Privacy Policy
Effective date: 20 July 2026 · Last updated: 25 September 2026
OvateChat is a private messenger built so that only you and the people you message can read your conversations — not us, not anyone else. This policy explains, in plain language, what information the app handles, what it deliberately cannot see, and the choices you have.
The short version
End-to-end encrypted No ads No tracking or analytics SDKs No selling your data No key escrow
- Your messages, calls-to-content, photos, files, voice notes and shared locations are protected with advanced end-to-end encryption. Our servers only ever relay opaque encrypted data they cannot decrypt.
- Your private encryption keys are generated on your device and never leave it. We hold no copy and cannot recover them — this is deliberate.
- We collect the minimum needed to run the service: an account handle, the public keys other people need to message you, and basic device/delivery information.
- We do not use advertising, third-party analytics, or trackers, and we do not access your phone's address book.
- You can delete your account — and all of its data — from inside the app.
- The one exception to the above: if you report someone, your device sends us the messages you chose to include, so a person can actually review them. Nothing else makes message content readable to us. See Reporting abuse.
1. Who we are
OvateChat (the "app", "service", "we", "us") is operated by Ovate Technologies, 1309 Coffeen Avenue STE 1200, Sheridan, Wyoming 82801, United States. For any privacy question or request, contact us at privacy@ovatechat.com.
2. Information we collect
We practice data minimisation — we ask for as little as possible, and much of what exists on our servers is encrypted so that even we cannot read it.
| Category | What it is | Why |
|---|---|---|
| Account | A username you choose; an optional email address; a display name. Your password or recovery phrase is stored only as a one-way cryptographic hash — never in a form we can read. | To create and secure your account, and to let you sign back in or recover it. |
| Public keys | Your public identity key and prekeys (the public halves of your encryption keys) and a registration id. | So other people can start an encrypted conversation with you. These are public by design; the matching private keys stay on your device. |
| Device | A device label, platform and OS version, app version, device model, and an installation identifier. | To register your device(s), manage multi-device linking, and keep your account secure. |
| Message envelopes | The encrypted ciphertext of messages while in transit, plus delivery metadata (which device sent/received, timestamps) and read receipts. | To deliver messages and show delivery/read status. Encrypted content is not retained after delivery (see Retention). |
| Connections | Your friend/contact relationships (by username) and block list. | To route messages and honour your privacy choices. We do not upload or scan your phone's address book. |
| Optional encrypted backup | If you enable it, an encrypted backup blob. | Stored as opaque data we cannot decrypt — only your recovery credential can. |
| Push token | A notification token from Apple/Google, if you enable notifications. | To wake the app for new messages. Our push notifications are content-less — they never contain your messages. |
| Reports you submit | If you report a conversation, the messages you chose to disclose from your own device (in readable form), the reason you selected, any note you write, and who you reported. | So a person can review what happened and act on it. This is the only circumstance in which message content becomes readable to us — see Reporting abuse. |
| Sign-in record | For each attempt to sign in to an account: the time, the method used, whether it succeeded, the network (IP) address, the country that address belongs to, and the type of device. The country is looked up on our own server from an offline list; your address is not sent to any other company. We never record the password, code or recovery phrase that was entered. | To protect accounts: to notice someone trying to get into an account that is not theirs, such as repeated failures or a sign-in from a country the account has never used. |
| Screenshot notices | When you take a screenshot of a chat (on iPhone, or on Android 14 and later), or start recording your screen while one is open (iPhone only — OvateChat does not detect screen recording on Android), the app tells the other people in that chat. The notice itself is end-to-end encrypted, like any message. What our server can see is the same as for any message — who sent it, in which conversation, and when — plus the fact that this particular message is a screenshot notice, because that label is not encrypted. | So the people you are talking to know their conversation was captured. Each person chooses, in Privacy → Screen security, whether others may capture their chats. While protection is on, on Android the screenshot is refused and on iPhone the chat is hidden from it. Accounts that existed before this choice was added keep protection on; new accounts start with it off. When a chat is captured and the phone reports it, the notice is sent. In a group, the chat stays protected only while every member keeps protection on. |
| Account switched off | If you switch an account off, our server records that it is off and since when. | So the account looks offline on all its devices: messages and calls wait on our server, nothing rings or notifies, no read receipts or typing are sent, and others see your "last seen" as the moment you switched it off. |
| Technical logs | Standard server logs: request identifiers, timestamps, IP address, and error diagnostics. | To operate the service securely and diagnose problems. These never contain message content. |
3. How we use information
- To deliver your encrypted messages and show delivery and read status.
- To create, authenticate and secure your account and your linked devices.
- To send you notifications you've enabled (content-less).
- To send verification or sign-in codes to an email address you provide.
- To protect the service against abuse, fraud and security threats.
- To review reports of abuse that people send us, and to act on them.
- To send occasional operational notices (see "In-app announcements").
We use information only for the purposes above. We do not use it for advertising or profiling, and we do not sell or rent it.
No intrusive messaging — by design
Many messaging apps turn your phone number into a public doorway: anyone who has it can find you and message you, and your address book is uploaded to map your social circle. OvateChat rejects that model.
- No phone number needed. An account is a username — your number is never required, and never a way for strangers to reach you.
- Your address book stays on your phone. We never upload or scan your contacts. You connect with people by exchanging usernames yourself.
- You are not discoverable unless you choose to be. Being findable by your email address is off by default; you decide if and how people can find you.
- You control who can message you. Restrict direct messages to friends only, require friend requests before anyone can add you, and block or report anyone with one tap.
- Spam accounts can't start conversations. New, unverified accounts cannot initiate contact with strangers — they can only reply to people who contacted them first.
The result: no cold messages from unknown numbers, no harvested contact lists, no unsolicited "who is this?" spam. Every conversation in OvateChat exists because both sides chose it.
4. Encryption
OvateChat uses advanced end-to-end encryption. Encryption and decryption happen entirely on your devices. On our servers, messages exist only as opaque ciphertext. Your local message history is additionally encrypted at rest on your device.
Learn more: What is end-to-end encryption?
5. In-app announcements
The read-only "OvateChat" channel inside the app carries occasional product news and important operational notices from us. Because these are broadcasts from us, they are not end-to-end encrypted, and the app labels them accordingly. They never contain your personal messages.
6. Reporting abuse
Because your conversations are end-to-end encrypted, we cannot scan them — not for abuse, not for anything. So there is only one way for us to act on abuse: you show us.
When you report a conversation from inside the app, your device decrypts the messages you chose to include and sends those messages to us in readable form, along with the reason you picked and anything you wrote. The app tells you this at the moment you report, and shows you how many messages are included.
- Only what you send. We receive nothing beyond the messages that report contained. We cannot go and read the rest of that conversation, or any other.
- It is capped and rate-limited — a report carries at most 20 messages, and an account can send at most 10 reports an hour.
- It is deleted. Reports and the messages in them are removed 90 days after the report is closed.
- Only our moderation team sees it, for the purpose of deciding whether our Terms were broken. It is never used for advertising, profiling, training, or anything else.
- The person you report is not told that you reported them.
We aim to review reports of objectionable content and act within 24 hours. To report abuse outside the app, email abuse@ovatechat.com.
7. Data retention
- Message content (ciphertext): retained only until delivered. Once all recipient devices acknowledge a message, its encrypted content is scrubbed from our servers; undelivered messages and media expire automatically after a limited period.
- Delivery metadata and receipts: retained to provide delivery/read status and support the service.
- Account and connection data: retained while your account is active.
- Reports you submit: the report and any messages it contained are deleted 90 days after the report is closed.
- Sign-in record: each entry is deleted after 90 days. The list of countries an account has signed in from is kept while the account exists, and is erased with it.
- Screenshot notices: the notice is a message and is kept like one — its encrypted content is removed once delivered; the record that one was sent stays with the other delivery metadata.
- While an account is switched off: messages sent to it wait on our server until it is switched back on. Photos and files follow the usual expiry — 14 days, or 7 days for large files — so an account left off longer may find some of them no longer available. The on/off record is kept while the account exists.
- Logs: retained for a limited period for security and troubleshooting.
8. Deleting your account
You can delete your account at any time from Settings → Security → Delete account. When you request deletion:
- Your account is frozen immediately (it stops being reachable and is hidden from search) and scheduled for permanent deletion after a 30-day grace period.
- If you change your mind, simply sign in again before the 30 days elapse and the deletion is cancelled.
- After the grace period, your account and all associated data are permanently and irreversibly deleted from our servers.
9. Sharing and third parties
We do not sell your data and we do not share it with advertisers or data brokers. We rely on a small number of service providers strictly to run the app:
- Push notifications — Apple Push Notification service and Google Firebase Cloud Messaging deliver content-less wake notifications. The Firebase SDK we use is limited to messaging; we do not include Firebase Analytics or any other analytics/tracking SDK.
- Verification codes — an email provider delivers sign-in and verification codes to the address you provide.
- Hosting — our infrastructure provider hosts the servers that relay encrypted data.
We may disclose information if required by law, but we can only ever provide what we actually hold — which does not include the content of your end-to-end encrypted conversations. The only message content we ever hold is what a reporter chose to send us about a specific exchange, for as long as that report is retained.
10. Your rights and choices
- Delete your account and data in-app (Section 8).
- Control discoverability — you're found by username or friend request; discovery by email address is off unless you opt in, and we never upload your address book.
- Access or export — contact privacy@ovatechat.com to request a copy of the account information we hold about you.
- Depending on where you live (e.g. the EEA/UK under GDPR, or California under the CCPA), you may have additional rights to access, correct, delete, or object to processing. Contact us and we'll help.
11. Security
Beyond end-to-end encryption, we protect accounts with hashed credentials, session and device revocation, rate limiting, and encryption of your local database at rest. No system is perfectly secure, but privacy is the core of how OvateChat is built.
12. Children
OvateChat is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect information from them. If you believe a child has provided us information, contact us and we will delete it.
13. International transfers
Your information may be processed on servers located outside your country. Because message content is end-to-end encrypted, its confidentiality does not depend on where the ciphertext is relayed.
14. Changes to this policy
We may update this policy from time to time. Material changes will be announced in the app and reflected by the "Last updated" date above.
15. Contact us
Questions or requests: privacy@ovatechat.com. For help using the app, see Support.