Privacy Policy

Last Updated: July 31, 2026

Our Philosophy

Chatit is built on the principle of "private-by-design". We are a "zero-knowledge" platform, meaning we are architected to have no access to your message content. Privacy isn't an option; it's the foundation upon which this application is built.

Our messaging application uses state-of-the-art end-to-end encryption (E2EE). Your messages are encrypted on your device and can only be decrypted by your intended recipient. Neither we, nor anyone else, can read these messages.

This same end-to-end encryption (E2EE) principle applies to our Audio and Video Calls. The call's media stream is encrypted directly between you and the person you're calling. Your private conversations remain private, always.

Data Controller

The controller of the data processed through the Chatit application and website is INNOVATEX DESIGN SRL, registered in Romania, Cluj, Dej, Strada 1 Mai no. 41, Company ID (CUI) 48509212. You can contact us anytime at contact@chatit.ro for any privacy matter.

What Information We Collect (And Why)

We collect the absolute minimum information required for the app to function. We never ask for your real name, email address, or phone number.

1. Information Stored on Our Servers

  • Account Data: When you create an identity, we store your `userId` (a random identifier) and your `publicKey` (your public signing key) on our server. We need your public key to verify the authenticity of messages you send (to prevent spam or identity spoofing).
  • Nickname (Optional): If you choose to set a public "nickname", it will be stored on our server and visible to other users you contact.
  • Push Notification Tokens: To notify you when you receive a new message and the app is closed, we store a `pushToken` provided by Google (Firebase Cloud Messaging) or Apple (APN). This token is anonymous and is not linked to your personal identity, only to your app installation on your device.
  • Messages in Transit: Every message you send is stored on our server in its encrypted form until the recipient's device confirms delivery. That confirmation arrives immediately if the recipient is online, or at their next connection if they are not. A message that stays unconfirmed is deleted automatically after at most 30 days. We can never read these messages: the decryption keys never reach us.
  • Call Signaling: Our server relays connection signals between users so an end-to-end encrypted call can be established. Call content (audio and video) never passes through the signaling server and cannot be heard by us. What we do record: the initial call invitation is stored for at most 2 minutes, while the phone rings, and is deleted once the call is answered, declined, or expires; in addition, we keep two aggregate counters, how many audio and how many video calls were started in total, without recording who spoke with whom. Those same two numbers are published on the chatit.ro homepage.

2. Information Stored Only on Your Device

The following data is generated and stored exclusively on your device. We have no access to it, and deleting the app will permanently remove it (unless you have a manual backup).

  • Mnemonic Phrase and Private Keys: Your complete identity (your 12-word mnemonic phrase, your private signing key, and your private encryption key) is stored in `SecureStore` (an encrypted area of your phone). This data never leaves your device.
  • Application PIN Code: If you set a PIN, it is stored locally in `SecureStore` to lock access to the app.
  • Contact List and Messages: The contacts you add and your entire conversation history are stored locally on your device in an encrypted format. Messages are only decrypted live (in-memory) when you open a conversation. This provides an extra layer of security, protecting your data even if your device's storage is physically accessed.

How We Use Information

We use the collected information (public keys, push tokens) strictly to:

  • Authenticate users and verify message integrity.
  • Route encrypted messages between users.
  • Relay connection signals to establish end-to-end encrypted audio and video calls.
  • Send push notifications when you are offline.
  • Allow the contact list functionality (sharing of nicknames and public keys).

Information Sharing

We do not sell, rent, or share your information with third parties for marketing purposes. The only third parties we interact with are essential service providers for push notifications:

  • Google (Firebase Cloud Messaging) and Apple (Apple Push Notification service): We send them your `pushToken` and a generic notification (e.g., "New Message") to deliver the alert to your device.

International Data Transfers

To deliver push notifications we use Google (Firebase Cloud Messaging) and Apple (Apple Push Notification service), which may process your `pushToken` on servers located outside the European Economic Area, including in the United States. These transfers rely on the European Commission's Standard Contractual Clauses and these providers' own compliance frameworks. We only send them an anonymous token and a generic notification. We never send them your message content, which is end-to-end encrypted.

Data Deletion

You have full control over your data. You can delete your account at any time from within the app by navigating to Settings {'>'} App Data {'>'} Delete All Data. On your device the following are deleted immediately and irreversibly: your identity (recovery phrase and private keys), contact list, message history, call log, PIN, and settings. On our server, upon receiving the request cryptographically signed by your device, we delete your user row, meaning your `userId`, `publicKey`, `nickname`, `pushToken`s, platform, and registration date, together with all messages in transit to you that have not yet been delivered. The deletion is physical, not just logical: freed database pages are overwritten and the transaction journal is compacted immediately.

Deleting your account from the server requires an internet connection. If you press the button without internet, the app tells you and lets you choose: try again, or delete only the data on your phone, in which case the server account remains. You can delete it any time later, because your identifier is derived from your 12 word phrase: restore your identity, press the button again, and the request goes through. Alternatively, write to us at contact@chatit.ro.

What survives deletion, and for how long

Messages you sent to other people remain in the recipient's queue until delivery or for at most 30 days. They are end-to-end encrypted, so we cannot read them, and the recipient is waiting for them; we do not recall them, much as a posted letter cannot be recalled. Backups: up to 7 days. We take a daily encrypted backup of the database with automatic rotation, encrypted with keys the server does not hold, so the server cannot read its own copies. We keep a minimal deletion register consisting only of an irreversible hash of the identifier and a date, solely so that deletions can be reapplied if a backup is ever restored; it is deleted automatically after 30 days. Technical logs: may contain a fragment of the account identifier, and network logs the IP address, for error diagnosis and abuse prevention. Copies held by people you talked to: permanently, and beyond our reach. Your messages, identifier, public key, and nickname that your contacts saved live on their phones, not with us. The very property that stops us from reading your messages also stops us from deleting them. Push notifications: we delete the token from our database, so we can no longer send you notifications, but we cannot revoke it at Google or Apple; it becomes invalid on their side when you uninstall the app. Public statistics: the aggregate counters (messages delivered, calls made) are numbers unconnected to any individual account and are not deleted.

One important thing about your identifier. Your account identifier is not assigned by us: it is computed mathematically from your 12 word phrase. If you restore your account from the same phrase you will get exactly the same identifier, not because we did not delete it, but because it derives from something only you hold. If you want a clean break, generate a new phrase when reinstalling. Note also that if you still have the app installed on a second device with the same identity, that device will re-register your account automatically at its next start.

Minimum Age

Chatit is intended for people who are at least 16 years old. We do not knowingly collect data from anyone under 16. If we learn that we have processed data of someone below this age without the consent of the holder of parental responsibility, we will delete it.

Your Rights (GDPR)

As a data subject under Regulation (EU) 2016/679 (GDPR), you have the following rights:

  • Access: to know what data we hold about you.
  • Rectification: to correct inaccurate data (for example, your nickname).
  • Erasure: to delete your data (the 'right to be forgotten'), directly in the app, at Settings → App Data → Delete All Data.
  • Restriction and objection: to limit or object to certain processing.
  • Portability: to receive your data in a structured, commonly used format.

You can exercise these rights by contacting us at contact@chatit.ro. You also have the right to lodge a complaint with the Romanian supervisory authority, the National Supervisory Authority for Personal Data Processing (ANSPDCP), www.dataprotection.ro.

Cookies (For the Website)

Our website, `chatit.ro`, uses strictly necessary cookies for basic functionality and our own privacy-respecting, first-party analytics (synux.ro), with no tracking cookies, no personal data, and nothing shared with third parties. We do not use advertising cookies.

Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any changes by posting the new policy on this page. You are advised to review this page periodically for any changes.

Contact Us

If you have any questions about this Privacy Policy, you can contact us at: contact@chatit.ro