Effective Date: September 29, 2026
Welcome to island.chat — a private, invitation-only communication space designed for users who value confidentiality and control over their conversations. These Terms of Service ("Terms") govern your access to and use of our website, web application, and related features (collectively, the "Service"). By accessing or using the Service, you agree to be bound by these Terms and by our Privacy Policy. If you do not agree, please do not use the Service.
You must be at least 18 years old to use the Service. By creating an account or accepting an invitation, you represent and warrant that you are 18 years of age or older and have the legal capacity to enter into a binding agreement. We do not knowingly permit minors to register or use the Service. If we learn that an account has been created by a person under 18, we may immediately suspend or terminate the account and delete related data, except where we preserve information for legal process, abuse reports, safety investigations, reporting to competent child-safety authorities or hotlines, NCMEC/CyberTipline reporting where required or appropriate, fraud prevention, billing disputes, or other retention required or permitted by law.
The Service is not offered in the United Kingdom. Access from the United Kingdom is blocked at registration and login.
Our Service provides a secure, private communication space for consenting users. It is not a social network, public forum, or mass-messaging platform. The Service is designed for private, one-to-one interactions and should only be used in contexts of mutual trust and consent. Any attempt to use the Service for harassment, exploitation, or illegal activity is strictly prohibited.
Your privacy is central to how this Service operates. We minimize data collection, do not use tracking cookies, and provide configurable message retention. For full details on how we process, store, and protect information, please review our Privacy Policy.
We have not built mechanisms for the application backend to decrypt user message content. We cannot scan encrypted message content during honest operation, and safety review depends on user-submitted reports, available metadata, payment records, security logs, and lawful process.
Device Traces Warning: Island.chat is web-only by design, but optional features may leave traces on your device. There is no native app to install and no push-notification token to register, but browser and device features can still retain data. If you allow your browser to save your password or set up Face ID/Touch ID, credentials will be stored in your browser's password manager or device keychain. To minimize device traces, decline password save prompts, skip Face ID/Touch ID setup, use Private/Incognito mode, and manually enter credentials each time.
We built this Service to provide a safe, respectful, and private communication space. To preserve that environment and comply with applicable law, you agree not to misuse the Service in any way.
We retain the right and operational capability to suspend, restrict, or terminate accounts that violate these Terms upon credible report, safety review, investigation, or lawful request.
You may use the Service only for:
You may not:
Violations may result in immediate suspension, account restrictions, preservation of relevant records, safety review, reporting to competent authorities, child-safety hotlines, or NCMEC/CyberTipline where required or appropriate, and/or deletion of data.
If you believe the Service is being used for abuse, exploitation, threats, harassment, fraud, or illegal activity, contact safety@island.chat. If an in-app reporting tool is available, you may also use that flow.
What a safety report contains. Because messages are end-to-end encrypted, we cannot read message content unless a conversation participant voluntarily provides it. When you submit an in-app safety report, your browser decrypts only the specific messages or files you select and uploads them to us together with the report category, your explanation, your answers to jurisdiction questions, your browser timezone, and your IP address at the time of submission. Submission requires your explicit confirmation that you consent to us processing the content you include, and that confirmation is recorded. Reports are limited to defined categories of illegal activity: child sexual abuse and exploitation, grooming, sextortion, human trafficking, threats of violence or self-harm, and other illegal content.
Only content that still exists can be reported. When a message is deleted, we remove its encrypted content from our servers, and removing a contact permanently deletes the whole conversation for both people. Deleted messages and removed conversations therefore cannot be reported from within the app. If you want to report a conversation, report it before removing the contact. You can still use our public reporting form.
The identity snapshot. So that a safety report remains actionable by child-protection organizations and law enforcement even if an account is deleted afterwards, we capture a snapshot at the moment a report is submitted. For the reporter, it records the account handle, account creation and last-login timestamps, and the IP address the report was submitted from. For the reported account, it records the handle, account timestamps, any email on file, payment references (payment method, payment-provider transaction identifiers, and Stripe customer identifier where one exists), and how the account was invited to the Service. This snapshot is encrypted, is accessible only under the controls described below, and — unlike ordinary account data — is not erased when either account is deleted.
A copy of the reported messages as we stored them. For each message included in a report, we also keep a copy of that message exactly as it was stored on our servers at the moment of the report: its encrypted content, the technical values used to encrypt it, the two accounts' identifiers and public encryption keys, and the times it was sent and edited. For images and files, this includes the encrypted file. We cannot read this copy; it lets a participant's key later confirm that the reported content matches what was actually sent. It is kept in the compliance vault for the same period as the report, and — like the identity snapshot — is not erased when the message is deleted, when either person removes the other as a contact, or when either account is deleted.
How report data is protected. Reported content and the identity snapshot are stored encrypted in a compliance vault that is separate from ordinary message storage. Access requires individually granted compliance permissions; ordinary administrative access does not include report content. Every access to report content is logged.
How long report data is kept. Reports in child-protection categories are retained for 365 days, consistent with the one-year preservation period under U.S. law for reports to the National Center for Missing & Exploited Children (NCMEC). Reports in all other categories are retained for 90 days. A specific report may be preserved for longer where it has been referred to an authority, where a preservation obligation applies, or where we reasonably anticipate legal proceedings. Residual report records — including the identity snapshot — are erased on a schedule after a report is closed: no later than 12 months after closure for child-protection categories and 6 months for all others, unless an active preservation obligation applies. Encrypted backup copies age out on our backup rotation schedule (at most about 30 days) after the live copy is deleted.
Who report data may be shared with. Where a report gives rise to a reporting obligation or a serious-safety concern, we may provide the report package to NCMEC, to Bulgarian or other EU member-state authorities, or to Europol, in each case limited to the report at issue. We do not give any authority standing or bulk access. Aggregate, non-content alerting metadata (report identifier, category, priority) is processed by our EU-hosted error-monitoring provider so that reports are reviewed promptly.
No notice to the reported account. We do not notify an account that it has been the subject of a safety report, and we will neither confirm nor deny the existence of a safety report in response to a data-subject request, to the extent permitted by applicable law, because doing so would expose the reporter and could prejudice the prevention or investigation of criminal offences.
False reports. Submitting deliberately false reports is a violation of these Terms and may result in account termination. Report submission is rate-limited.
User-uploaded files are encrypted before storage, so Island.chat generally cannot view or inspect uploaded content. Copyright owners or their agents may send copyright notices to legal@island.chat. If you are submitting a notice under the U.S. Digital Millennium Copyright Act, please include the information required by 17 U.S.C. Section 512. Unless a separate U.S. DMCA designated agent is published for Island.chat, this address is our general copyright and legal notice contact. Please include enough information for us to identify the account, file, link, or other material at issue. We may disable access, preserve relevant records, or take other appropriate action when we receive a valid notice or lawful process.
The Service offers a paid subscription for unlimited messaging at $20 USD for 30 days of access. This fee unlocks unlimited messaging with all your connections for the duration of the subscription period. Pricing is subject to change; any changes will be communicated in advance and will apply only to future subscription periods.
Users without an active subscription may send up to 10 unanswered messages to each connection. Once the other user has sent you any message, you may send 3 more messages before a subscription is required. The same applies to them: they may send 3 messages after receiving yours. If either user in a conversation has an active subscription, both can message freely. Trial usage is tracked permanently per user pair and does not reset if users disconnect and reconnect.
Each payment grants 30 days of access beginning from the date of payment. There are no scheduled or background charges: a card payment is renewed only when you log in after your 30-day period has ended (Section 5.4), and a cryptocurrency payment is never renewed automatically — to continue after it ends, you purchase access again.
If you paid by card (credit, debit, or prepaid) and your 30-day period has ended, we automatically charge $20 to your saved card when you next log in, renewing your access for another 30 days. If you do not log in, you will not be charged. This keeps renewals tied to active use of the Service. Cryptocurrency payments cannot be charged automatically and are not renewed; you purchase access again when you want it.
You may prevent auto-charges by:
You may cancel your subscription at any time through the Settings page. Upon cancellation:
Cancellation stops future charges and keeps your remaining paid access. To return a payment, request a refund under Section 5.8.
We accept the following payment methods:
When you pay by card, your payment details are securely stored with our third-party payment processor (Stripe) so that access can be renewed when you log in after your 30-day period ends (Section 5.4). We do not store your full card number on our servers. Cancelling your subscription, or removing your saved card after your subscription has ended, through Settings removes the saved payment method for future charges on this account.
Everyone gets a 14-day money-back guarantee on their first paid purchase, whether they pay by card or cryptocurrency. Request a refund within 14 days after that payment succeeds and we will return the full purchase price. No reason is required. The guarantee does not restart for renewals or later purchases. Your statutory rights remain unaffected.
Use the refund request in Settings or write to support@island.chat. If you contact support, include your payment reference, or the date, amount and last four digits of the charged card. Never send your full card number, password, or private keys.
A full refund ends the remaining access bought by that payment and stops automatic card renewal. Your account stays open. Ordinary cancellation stops renewal but keeps paid access until its end date and does not itself request a refund.
Card refunds go back to the card charged. Cryptocurrency refunds are handled manually; contact support to agree the refund destination and currency. We refund the full purchase price without a deduction for use. We issue eligible refunds without undue delay and within 14 days of receiving the request; payment providers may take additional time to make the funds available.
This guarantee is additional to your legal rights. EU consumers generally have a 14-day right to withdraw from a distance service contract. Starting access does not waive that right. You may send any clear statement that you wish to withdraw to support or use the refund request in Settings. Refunds or other remedies required by law remain available for later purchases, renewals, or a service that is not provided as promised.
If you initiate a chargeback or payment dispute with your card issuer, we reserve the right to:
Users who have filed chargebacks may still use the Service by paying with cryptocurrency.
You may stop using the Service at any time and delete your account in Settings. Deletion is immediate and permanent: your account, connections, and messages are erased, and any remaining paid access ends without a refund, except as described in Section 5.8.
We may suspend, restrict, or terminate an account that breaches these Terms, as described in Section 4. We may also discontinue the Service, giving reasonable advance notice where we can. Paid access that has not been used when an account is closed is subject to Section 5.8. If we discontinue the Service, we refund prepaid access we will no longer provide.
The Service is provided on an "as is" and "as available" basis. We work to keep it secure and available, but we do not promise that it will be uninterrupted or error-free, and the Service has the security limits described in our Security page and Privacy Policy. You are responsible for keeping your password safe: because your password is never sent to us, we cannot recover your account or your messages if you lose it.
To the extent permitted by law, we are not liable for indirect or consequential loss, or for loss of data, profits, or business, and our total liability to you for any claim relating to the Service is limited to the amount you paid us in the 12 months before the claim arose. Nothing in these Terms limits liability that cannot be limited by law, including for death or personal injury caused by negligence, for fraud, or for gross negligence or wilful misconduct, and nothing in these Terms affects rights you have as a consumer under mandatory law.
These Terms are governed by the laws of Bulgaria and applicable European Union law. If you are a consumer, this choice of law does not deprive you of the protection of mandatory provisions of the law of the country where you live.
We may update these Terms to reflect legal or functional changes. Revised versions will include a new effective date, and we will give notice of material changes in the Service. Changes to fees apply only to future paid periods, as described in Section 5.1.
Island.chat is operated by Lion Technologies Ltd., Sofia 1712, Mladost 3, bl. 325, Adm. building, fl. 3, Bulgaria (UIC 130030121, VAT BG130030121). For support and billing, contact support@island.chat; for legal notices, legal@island.chat; for privacy requests, privacy@island.chat.