Hitodor Chat Privacy Policy
Effective 15 September 2026 ยท applies to the Hitodor Chat apps for Android and iOS
Hitodor Chat is a private messenger. It is built so that we do not need to know who you are, who you talk to, or what you say. This policy explains what little data exists, where it lives, and how long it is kept.
Who is responsible
Hitodor, Munich, Germany ("we"). Contact, including for data-subject requests: hitodorprivacy@outlook.com.
No account, no phone number, no email
You do not register with us. Your identity is a cryptographic key created and kept on your device. We never ask for your name, phone number, email address or contact list, and Hitodor Chat never uploads your contacts.
Your messages and media
- Messages, photos, videos, voice notes and Circle (group) conversations are end-to-end encrypted on your device. Only the people you are talking to can read them. We cannot.
- Our relay servers store encrypted envelopes only until they are delivered, and for no longer than 30 days. Encrypted attachments expire after at most 30 days.
- Photo and video location metadata is removed on your device before anything is encrypted and sent.
Contacts and invitations
- A contact is added only when an invitation is accepted, or when you approve a request made from your card. No server receives or reconstructs your contact list or your social graph.
- Our invitation service stores an encrypted invitation, its signed offer, a use count and its expiry. It is deleted when the invitation expires (at most 7 days) or is revoked. It never stores who received or accepted it.
- If you publish a card or handle, the card you choose to publish is public so that people can send you a request.
Network privacy
The app reaches our services through Oblivious HTTP (OHTTP), which encrypts each request so that the relay forwarding it cannot read it. During this alpha, that relay and our services are operated by the same organisation, so we do not claim that no single operator could see both your network address and your requests. Mailboxes on our relay are not linked to any account, name or phone number.
Notifications
To wake the app when something arrives, we use Apple Push Notification service on iOS, and on Android a UnifiedPush distributor app that you choose and install (Hitodor Chat contains no Google Firebase code). The push service gives the app a push address or token, which we store so a wake-up can be delivered. A push contains only an app identifier, an opaque wake token and a collapse identifier. It never contains message content, sender names or who is writing to you.
What we do not do
- No analytics, advertising, advertising identifiers, trackers or crash-reporting services in the app.
- No selling or sharing of personal data.
- No reading, scanning or profiling of your conversations. We have no ability to do so.
Operational data on our servers
To keep the service running and protect it from abuse, our servers count events in aggregate (for example, how many messages were relayed in an hour). These counters never contain mailbox identifiers, invitation identifiers, key fingerprints, message content or per-conversation data.
Adults only
Hitodor Chat is for people aged 18 and over. When you first open the app you confirm that you are an adult; that confirmation is stored on your device only and is not sent to us.
Data on your device, and deletion
Your keys, conversations and media are stored on your device, protected by your device's security. Deleting the app deletes them. Anything left on our servers expires automatically as described above. Backups of keys are made only if you explicitly create one yourself.
Legal basis and your rights (EU/EEA)
We process the limited data above to provide the service you ask for (Article 6(1)(b) GDPR) and to keep it secure (Article 6(1)(f) GDPR). You have the right to access, rectify, erase, restrict or object to processing, and to data portability. Because we hold no account and cannot link server data to you, we may be unable to identify data relating to you; contact us and we will help where we can. You may also complain to your data protection supervisory authority.
Changes
If this policy changes, the new version will be published here with a new effective date.