/03What is stored
Privacy
Transparency is part of security. Here's exactly what is stored – and what is not.
No phone number, no required data
All you need is a username. No mobile number, no mandatory email.
What lives on the server
Username, a login hash (no plaintext password), your public key, online status and encrypted messages as ciphertext until delivered.
What is NOT on the server
Your message content in plaintext, your private key, your password. We technically cannot read your messages – there is no key escrow.
No readable friendship graph
Your contact list only sits on the server as an encrypted bundle. The sender of a friend request is encrypted anonymously too – there is no plaintext link “X knows Y”.
Profile & group pictures
These live as metadata on the server (not end-to-end), but contain no message content. If you prefer, leave them empty.
Local storage
Messages and contacts are stored encrypted on your device and unreadable without your password.
Privacy Policy
This policy informs you under Art. 13 and 14 GDPR about which personal data is processed when you use PriChat, for what purpose, on what legal basis, and what rights you have. We deliberately keep processing to the technical minimum.
1. Controller
The controller within the meaning of Art. 4(7) GDPR is:
Fabian Ehard
Vogelheimerstraße 32
45326 Essen
Germany
Email: [email protected]
PriChat is run as a private, free project. Even a free, publicly reachable service processes personal data and is subject to the GDPR.
The server PriChat runs on is operated by the controller named above and stores the metadata listed below. However, it technically cannot read your message contents: they are end-to-end encrypted and are encrypted and decrypted exclusively on your device. There is no spare key and no escrow service.
2. Core principle: end-to-end encryption and data minimization
Your messages, your contact list and your private keys are encrypted and stored on your device. On the server, messages exist only as ciphertext and only until they are delivered. The server is a mailbox and address book, not a reader.
3. What we process, why, and on what legal basis
a) Registration and account. We store your chosen username, a random value for key derivation (salt), an irreversible login hash (argon2id, not your password), your public key, and a recovery block encrypted with your recovery phrase. Purpose: providing your account and sign-in. Legal basis: Art. 6(1)(b) GDPR.
b) Message delivery. To deliver a message, the server temporarily stores the recipient username, the encrypted content and a timestamp. The sender is not stored; it travels encrypted inside the content. After delivery, or after 14 days at the latest, the message is deleted. Legal basis: Art. 6(1)(b) GDPR.
c) Connection data and security. When you access the server, your IP address is processed, as are the times of sign-in attempts. This serves secure operation and abuse prevention (such as rate limiting and protection against automated password guessing). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in security).
d) Online status. To show contacts whether you are reachable, an online status and the time of last activity are processed. Legal basis: Art. 6(1)(b) and (f) GDPR.
e) Profile picture, group picture and status message. Optional. They sit as metadata on the server (not end-to-end encrypted). If you prefer, leave them empty. Legal basis: Art. 6(1)(b) and (f) GDPR.
f) Two-factor authentication and passkey. If you enable 2FA, we store the required secret (TOTP). With a passkey, the key material stays inside your device's security chip; the server only receives an unreadable block. Legal basis: Art. 6(1)(b) and (f) GDPR.
g) Support requests. If you contact support, we process the content of your request to answer it. Unlike chats, support messages are not end-to-end encrypted because they are addressed to the operator. Legal basis: Art. 6(1)(b) and (f) GDPR.
h) Session. After sign-in, a technically necessary session token is set (valid 30 days) so you stay logged in. Legal basis: Art. 6(1)(b) GDPR and Section 25(2) TTDSG (strictly necessary).
4. What we explicitly do not process
- Message contents in plaintext, your password and your private keys.
- Who messages you: the sender of a message is not in the database.
- A readable friendship graph: your contact list only exists encrypted, and the sender of a friend request is encrypted anonymously.
- Group memberships in plaintext: members are stored only as pseudonyms.
- Phone number, real name or other proof of identity.
- No tracking, no advertising, no analytics services, no sharing for advertising, no profiling.
5. Cookies and local storage
PriChat sets only a technically necessary session cookie. In addition, your encrypted data (messages, contacts) and settings are stored in your browser's local storage so the app works. No tracking or advertising cookies are used, which is why there is no consent banner.
6. Recipients and processors
Hosting. The server is operated at Bieber IT GmbH (Host-Unlimited.de), Braunschweiger Straße 22, 38518 Gifhorn, Germany. A data processing agreement under Art. 28 GDPR is in place with the provider.
Cloudflare. For secure and resilient delivery we use Cloudflare (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA). Cloudflare processes technically necessary connection data, in particular your IP address, and terminates the TLS encryption of the transport path. Legal basis: Art. 6(1)(f) GDPR. Details: Cloudflare privacy policy.
No further disclosure of your data to third parties takes place.
7. Transfer to third countries
Using Cloudflare may involve processing in the USA. This is safeguarded by the EU Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.
8. Retention periods
- Messages: until delivery, deleted after 14 days at the latest.
- Account data: until you delete your account. Deletion is possible at any time in the app and removes your account data from the server.
- Sessions: 30 days, after which you need to sign in again.
- Security and connection data: only as long as necessary for secure operation and abuse prevention.
9. Your rights
Under the GDPR you have the following rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21). You can exercise much of this directly in the app: you can export your data encrypted and fully delete your account yourself. For anything else, reach us at [email protected].
10. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority at the controller's location is among those competent.
11. No automated decision-making
There is no automated decision-making or profiling within the meaning of Art. 22 GDPR.
12. Minimum age
PriChat is not directed at children. To use it independently you should be at least 16 years old; otherwise the consent of a legal guardian is required.
13. Changes to this policy
We update this privacy policy when the service or the legal situation changes. The version published here applies. Last updated: July 2026.