Privacy policy
Short version: we can't read your messages, and we collect as little as we can.
This policy covers the Frozen Chat apps, Frozen Chat Web, this website and the licence-key shop (together, the “service”). Last updated: draft, not yet in force.
What we never have
- The content of your messages, calls, files, voice messages, stickers or group details. They are end-to-end encrypted; we don't have the keys.
- Your phone number, e-mail address or address book. The service doesn't ask for them.
- Your private keys, your Recovery Key or your recovery PIN.
What the server stores to run the service
- Account: a random account id, your username (as a keyed hash for lookups, and encrypted for account administration), public keys, your signed device list, and the day the account was created and last seen.
- Licence: your plan, its status and end date. Licence keys are stored only as hashes, and nothing records which account redeemed which key.
- Messages in transit: encrypted envelopes until your devices fetch them, at most 30 days. Encrypted attachments for at most 30 days.
- Profile: your profile name and photo, encrypted with a key only your contacts get.
- Push tokens: if you use Google or Apple push, your device's push token, encrypted at rest. Pushes carry no content.
- Groups: encrypted group messages until every member device has read them (at most 30 days), and which devices follow which opaque group id.
What we don't log
We don't keep access logs of who connected when. IP addresses are used only in memory, for rate limiting, and are not written to disk. Stored timestamps are rounded (to the minute or the day).
This website
No cookies, no analytics, no trackers, no third-party scripts, fonts or embeds. The web server does not write access logs.
Licence-key shop
Buying a key needs no account, name or e-mail. We store the order: plan, quantity, price, status, timestamps, the payment provider's invoice id and a hash of a secret that only your browser holds. Your keys are kept encrypted until 24 hours after you first view them, then deleted; only their hashes remain so they can be redeemed. Payments are processed by NOWPayments, which receives the order id, the price and the payment details you give them, under their own privacy policy. On the blockchain, cryptocurrency payments are public by nature.
Sharing
We don't sell or share data for advertising. We use service providers to run the service (hosting, object storage, push delivery by Google/Apple, payment processing by NOWPayments). If the law compels us to hand over data, we can only hand over what is listed above, and we will challenge requests we believe are unlawful.
Your rights
You can delete your account at any time from the app; the server then deletes your account data and queued messages. Because we hold so little, most requests for access or correction can be answered by the app itself. For anything else, write to hello@mi6a.online.
Children
The service is not intended for children under 13 (or the minimum age in your country).
Changes
We will announce material changes in the app and on this page before they take effect.