Frozen Chat
Legal

Privacy policy

Short version: we hold as little as a messenger can, we can't read your messages, and we don't track you.

Last updated: 8 October 2026

No phone number
No e-mail address
No contacts or address book
No IP addresses logged
No message content: end-to-end encrypted
No tracking, no analytics, no cookies

1. Who we are and what this policy covers

Frozen Chat (“we”, “us”) operates the Frozen Chat apps for Android and iOS, Frozen Chat Web, the website at frozenchat.com, the licence-key shop and the website support chat (together, the “service”). For the personal data described here we are the controller under the EU and UK General Data Protection Regulation (GDPR / UK GDPR) and the “business” under the California Consumer Privacy Act (CCPA/CPRA).

One address handles everything (privacy, support, legal and security questions): [email protected].

2. How the service is built

Frozen Chat is designed so that we hold as little as possible. You sign up with a username only: no phone number, no e-mail address, no name. Messages, calls, files, voice messages, stickers, profile names and photos, and group details are end-to-end encrypted on your device using the Signal protocol (one-to-one chats) and Messaging Layer Security (groups). The keys are created on your device and never leave it, so we cannot read that content, and nor can anyone who breaks into our servers. The security page explains the design in plain language.

3. What we process, why, and on what legal basis

The table lists every kind of data the service stores or handles. “Contract” means the data is needed to provide the service you asked for (GDPR Art. 6(1)(b)). “Legitimate interests” means keeping the service secure, free of spam and abuse, and able to answer you (Art. 6(1)(f)). “Legal obligation” means we must keep it by law (Art. 6(1)(c)).

DataWhat exactlyWhyLegal basis
AccountA random account id; your username as a keyed hash (for lookups) and in encrypted form (one copy only your devices can decrypt, one copy encrypted at rest that our administrators can decrypt to handle support requests and abuse reports); your public account identity key; an optional registration-lock value derived from your recovery PIN (stored only as an Argon2id hash); the day the account was created and the day it was last seen.To let people find you by username and deliver messages to you.Contract
Devices and keysFor each linked device: a device number, its public identity and pre-keys, a registration id, a hash of its login key, the platform (Android, iOS, web), your signed device list, and the day it was added. Login tokens are stored only as hashes.So others can start encrypted chats with each of your devices, and so only your devices can log in.Contract
Encrypted profileYour profile name and photo, encrypted on your device under a key that only your contacts receive. We store an unreadable blob and a version number.So your contacts see your name and photo.Contract
Messages in transitEncrypted envelopes waiting for your devices, with a padded size and a delivery time rounded to the minute. With sealed sender the server does not learn who sent a message.To deliver messages to devices that are offline.Contract
AttachmentsFiles, photos, videos and voice messages, encrypted on your device with a fresh key per file, padded, and stored under a random name. The key travels only inside the encrypted message.To deliver files.Contract
GroupsEncrypted group state and group messages (MLS ciphertext), which devices follow which random group id, and encrypted invite-link records. No group names, photos, member roles or sender identities in readable form.To deliver group messages and keep groups in sync across devices.Contract
Push tokensIf you use Google or Apple notifications: your device's Firebase Cloud Messaging, Apple Push or Apple VoIP push token (or your UnifiedPush endpoint), encrypted at rest.To wake your device when something arrives. Pushes contain no content.Contract
LicenceYour plan, its status (active, grace, expired), start and end date, and how it was granted (key, shop order, administrator). Licence keys are stored only as hashes and nothing records which account redeemed which key.To apply your plan's limits and tell you when it ends.Contract
Encrypted backups (optional)If you turn on backups to our storage: encrypted backup files under a random backup id, a hash of the backup access secret, and padded sizes. Backups are encrypted with a key derived from your recovery words, which we never have.To let you restore your chats on a new device.Contract
Private notes (optional)If you create a one-time note: its ciphertext (the key is in the link's #fragment, which is never sent to us), hashes of the open and delete tokens, the expiry time, and, only if you ask to be told when it is read, your account id.To deliver the note once.Contract
Key transparencyA tamper-evident log of hashed commitments to usernames and public keys, so apps can detect a server that swaps someone's keys. Deleted accounts get a tombstone entry.Security of the encryption.Legitimate interests
Anti-abuse countersShort-lived rate-limit counters per account or device, and a list of first-contact recipients per day stored only as keyed hashes under a key that changes daily. Limits per network address exist only in server memory and are never written to disk.To stop spam and attacks without collecting phone numbers.Legitimate interests
Support in the appMessages you send to @frozenchat in the app. These are end-to-end encrypted like every chat; our support team reads them on its own device.To answer you.Contract / legitimate interests
Website support chatWhat you type into “Chat with us” on this website, and our replies, with timestamps. This chat is not end-to-end encrypted. No IP address, browser details or other identifier is stored; your browser keeps a random chat id and token.To answer questions before you buy.Legitimate interests
Shop ordersPlan, quantity, price, order status, timestamps, the payment provider's invoice id, a hash of a secret only your browser holds, your purchased keys (encrypted, for a limited time), and for “upgrade or extend” orders the account id the purchase was applied to (for a limited time). No name, e-mail or card details.To deliver your keys or apply your purchase, and to handle payment problems.Contract; legal obligation for accounting records
E-mail to usWhatever you write to us and your e-mail address.To answer you.Legitimate interests
Administrator audit logA record of actions our administrators take (for example applying a licence, suspending an account, replying in the website chat), with the target account or order and the time. Replies are recorded by length, never by text.Accountability and security of our own staff access.Legitimate interests

4. What we never collect

  • Your phone number, e-mail address (unless you write to us), real name, contacts or address book.
  • The content of your messages, calls, files, voice messages, stickers, profile or groups.
  • Your private keys, your recovery words (Recovery Key) or your recovery PIN.
  • Whom you talk to: sealed sender hides the sender of a message from the server, and blocking happens only on your device.
  • IP addresses, access logs or location. We do not write connection logs; the apps do not ask for location.
  • Advertising ids, analytics, crash reports sent to third parties, tracking pixels or fingerprinting.
  • Cookies. Neither the website nor the web app sets tracking cookies; the website loads no third-party scripts, fonts or embeds.

5. Calls

Call setup travels inside end-to-end encrypted messages. Call media is encrypted (DTLS-SRTP for one-to-one calls, end-to-end encrypted frames for group calls) and relayed by our own servers (a TURN relay and a self-hosted LiveKit media server) when a direct connection isn't possible. Relays necessarily see the network addresses of the devices in a call while it lasts, but cannot decrypt the media and do not log those addresses. Relay credentials are short-lived and do not carry your account.

6. Service providers (processors)

We don't sell or share personal data, and we don't share it for advertising. We use these providers to run the service:

ProviderWhat they doWhat they can see
Cloudflare, Inc.Network provider: carries all HTTPS traffic to our website, web app, API and admin console, and protects against attacks.The IP addresses of devices that connect, and the traffic itself. Message content is end-to-end encrypted inside that traffic; website pages, shop requests and the website support chat are not.
iDrive e2 (iDrive Inc.), EU region (eu-west-3)Object storage for encrypted attachments, encrypted backups and our encrypted database backups.Encrypted files under random names and their padded sizes, and the IP address of the device that uploads or downloads.
NOWPaymentsProcesses cryptocurrency payments in the shop.The order id, the price, and whatever you give them when you pay (for example your wallet address). Not your account or username.
Google (Firebase Cloud Messaging)Delivers wake-up notifications to Android phones with Google services.Your device's push token and that it received a content-free push, and when.
Apple (Apple Push Notification service)Delivers wake-up notifications and incoming-call alerts to iPhones.Your device's push token and that it received a push, and when. Pushes contain no message, sender or chat.

Our servers (database, API, TURN relay and LiveKit media server) are run by us on rented infrastructure. On Android phones without Google services, notifications can use UnifiedPush through a distributor you choose, or the app's own connection to us; in that case Google sees nothing. Payments on a blockchain are public by nature.

7. How long we keep data

DataKept for
Encrypted messages waiting for deliveryUntil every recipient device has fetched them, and at most 30 days
Encrypted group messagesUntil every member device has fetched them, and at most 30 days
Encrypted attachmentsAt most 30 days after upload
Account, devices, keys, encrypted profile, push tokens, licenceUntil you delete your account or unlink the device
Encrypted backups in our storageUntil you delete them or your account; 30 days after your plan stops including backups; 180 days without any upload
Private notesUntil opened (once), deleted by you, or expired (1 hour to 30 days, as you choose)
Website support chatDeleted after 30 days without a new message (after 1 day if you never wrote anything)
Purchased keys held for you in the shop24 hours after you first view them, or 90 days after payment if never viewed; afterwards only their hashes remain
Link between an “upgrade or extend” order and an accountSame schedule as held keys, then removed
Unpaid ordersMarked expired after 7 days; order records without keys or account link are kept for our accounting
Rate-limit countersMinutes to one day
Key-transparency proofs for auditors14 days; the log itself is permanent but contains only hashed commitments
E-mail correspondenceAs long as needed to resolve your request
Encrypted service backupsKept only to restore the service after a failure, and overwritten automatically

8. Where data is processed

Our attachment and backup storage is in the European Union (iDrive e2, Paris region). Cloudflare, Google and Apple operate worldwide, including in the United States. Where personal data leaves the EU/EEA or the UK, we rely on the European Commission's adequacy decisions (including the EU-US Data Privacy Framework where the provider is certified) or Standard Contractual Clauses with the provider.

9. Security

End-to-end encryption protects content even from us. On top of that: everything in transit uses TLS; push tokens, usernames for administration, held shop keys and database backups are encrypted at rest; secrets such as login tokens, licence keys and note tokens are stored only as hashes; administrator access needs a password and a one-time code and is logged. No system is perfectly secure; see the security page for known limits and how to report a vulnerability.

10. Your rights

Depending on where you live (for example the EU, UK, California or other US states), you have the right to: access your data and get a copy; correct it; delete it; restrict or object to processing based on legitimate interests; data portability; and withdraw consent where we rely on it. California residents also have the right to know what we collect and not to be discriminated against for exercising their rights. We do not sell or “share” personal information as the CCPA defines those terms, and we do not use sensitive personal information to infer characteristics about you.

How to exercise them:

  • Delete: delete your account yourself, or ask us. See how to delete your account.
  • Access and portability: almost everything about you lives on your own devices, and the app shows it to you (your profile, devices, licence). Encrypted backups export your chats in a form only you can read.
  • Correction: change your profile name and photo in the app at any time; for anything else, write to us.
  • Anything else: e-mail [email protected]. Because we don't know who you are, we may ask you to prove control of the account, for example by sending us a message from it in the app. We answer within one month.

You can also complain to a data protection authority, for example the one in the country where you live or work. We would appreciate the chance to sort it out with you first.

11. Deleting your account

When you delete your account, the server deletes your account record, devices, keys, encrypted profile, push tokens, licence and queued messages immediately, schedules your attachments and backups in our storage for deletion, and frees your username. Our encrypted service backups are overwritten automatically. Messages you already sent stay on the devices of the people who received them. Details: delete your account.

12. Children

The service is not for children. You must be at least 16 years old to use it (at least 13 in the United States, where your local law allows), or older if your country requires it. We do not knowingly process data of younger children; if you believe a child is using the service, write to [email protected] and we will delete the account. See also our child safety standards.

13. Law enforcement

We can only disclose the little we hold, and only when legally required. See information for law enforcement.

14. Automated decisions

We don't make decisions about you based solely on automated processing that have legal or similarly significant effects. Automatic rate limits may briefly slow or refuse requests that look like spam.

15. Changes to this policy

We will post any change here with a new “last updated” date, and announce material changes in the app before they take effect.

16. Contact

Questions, requests or complaints about privacy: [email protected].