Privacy Policy

Effective Date: September 29, 2026

This policy explains what personal data island.chat (the "Service") processes, why, for how long, who else receives it, and the rights you have. It should be read together with our Terms of Service. For how the encryption works, see our Security page.

1. Who We Are

The Service is operated by Lion Technologies Ltd., Sofia 1712, Mladost 3, bl. 325, Adm. building, fl. 3, Bulgaria (UIC 130030121, VAT BG130030121), which is the controller of the personal data described here. For any privacy question or request, write to privacy@island.chat.

2. What We Can and Cannot Read

Messages, files, file names and captions, and the names you give your contacts are end-to-end encrypted in your browser before they are uploaded. We store them only as ciphertext and have not built any way for our servers to decrypt them. Your password is never sent to us (we use the OPAQUE protocol), and your private encryption key is stored only inside an envelope encrypted with a key derived from your password.

The only exception is a safety report: when a conversation participant reports specific messages or files, their browser decrypts those items and sends them to us (see Section 3 and Section 4.1 of the Terms). We do not scan, moderate, or otherwise access encrypted content outside that user-initiated flow.

Operational data needed to run the Service is not end-to-end encrypted. The rest of this policy is about that data.

3. What We Process, Why, and on What Legal Basis

  • Account data — your auto-generated handle, OPAQUE registration record, encrypted key envelope, public key, settings (such as message retention and activity sharing), account timestamps, your connections and invitations, and, if you set one up, a passkey's credential ID and public key. We do not ask for your name, email address, or phone number. Purpose: providing the Service. Legal basis: performance of our contract with you (GDPR Art. 6(1)(b)).
  • Message metadata — sender and recipient identifiers, timestamps, delivery and read state, edit and deletion markers, and the size and type of encrypted files, alongside the ciphertext itself. Purpose: delivering and storing your messages. Legal basis: contract (Art. 6(1)(b)).
  • Payment data — payment method type, amount, currency, status, the payment processor's transaction and customer identifiers, a reference to your saved card (never the card number), refunds, refund requests, chargebacks, and any checkout confirmations you previously gave. Card details go directly to Stripe; cryptocurrency payments go through NOWPayments. Purpose: selling and renewing access, handling refunds and disputes, and preventing payment fraud. Legal basis: contract (Art. 6(1)(b)), our accounting and tax obligations (Art. 6(1)(c)), and our legitimate interest in preventing fraud and chargebacks (Art. 6(1)(f)).
  • Security data — IP addresses and request details in server logs; short-lived counters keyed by IP address (IPv6 addresses by network prefix) or by account, used for rate limiting; and the country of your IP address, looked up in a database on our own server, used to block access from countries where we do not offer the Service. Purpose: keeping the Service secure and available, and preventing abuse. Legal basis: our legitimate interests (Art. 6(1)(f)).
  • Error reports — technical reports of server errors (error messages, stack traces, request method, tags). We remove user identifiers, request bodies, headers, and cookies before a report leaves our server. Purpose: finding and fixing faults. Legal basis: our legitimate interests (Art. 6(1)(f)).
  • Safety reports — the items a reporter chooses to decrypt and submit, their explanation and answers, the reporter's IP address and browser timezone, an identity snapshot of both accounts, and a copy of the reported messages as we stored them, all held in an encrypted compliance vault. The full description is in Section 4.1 of the Terms. Purpose: reviewing and acting on reports of illegal content, and cooperating with competent authorities. Legal basis: our legal obligations (Art. 6(1)(c)) and our legitimate interests in child protection, platform safety, and the establishment, exercise, or defence of legal claims (Art. 6(1)(f)). The reporter also confirms, when submitting, that they consent to our processing the content they include.
  • Requests from authorities — see Section 9. Legal basis: legal obligation (Art. 6(1)(c)).

We do not sell personal data, show advertising, use analytics or tracking tools, build profiles, or make decisions about you by automated means that have legal or similarly significant effects.

4. Who Else Receives Data

We use the following service providers. Each receives only what it needs for its task:

  • FlokiNET ehf (Iceland) — hosts our servers, database, and the storage for encrypted files. Iceland is part of the European Economic Area.
  • Stripe — processes card payments. Stripe receives your card details, the amount, and technical data its payment form collects to prevent fraud. We do not give Stripe your handle or account identifier. Stripe also acts as an independent controller for some of this data under its own privacy policy.
  • NOWPayments — processes cryptocurrency payments. It receives a random order number and the amount, not your handle; you complete the payment on its site, under its own privacy policy.
  • Sentry (Functional Software, Inc.) — error monitoring, using its EU data region. It receives the stripped error reports described in Section 3 and, for safety reports, alert metadata only (report identifier, category, priority), never report content.

Where a provider processes data outside the European Economic Area, the transfer is protected by a European Commission adequacy decision or by the Commission's standard contractual clauses. Safety report data may also be shared with authorities and child-protection organizations as described in Section 4.1 of the Terms.

5. How Long We Keep Data

  • Messages and files: according to the retention setting you choose (1 hour, 8 hours, 1 day, 7 days, 30 days, 90 days, 1 year, or until deleted). In a conversation the shorter of the two participants' settings applies to both. Deleting a message removes its encrypted content at once; removing a contact permanently deletes the whole conversation for both people.
  • Account data and payment records in our database: until you delete your account. Deletion is immediate and permanent and also deletes your customer record and saved card at Stripe. Refund requests and their payment references are kept until resolved, then for 90 days, including if you delete your account while a refund is being handled.
  • Payment processors' records: Stripe and NOWPayments keep their own transaction records for the periods their legal obligations require.
  • Server logs: 14 days.
  • Rate-limit counters: expire automatically, at most 24 hours after they are created.
  • Sessions: end after 30 minutes of inactivity and at most 8 hours after login.
  • Encrypted backups: replaced on a rolling schedule; a deleted record leaves the backups within about 30 days.
  • Safety reports: for the periods stated in Section 4.1 of the Terms, which continue even if an account involved is deleted.

6. Cookies and Browser Storage

We use only what the Service needs to work, so no consent banner is required:

  • privacy_chat_session — keeps you logged in; HTTP-only, ends with your session.
  • XSRF-TOKEN — protects your requests against cross-site forgery; expires within an hour.
  • A short-lived entry in your browser's session storage while a cryptocurrency checkout is open in another tab; it is cleared when the tab closes.

When you open the card payment form, Stripe's payment form may set its own cookies to prevent fraud. The Service never writes your decrypted keys, messages, or files to cookies or browser storage.

7. Your Rights

Under the GDPR you have the right to access your personal data, have it corrected, have it erased, restrict its processing, receive it in a portable format, and object to processing based on our legitimate interests. You can delete your account yourself at any time in Settings. For any other request, write to privacy@island.chat. Because accounts have no email address or name, we will ask you to prove that you control the account before acting on a request, and we will answer within one month.

Some rights are limited by law: we may keep data we are legally required to keep, and we answer requests that concern safety reports under the restrictions described in Section 4.1 of the Terms.

You also have the right to lodge a complaint with a supervisory authority — in Bulgaria, the Commission for Personal Data Protection (www.cpdp.bg), or the authority in the EU country where you live or work.

8. Security

Beyond end-to-end encryption, network traffic is protected with HTTPS/TLS, backups are encrypted, and access to safety-report data requires individually granted permissions and is logged. The web application keeps decrypted data in memory only while you use it, but browsers, devices, password managers, screenshots, and extensions may retain traces outside our control. Our Security page describes the design and its limits.

9. Requests from Authorities

We comply with lawful requests while protecting user confidentiality. We verify the validity and jurisdiction of any court order, subpoena, administrative order, or other legal request before responding and disclose only the minimal data held. Stored application records do not contain readable message content or users' decrypted private keys, so those records cannot provide message plaintext. This does not promise protection against a compelled future change to the served application. The Service does not provide forward secrecy, signatures, metadata hiding, protection from malicious frontend code, compromised endpoints, server public-key substitution, long-term-key compromise, or participant forgery. Law enforcement, judicial authority, and EU Digital Services Act authority requests should be directed to legal@island.chat with appropriate legal process. We accept authority communications in Bulgarian and English. Users will be notified of legal requests where legally allowed. We will publish an annual transparency summary, even if no law enforcement requests were received during the reporting period.

10. Minors

The Service is only for people aged 18 or over. If we learn that an account belongs to someone under 18, we handle it as described in Section 1 of the Terms.

11. Changes to This Policy

We will publish any change here with a new effective date, and give notice of material changes in the Service.