This policy explains what ChatVia collects, what we do with it, and what we deliberately don't collect. We've tried to write it in plain English; the legal version is the same content with more commas.
Who we are
ChatVia is operated by Immersive Mobile Designs Private Limited ("ChatVia," "we," "us"). Contact: privacy@chatvia.in.
What we collect
To make the service work, we collect:
- Account info: the email address you sign up with, a display name, and an avatar if you upload one.
- Device identifiers: a per-device ID so we know where to deliver messages.
- Push tokens: APNs (iOS/macOS) or FCM (Android/web) tokens so push notifications reach you. These are stored encrypted at rest.
- Message data: encrypted at rest on India-resident infrastructure. Today, ChatVia operators retain technical access to message contents for incident response; the full end-to-end encryption model, with no operator access, ships at v1.0. See /security for the current posture and the v1.0 plan.
- Metadata necessary for delivery: timestamps, conversation IDs, participant lists. We don't sell, share, or advertise against this data.
- Diagnostic logs: minimal request logs (IP, user agent, status code). Rotated within 14 days.
What we don't collect
- The content of your messages for analytics, advertising, profiling, or model training, ever. (Your messages are stored encrypted at rest only to deliver and back up your conversations. Today operators retain technical access for incident response; no-operator-access end-to-end encryption ships at v1.0. See /security.)
- Your contact list, address book, or social graph beyond people you actually message.
- Browsing or telemetry beyond what's needed to run the service.
- Third-party advertising identifiers. There are no ads in ChatVia.
Cookies and tracking
The marketing site (chatvia.in) sets no tracking cookies and runs no third-party analytics by default. If you opt in to error reporting inside the app, we collect anonymised crash traces via a self-hosted instance, never shared with third parties.
Third parties
To run ChatVia, we rely on a small number of vendors:
- Apple Push Notification service (APNs): delivers push notifications to Apple devices. Notification payloads are encrypted in transit and kept minimal, just enough to wake your device.
- Firebase Cloud Messaging (FCM): same as above, for Android and web push.
- S3-compatible object storage: hosts release artifacts and media attachments, encrypted at rest. Client-side media encryption arrives with the v1.0 end-to-end model.
We don't have any data-broker relationships and don't sell your data to anyone, for any purpose, ever.
Data retention
- Encrypted messages: kept until you or the recipient deletes them, or you delete your account.
- Account info: kept while your account is active. Deleted within 30 days of account deletion.
- Diagnostic logs: rotated every 14 days.
- Push tokens: deleted as soon as you sign out or APNs / FCM report the token expired.
Your rights
Depending on where you live, you have the right to access, correct, export, or delete your personal data. You can do all of these from Settings → Privacy inside the app, or by emailing privacy@chatvia.in.
Account deletion is permanent and unrecoverable. We mean it when we say we don't keep secret backups.
Children
ChatVia isn't directed at children under 13 (or 16 in the EU). We don't knowingly collect personal information from them. If you believe a child has signed up, contact us and we'll remove the account.
Changes
If we change this policy in a material way, we'll notify you in-app and via email at least 30 days before the change takes effect. The "last updated" date at the top of this page reflects the most recent revision.
Contact
Privacy questions: privacy@chatvia.in. Security issues: security@chatvia.in.