LEGAL
Privacy Policy
This is a convenience translation; the German version is authoritative.
Last updated: October 2026
KindChat, an end-to-end encrypted messenger with on-device AI protection. Hosted in the EU, no tracking, no profiling.
Controller: sonrisa ventures GmbH, Kleiststraße 35, 10787 Berlin, Germany · hi@kindchat.app
Data Protection Officer: José M. Díaz Delgado · hi@kindchat.app
1. General principles
Our processing follows these principles:
- On-device-first: AI moderation runs primarily locally on your device. For normal moderation, no message content is transmitted to servers.
- End-to-end encryption (E2EE): the provider has, in principle, no access to plaintext.
- No tracking, no profiling.
- Transparency & data minimization.
- EU hosting.
This policy refers to Art. 13/14 GDPR, Art. 50 of the AI Act and the Digital Services Act (DSA).
2. What data we process and why
2.1 Registration and account (mandatory data)
- Phone number (identification and Signal-protocol E2EE)
- Device token for push notifications (APNs/FCM, standard DPA)
- App version, operating system, device model
Purpose: provision, authentication, delivery. Legal basis: Art. 6(1)(b) GDPR. Retention: until account deletion plus statutory periods.
2.2 On-device AI moderation (core function)
Classification of text, image, video and audio happens on your device. The models reside locally. In cases of doubt, your device asks the second check stage (see 2.3).
Only with your consent: contributions to improving moderation. In the app settings under Privacy you can switch on “Help improve moderation”. While the switch is on, we store, for decisions of the second check stage, the checked text in pseudonymized form, together with language, category and decision. These records contain no identifier of your account. Names, phone numbers and email addresses are replaced before storage, as far as our procedure recognises them. The records are pseudonymized, not anonymous. They serve to evaluate and further develop our own moderation model. The switch is off by default, and you can switch it off again at any time; after that, nothing further is stored about your messages. Without this consent, the checked text is discarded after the decision.
Purpose: evaluation and further development of moderation quality. Legal basis: Art. 6(1)(a) GDPR (consent), revocable. Retention: 36 months, then automatic deletion. Storage location: EU only.
Purpose: protection from harmful content. Legal basis: Art. 6(1)(f) GDPR as well as Art. 6(1)(a) (consent for the Care Circle). See AI Transparency.
2.3 Second check stage on EU infrastructure (case of doubt)
If the check on the device cannot decide with certainty, your device sends the text in question and up to five preceding messages of the conversation to our own moderation service on EU infrastructure. This happens before encryption and is done by your device itself. We do not decrypt messages in transit or in storage; the keys required for that reside on the devices. There are two exceptions. Messages that you yourself write to KindChat Support are decrypted by our server, and our support team reads them in order to help you. And if you report a message and consent in the report dialog, your device hands over to us the content of, or the key to, exactly this one message; with that key we open at most this one message. The request to the second check stage is authenticated to protect against abuse; our server recognises your account when it arrives, but passes only the text and the preceding messages on to the checking model, without an identifier of the persons involved. Text and account are never stored together, and the transmitted text is discarded after the decision.
Purpose: protection from serious harm; reporting obligations for criminal offenses. Legal basis: Art. 6(1)(f) and, where applicable, (c). Deletion deadline: the checked text is discarded after the decision. Only with your consent is a pseudonymized version retained (see 2.2). Technical logs without message content: max. 30 days, except where a statutory retention obligation applies. No sharing other than with processors under a data-processing agreement, EU-only.
2.4 Voice messages / voice transcription
Voice messages are currently paused: current app versions (1.1.1 and later) can no longer record, send or play voice messages. As long as older app versions still include the feature, the following applies to them: automated transcription exclusively on the device; upon escalation only the transcript text is checked for content classification on EU infrastructure, never the audio file. Pure content recognition, no emotion recognition (Art. 50(3) AI Act); no biometric data is stored. Legal basis as in 2.2/2.3.
2.5 Care Circle function (optional)
- Consent of the protected person
- Settings and metadata of the protection relationship (not the content!)
- Notifications about protective measures
Purpose: support in managing contacts and protective measures. Legal basis: Art. 6(1)(a) (consent, revocable). No one gains insight into message content.
2.6 Technical and security data
- IP address (short-term, for security and abuse prevention)
- Crash and error reports to our self-hosted error tracker in Germany, without message content. One exception concerns app versions 1.1.1 to 1.1.10: in a report they could include the text of whatever had been tapped, so for a chat message its text and, in groups, also the sender’s display name. They could also include technical identifiers of conversation partners and messages that appeared in requests to our server. Since 22 September 2026 our server no longer accepts reports from these versions; those already received are still stored. From version 1.1.11 the app sends neither tapped text nor these identifiers. On iPhone, at the first start and before it sends anything, it deletes once all reports from older versions that had not yet been sent.
- aggregate usage statistics
Legal basis: Art. 6(1)(f).
2.7 No further data
Your address book never leaves your device. If you want to invite friends through the invite feature, the app may, at your request, read your contact list, purely locally on your device and only so you can choose the people you would like to invite. The address book is never uploaded or stored; only the numbers of the recipients you explicitly confirm are used once to send the invite SMS and are not stored. No location data, no content for advertising or for training external models.
2.8 Children and young people in a Care Circle
People aged 13 and over may use KindChat as a protected member of a Care Circle; clause 1.4 of the Terms of Service says in which countries. The legal basis for the account is the protected member's own contract of use, which the adult holder of the Care Circle enters into for the protected member (Art. 6(1)(b) GDPR). The care functions, that is, the approval of new contacts and group joins, are part of that contract (Art. 6(1)(b) GDPR). Where processing rests on consent, the holder gives it for the protected member and declares it explicitly when the parent code is created (Art. 6(1)(a) in conjunction with Art. 8 GDPR). An age range is asked for, not a date of birth: at signup, and at a sign-in on a new device where the account's age band is not already stored. Only the resulting age band, the time and the country are stored. For protected members we additionally store when the holder made their declaration and which version of it, the identifiers of the Care Circle and its holder, the status of the approval requirement and, where applicable, the date the account was paused. Age range from the operating system: for accounts in the US (decided by the phone number or the declared residence), the app also asks for the age range provided by the device’s operating system or app store, where one is held there; several US states have required such a request since 2026. Only the age range itself is transmitted to us: no date of birth, no name of a guardian, and no platform identifier. It is not stored separately but feeds into the account’s age band, and it takes effect only where it is lower than the person’s own statement; it can never raise an age band. The purpose is the protection of minors. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in effective protection of minors) and, where a legal duty to make the request exists, Art. 6(1)(c) GDPR. The holder approves new contacts and group joins. In doing so they see the display name of the requesting person; for groups the group name, the inviting person and the member count. They have no access to messages, calls or location. The protected member can see at any time in the app that the approval requirement is active and which care functions the holder has granted; there is no covert supervision. Anyone who sends a contact request to a protected member or invites them to a group should know: their display name, and for groups the group name and member count, are shown to the holder of the Care Circle for approval; the holder learns nothing more about the requesting person. Decided approval requests are deleted 90 days after the decision. If the holder refuses a request, the name of the group or community is deleted at once. The legal basis for showing the requesting person's details is Art. 6(1)(f) GDPR (legitimate interest in protecting the protected member). The voluntary consent “Help improve moderation” is not available to protected members. On first launch, protected members receive a child-friendly summary of this policy (Art. 12 GDPR).
3. Recipients / processors
- Hosting: Hetzner Online GmbH in Germany, under a data-processing agreement; no third-country transfer for content data
- Push: Apple/Google (standard DPA, data minimization). What travels is a wake-up signal to the device push address. Depending on its kind, it carries a fixed notice text such as “New message”, the number of unread messages, identifiers that only KindChat can match, and, for an incoming call, the display name of the caller, the type of call (audio or video) and its start time. Apple or Google receive these details and learn that a device was woken and when. They do not receive message content.
- Device check at sign-in and on invite SMS (from app version 1.1.11, on invite SMS from 1.1.13 and only once we switch it on): when you request a sign-in code, the app has Apple (App Attest) or Google (Play Integrity) confirm that the request comes from the genuine KindChat app on a genuine device. On iOS, if it does not have one yet, the app creates a device key for this at the start of sign-in and has Apple confirm it once. A key older than 80 days is replaced at the next sign-in; until the new one is confirmed, the old one remains valid. Apple thereby learns that, and when, a key for KindChat was created on the device, and receives a check value derived from a random number from our server, without your phone number. On Android, each time a sign-in code is requested, Google checks the device, the app and its license status for the Google accounts signed in on the device, and receives a check value derived from a random number from our server, the type of request and your phone number. Because Google never receives the random number, the phone number cannot be worked back out of it. If your account has no device proof yet, for example because you have not signed in again since the device check was introduced, the app checks the device in the same way when you invite someone by SMS; on iOS it creates a device key for this if there is none yet. On Android, Google then receives a check value that is formed anew for each request from our server’s random number and contains no phone number, not even the invited person’s; it can neither be traced back to your account nor linked with other requests. Google keeps the data collected in the process, the check value included, for a fixed period, by its own account. Apple and Google do not receive message content or identifiers of your KindChat account. Processing by Apple and Google may take place in the USA; our server checks the response itself, in the EU. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in fending off abuse of sign-in and invite SMS).
- in the escalation case, only trained internal staff or specialized EU service providers under a data-processing agreement
- no sharing with advertising networks, data brokers, or for training generative AI
- SMS: mobile numbers and SMS consent are never shared with third parties or affiliates for marketing or promotional purposes, and your consent to receive SMS is not passed on to anyone. KindChat texts your number only with sign-in codes and service notices; the SMS providers that deliver them act on our behalf under a data-processing agreement. For some countries (initially Turkey) the SMS is delivered by Twilio Inc., based in the USA, which receives the mobile number and the text of the SMS for that purpose; this also applies to invitation SMS to numbers in those countries. The transfer to the USA is based on the EU-U.S. Data Privacy Framework, under which Twilio is certified, and otherwise on the EU standard contractual clauses; a copy is available on request from hi@kindchat.app.
Where there is a legal obligation (e.g. a court order), disclosure takes place only to the extent permitted.
4. Retention and deletion
- Account/profile until deletion plus 30 days
- Message content only encrypted on the devices; the provider does not store it permanently. The exception is the encrypted backup (part of Plus): if you switch it on, an encrypted copy of your history is held on our servers in the EU, which only your recovery code can open. It is deleted when you switch the backup off or delete your account
- The text sent to the second check stage is discarded after the decision; only with consent is a pseudonymized version retained for 36 months (see 2.2)
- Device key from the device check at sign-in (iOS): we store its identifier, its public key, a counter, the environment (development or production) and three dates without a time of day, with no link to an account, a phone number or an IP address. A key that is never used is deleted 7 days after we stored it, a used one 90 days after its last use; because we store only days and delete once a day, it can take up to about two days longer. On Android, Google's response is checked and not stored.
- Your account’s device proof: we store with your account the time at which it first gave a valid device proof, at sign-in or, from app version 1.1.13, on an invite SMS. Invite SMS from accounts without this proof are held back; invitations by link or through the share menu are not affected. The time is deleted with your account and is part of your data export. The legal basis is Art. 6(1)(f) GDPR (fending off abuse of invite SMS).
- Contact requests: a request that goes unanswered is deleted 30 days after it was sent. An accepted request is deleted 30 days after it was accepted if the person is then among your contacts. If you declined a request or removed a contact, or an accepted request did not lead to a contact, a note remains for as long as both accounts exist, so that the same person cannot ask you again (Art. 6(1)(f) GDPR, protection against repeated unwanted contact). 30 days after the decision, we remove any accompanying text and the information about which group the request came through. Log entries recording who asked whom and how the person who was asked decided, without any content, are deleted after 12 months.
- Blocking: if you block someone, we also store when you did. It is used to tell you, before you join a group of a community, whether someone you blocked before your request is in it; this feature is not switched on yet. If you unblock the person, we delete that time but keep the ended period (start and end) for as long as both accounts exist, also after you add a removed person again. It keeps hidden from you what the person commented on or marked in Pulse during that time, and from the person what you read during that time. If you remove a blocked person from your contacts, the note about the removal keeps the time and stays as described above (Art. 6(1)(f) GDPR, protection against unwanted contact). The information you receive on an access request (Art. 15 GDPR) includes it and your own ended periods.
- Messages that are not delivered: if a message cannot be delivered, for example because the other person does not (or no longer) have you as a contact or you can no longer reach them, we store only what you yourself see about it: who it was to, when, and whether it had an attachment. We do not store its content, and the other person receives nothing of it; to you it looks like any other message that has not been delivered yet. We delete this information after 30 days, after 12 months at the latest if either side is a Plus member, and immediately when either account is deleted. Until then an attachment stays stored end-to-end encrypted; we cannot read it and the other person cannot fetch it (Art. 6(1)(f) GDPR, the legitimate interest of both sides that a block or a removal is not recognisable).
- Technical logs max. 90 days
Account deletion is possible at any time in the app settings; deletion then takes place within 30 days, insofar as no statutory obligations stand in the way.
5. AI transparency under Art. 50 AI Act
AI is used exclusively for classification, not for generation; primarily on-device. We inform you during onboarding, at a moderation decision (notice “Automated check” plus a link to the complaint), and on the website and in the app. Since no synthetic content is created, there is no labeling obligation under Art. 50(2).
Details: AI Transparency page and Terms of Service, section 3.
6. Your rights (Art. 15–22 GDPR)
You have the right to access, rectification, erasure, restriction, data portability, objection and withdrawal. You also have the right to lodge a complaint with a supervisory authority, e.g. the Berlin Commissioner for Data Protection and Freedom of Information (https://www.datenschutz-berlin.de).
Contact: hi@kindchat.app; response within one month (potentially plus 2 months).
7. Security of processing
We apply technical and organizational measures according to the state of the art (E2EE via the Signal protocol, on-device AI, encryption of data at rest, access controls, regular audits). A residual risk cannot be fully excluded.
8. Changes to this Privacy Policy
We adapt this policy as needed. We inform you of material changes via in-app notification or email with reasonable notice. The current version is always available on this page (/en/privacy/).
9. Data processing on this website (kindchat.app)
Waitlist (closed): The waitlist from the beta phase is no longer continued, and signing up is no longer possible via this website. Addresses still on file are processed solely to serve the unsubscribe link in emails already sent. Legal basis: consent (Art. 6(1)(a) GDPR). You can withdraw at any time via that link; the address is then deleted.
Website hosting: Hetzner Online GmbH in Germany (Falkenstein), under a data-processing agreement.
E-mail: our mailboxes at kindchat.app, such as hi@kindchat.app, and the e-mail we send run through united-domains AG.
Analytics: We use Umami, self-hosted within the EU and privacy-friendly. It sets no cookies, stores nothing on your device, creates no personal profiles, and enables no cross-site tracking. Only aggregate, anonymous page-view counts are recorded. Google Analytics is not used. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
Supervisory authority: Berlin Commissioner for Data Protection and Freedom of Information, Friedrichstraße 219, 10969 Berlin.
10. Contact
sonrisa ventures GmbH, Data Protection, email hi@kindchat.app.