key is not kept beyond the life of the tab (only the room code is), so your key never rests on a shared machine. The resume record stays on your device and is never sent to us; the key, as elsewhere, never reaches us. Profile photos are sent (encrypted) to the other participant. We do not store them, with one exception you control: with a paid membership, a photo you add is kept with your account, encrypted, as described in Section 2.6(a). Deleting your photo deletes that copy. Whether the other person sees it is a separate setting; switching that off does not remove the copy we hold. You can clear all of this with your browser's site-data controls; doing so also permanently forfeits access to any active rooms. Device-local data does not synchronize between your devices: a name or photo you keep on one device exists only there. With a paid membership there are two exceptions: the name others see in a room, if you chose one, and your profile photo, whenever you have one. We keep them with your registration details (Section 2.6(a)) so they are there when you log in elsewhere, and removing either deletes it. References to a “device” in this Policy mean your browser or device: each browser profile on a machine, including a private or incognito window, maintains its own separate storage and functions as its own device.

2.3a What your device keeps of a conversation, encrypted (never sent to us). So that closing ChimeChat and coming back to a room you are still in does not lose your place, your browser may keep, on your device only, a copy of what is currently on your screen in that room — messages and attachments not yet cleared. It is stored encrypted, using that room’s own key, which never reaches us; we cannot read it, and it is never transmitted to us. It exists only for the life of that room and is removed when reply-triggered deletion clears the content (in the same act, so deletion reaches the stored copy and not only the screen), when the room ends, and in any event at the room’s expiry. Removal when a room ends is performed by the software on your device: if the room ends while ChimeChat is not open there, removal happens the next time it opens, and no later than expiry. On a computer you mark as “shared” when logging in, none of this is stored at all. This describes how the app holds a conversation on your device; it does not give you a way to save anything — saving an attachment out of ChimeChat is still offered only where the sender chose Give. You can clear all of it with your browser’s site-data controls. Nothing in this Section changes Section 2.1: our servers store no message content at any time.

2.4 Terms-acceptance records. When you accept the Terms, we record: the Terms version, a timestamp, an age-screen pass flag, and a salted hash of your device identifier. We do not record your birth date, name, or any other identity data at acceptance.

2.4a The inviter's name, encrypted. So that an invitation can say who it is from, your display name is encrypted on your device, with the key belonging to that room, and the encrypted result is held by us and handed to whoever opens your invite link. We cannot read it. The key travels only in the link's fragment, which never reaches any server, so to us it is an opaque string; someone guessing a room code receives the same opaque string and learns nothing. For a live room it is held in memory and dies with the room. For a scheduled room it is stored, still encrypted, alongside the booking (Section 2.3) and deleted with it.

2.5 Abuse reports (when you send one). If you report abuse, we receive what you choose to include — typically your description and your own copies (for example, screenshots) of the material — plus the reporting context. This is the one circumstance in which conversation content can reach us, provided voluntarily by a participant who holds it. We use it to evaluate the report, enforce the Terms, and meet legal obligations (Section 5), retain it as required by law (including the preservation required for CyberTipline report material under 18 U.S.C. §2258A(h)), and then delete it.

2.6 With paid memberships. A membership is an account: on our servers it is the registration details described in (a), stored encrypted, plus a subscription state. In full: (a) Your registration details. You log in with your email address; after your first log-in we ask for your full name and your mobile number, both required. We also store a display name, if you chose one different from your first name; and your profile photo, if you have one. Both are conveniences you can remove at any time, and removing them deletes them from our systems. We store these details encrypted at rest, with access limited to operating the Service, and we never sell them. Your email address is used to send your log-in links and notices about your account; we send news about ChimeChat to it only if you choose to receive it, and every such email includes an unsubscribe that we honor. The mobile number is not used by the Service today: we ask for it now so that a future account feature that needs it, such as log-in help by text, would not require asking everyone again, and this policy will describe any such use before it begins. Alongside the encrypted record we also keep a one-way salted hash of your email address; that hash is how the Service recognizes your membership in everyday operation, so the address itself is not handled where the hash will do (your own browser may remember the address locally to speed checkout). (b) Payment information is handled entirely by our merchant of record, which is the seller of record — we never receive or store card numbers; we receive subscription status, period dates, and non-reversible references used only to operate membership and enforce bans. (c) Codes and passes: we record which promo or guest codes a membership (by hash) redeems and when; a Member Pass records, by hash, which membership created it — so allotments work and a misused pass can be cancelled. (d) Invitee conversion timing: if a device (by hash) first used ChimeChat as an invitee and its person later becomes a member, we record the two timestamps and the hash linkage — counts and intervals, no identities. (e) Logged-in browsers: so that you can review and end your own log-ins, we keep, per logged-in browser, the browser and platform family (for example, “Chrome on Mac”), the log-in time, and a last-active time — shown to you in your membership account and removable there via “log out other browsers.” If you email support, we have what you sent, kept as needed to help you.

3.What We Do Not Do

And plainly, what does happen: a small number of service providers under contract process data for us so the Service can run, for example hosting and email delivery (Section 4). Our own measurements are aggregate counts (Section 2.2), never joined to who you are. We may share aggregate or de-identified data, which identifies no one, with others to improve the Service. Sponsored content may appear in ChimeChat in the future; if it ever does, this policy will say so before it happens.

Fonts and all page assets are served from our own servers — visiting ChimeChat does not send your address to any font or asset network.

4.Service Providers

We use a small number of infrastructure providers, and none of them process message content — none exists to process: Render (hosting; connection-level network data in transit per its policies); and, with paid memberships, a merchant of record (billing, under its own privacy policy) and a transactional email provider (log-in links, account notices, and product news if you opted in; email address and delivery metadata). This list is kept current on this page.

5.Disclosures Required by Law

We respond to valid legal process. What we can produce is limited to what Section 2 describes — aggregate counters, salted hashes, transient operational data if captured at the moment of service, acceptance records, and, with paid memberships, the registration details described in Section 2.6(a) (name, email address, mobile number if one was given, a display name if you chose one different from your first name, and your profile photo if you have one) together with billing status held by the merchant of record. Registration details are stored encrypted, but the encryption is ours, so unlike message content they can be produced when the law requires it. We cannot produce message content; none is stored and none is readable by us. Where we obtain actual knowledge of apparent child sexual abuse material, we report to the National Center for Missing & Exploited Children as required by 18 U.S.C. §2258A and preserve report-related material as required. We may disclose information as necessary to protect life and safety, enforce our Terms, or defend legal claims — always within the limits of what actually exists.

6.Security

End-to-end encryption (AES-GCM-256; per-room keys; device-to-device key handover for code joins); TLS for all transport; no content at rest; membership registration details encrypted at rest (AES-256-GCM, with the encryption key held separately from the stored data); salted one-way hashing for the identifiers we count with; least-data design throughout. No system is perfectly secure: the residual risks that matter most are on the endpoints — your device, your browser, and the person you talk to (Terms, Section 2.2). If we learn of a breach of data we actually hold, we will notify affected users and authorities as applicable law requires; because we hold no content, and registration details rest encrypted, the practical exposure of our servers is counters, hashes, and encrypted records.

7.Your Rights and Choices

Everyone: use the Service without an account; clear device-local data via your browser; decline optional features (photos, location); stop using the Service at any time — nothing about your conversations remains with us either way.

California residents: we honor the rights the California Consumer Privacy Act provides (to know, delete, correct, and opt out of sale or sharing). We sell no personal information and do not share any for cross-context behavioral advertising. If you have a membership, the registration details in Section 2.6 exist and we will disclose, correct, or delete them on request; beyond those, most categories of personal information simply do not exist here. Do Not Track / Global Privacy Control: we do not track users across sites or over time, so there is nothing for these signals to opt out of; we treat a GPC signal as an opt-out of sale/sharing, which is our default state.

Other U.S. states: residents of states with comprehensive privacy laws have similar rights; the answer is the same — the data mostly does not exist.

International visitors: the Service is operated from and directed to the United States.

To exercise any of these, here is .

8.Children

The Service is not directed to children and is not available to anyone under 18. We do not knowingly collect personal information from children under 13; if we learn we have, we will delete it. Our age screen is a neutral date-of-birth attestation and we retain no birth dates.

9.Changes; Contact

We will post changes on this page with a new version and effective date, and give reasonable advance notice of material changes (including by in-app notice). Contact: VAULTCAST, INC., Los Angeles, California. For privacy questions, and to exercise any of the rights in Section 7, here is . Tell us which right you are exercising and which U.S. state you live in, so that we apply the right law. If you have a membership, we hold the registration details described in Section 2.6, and what we have to do with them when you ask depends on the privacy law of the state you live in. Beyond those, most of the categories in Section 2 do not exist here, and the honest answer to many requests is that there is nothing to return or delete; we will say so plainly rather than send you a form.

Ask about your details

Privacy Policy — Section 7

This is about paid memberships. A membership is the only kind of account here. Without one, there are no registration details of yours for us to show you, correct, or delete.

If you have a membership, you can ask us for any of three things: to tell you what we hold for you, to correct something in it that is wrong, or to delete it. What we have to do when you ask depends on the privacy law of the state you live in. Send an email and include:

  1. Which of the three you want. Your own words are fine. You do not need to name a law or fill in a form.
  2. Which U.S. state you live in. States give people different rights, and we want to apply the right one to your request.
  3. The email address you log in with. Writing to us from that address is the simplest way, because it is how we find your account.
service@chimechat.com

We will write back and tell you what we found and what we did. For much of what this policy describes, the honest answer is that nothing about you exists to return or delete, and we will say so plainly.