Privacy Policy
Effective date: 20 July 2026 · Last updated: 20 July 2026
OvateChat is a private messenger built so that only you and the people you message can read your conversations — not us, not anyone else. This policy explains, in plain language, what information the app handles, what it deliberately cannot see, and the choices you have.
The short version
End-to-end encrypted No ads No tracking or analytics SDKs No selling your data No key escrow
- Your messages, calls-to-content, photos, files, voice notes and shared locations are end-to-end encrypted with the Signal Protocol. Our servers only ever relay opaque encrypted data they cannot decrypt.
- Your private encryption keys are generated on your device and never leave it. We hold no copy and cannot recover them — this is deliberate.
- We collect the minimum needed to run the service: an account handle, the public keys other people need to message you, and basic device/delivery information.
- We do not use advertising, third-party analytics, or trackers, and we do not access your phone's address book.
- You can delete your account — and all of its data — from inside the app.
1. Who we are
OvateChat (the "app", "service", "we", "us") is operated by Ovate Technologies, 1309 Coffeen Avenue STE 1200, Sheridan, Wyoming 82801, United States. For any privacy question or request, contact us at privacy@ovate.chat.
2. Information we collect
We practice data minimisation — we ask for as little as possible, and much of what exists on our servers is encrypted so that even we cannot read it.
| Category | What it is | Why |
|---|---|---|
| Account | A username you choose; an optional email address or mobile number; a display name. Your password or recovery phrase is stored only as a one-way cryptographic hash — never in a form we can read. | To create and secure your account, and to let you sign back in or recover it. |
| Public keys | Your public identity key and prekeys (the public halves of your encryption keys) and a registration id. | So other people can start an encrypted conversation with you. These are public by design; the matching private keys stay on your device. |
| Device | A device label, platform and OS version, app version, device model, and an installation identifier. | To register your device(s), manage multi-device linking, and keep your account secure. |
| Message envelopes | The encrypted ciphertext of messages while in transit, plus delivery metadata (which device sent/received, timestamps) and read receipts. | To deliver messages and show delivery/read status. Encrypted content is not retained after delivery (see Retention). |
| Connections | Your friend/contact relationships (by username) and block list. | To route messages and honour your privacy choices. We do not upload or scan your phone's address book. |
| Optional encrypted backup | If you enable it, an encrypted backup blob. | Stored as opaque data we cannot decrypt — only your recovery credential can. |
| Push token | A notification token from Apple/Google, if you enable notifications. | To wake the app for new messages. Our push notifications are content-less — they never contain your messages. |
| Technical logs | Standard server logs: request identifiers, timestamps, IP address, and error diagnostics. | To operate the service securely and diagnose problems. These never contain message content. |
3. How we use information
- To deliver your encrypted messages and show delivery and read status.
- To create, authenticate and secure your account and your linked devices.
- To send you notifications you've enabled (content-less).
- To send verification or sign-in codes to an email/phone you provide.
- To protect the service against abuse, fraud and security threats.
- To send occasional operational notices (see "In-app announcements").
We use information only for the purposes above. We do not use it for advertising or profiling, and we do not sell or rent it.
No intrusive messaging — by design
Many messaging apps turn your phone number into a public doorway: anyone who has it can find you and message you, and your address book is uploaded to map your social circle. OvateChat rejects that model.
- No phone number needed. An account is a username — your number is never required, and never a way for strangers to reach you.
- Your address book stays on your phone. We never upload or scan your contacts. You connect with people by exchanging usernames yourself.
- You are not discoverable unless you choose to be. Search by email or phone is off by default; you decide if and how people can find you.
- You control who can message you. Restrict direct messages to friends only, require friend requests before anyone can add you, and block or report anyone with one tap.
- Spam accounts can't start conversations. New, unverified accounts cannot initiate contact with strangers — they can only reply to people who contacted them first.
The result: no cold messages from unknown numbers, no harvested contact lists, no unsolicited "who is this?" spam. Every conversation in OvateChat exists because both sides chose it.
4. Encryption
OvateChat uses the Signal Protocol (X3DH key agreement and the Double Ratchet) for end-to-end encryption. Encryption and decryption happen entirely on your devices. On our servers, messages exist only as opaque ciphertext. Your local message history is additionally encrypted at rest on your device.
Learn more: What is end-to-end encryption?
5. In-app announcements
The read-only "OvateChat" channel inside the app carries occasional product news and important operational notices from us. Because these are broadcasts from us, they are not end-to-end encrypted, and the app labels them accordingly. They never contain your personal messages.
6. Data retention
- Message content (ciphertext): retained only until delivered. Once all recipient devices acknowledge a message, its encrypted content is scrubbed from our servers; undelivered messages and media expire automatically after a limited period.
- Delivery metadata and receipts: retained to provide delivery/read status and support the service.
- Account and connection data: retained while your account is active.
- Logs: retained for a limited period for security and troubleshooting.
7. Deleting your account
You can delete your account at any time from Settings → Security → Delete account. When you request deletion:
- Your account is frozen immediately (it stops being reachable and is hidden from search) and scheduled for permanent deletion after a 30-day grace period.
- If you change your mind, simply sign in again before the 30 days elapse and the deletion is cancelled.
- After the grace period, your account and all associated data are permanently and irreversibly deleted from our servers.
8. Sharing and third parties
We do not sell your data and we do not share it with advertisers or data brokers. We rely on a small number of service providers strictly to run the app:
- Push notifications — Apple Push Notification service and Google Firebase Cloud Messaging deliver content-less wake notifications. The Firebase SDK we use is limited to messaging; we do not include Firebase Analytics or any other analytics/tracking SDK.
- Verification codes — an email and/or SMS provider delivers sign-in and verification codes to the address or number you provide.
- Hosting — our infrastructure provider hosts the servers that relay encrypted data.
We may disclose information if required by law, but we can only ever provide what we actually hold — which does not include the content of your end-to-end encrypted messages.
9. Your rights and choices
- Delete your account and data in-app (Section 7).
- Control discoverability — you're found by username or friend request; email/phone discovery is off unless you opt in, and we never upload your address book.
- Access or export — contact privacy@ovate.chat to request a copy of the account information we hold about you.
- Depending on where you live (e.g. the EEA/UK under GDPR, or California under the CCPA), you may have additional rights to access, correct, delete, or object to processing. Contact us and we'll help.
10. Security
Beyond end-to-end encryption, we protect accounts with hashed credentials, session and device revocation, rate limiting, and encryption of your local database at rest. No system is perfectly secure, but privacy is the core of how OvateChat is built.
11. Children
OvateChat is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect information from them. If you believe a child has provided us information, contact us and we will delete it.
12. International transfers
Your information may be processed on servers located outside your country. Because message content is end-to-end encrypted, its confidentiality does not depend on where the ciphertext is relayed.
13. Changes to this policy
We may update this policy from time to time. Material changes will be announced in the app and reflected by the "Last updated" date above.
14. Contact us
Questions or requests: privacy@ovate.chat. For help using the app, see Support.