Privacy Policy

Last updated: 2026-09-11

This Privacy Policy explains how AmeChat processes personal data when you use our messaging service, under the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and the German Telecommunications Digital Services Data Protection Act (TDDDG).


1. Who we are

1.1 Data controller

The controller responsible for processing your personal data is:

AmeChat UG (haftungsbeschränkt)
Werderstraße 30
12103 Berlin
Germany

Registered in the Commercial Register (Handelsregister) at the Amtsgericht Charlottenburg (Berlin) under HRB 288604.

Privacy contact: [email protected]
General contact / legal notice: see our Impressum

1.2 Scope

This policy applies to the AmeChat applications and website (collectively, the "Service"): a cloud-based messenger in which you can exchange messages with other people and interact with a built-in AI assistant within the same conversations.

This policy does not cover third-party services you may link to or use outside AmeChat.

1.3 Our approach to your data

  • We do not show advertising in AmeChat.
  • We do not sell, rent, or trade your personal data.
  • We do not use the content of your conversations to build advertising or marketing profiles, and we never target you based on sensitive attributes.
  • We collect and keep only what we need to operate a secure, useful messenger.

2. What data we collect

We group the data we collect by what it relates to.

2.1 Your account

Account & identity data — your username/handle, the email you register with, and your password, which we store only as a cryptographic hash (never in plain text), plus any profile details you add. We do not collect phone numbers.

Third-party login data — if you sign in with Google or Apple, we receive: from Google, your account identifier, email and its verification status, name, and profile picture; from Apple, your account identifier, email and its verification status, and your name on first sign-in. Our use of data received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. You can disconnect a linked login in your account settings or revoke access from your Google/Apple account; this does not affect data we already received.

Account verification & anti-abuse data — when you register, we store the date, time, and IP address of registration and verify your email by a one-time code (double opt-in), to confirm account ownership and detect or trace misuse. Unverified registrations are automatically deleted after 24 hours.

Age assurance data — the Service is for adults only (Section 9.3). We do not ask for your date or year of birth and collect no data about your age. When your account is created we record the minimum age in force at that moment, together with the date, as part of the record of your acceptance of our Terms of Service. We do this to comply with our legal obligations to keep minors off the Service (Art. 6(1)(c) GDPR) and, where no such obligation applies, on the basis of our legitimate interest in operating an adults-only service (Art. 6(1)(f) GDPR).

Billing data — if you buy a subscription or credits: your plan, transaction history, and billing status. Your card details go directly to our payment provider (see Section 6.1) and never touch our servers; we store only a payment reference.

App store data — if you install our apps from a third-party app store (e.g. Apple App Store, Google Play), that store collects the data needed for the download under its own privacy policy, outside our control. We process information from the store only as needed to provide the app.

2.2 Your conversations

Message content & communications data — the messages, media, attachments, and voice messages you send and receive, group memberships, and conversation metadata (timestamps, delivery/read status). Because it is user-generated, message content may occasionally contain information that GDPR treats as special category data (see Section 3.2).

Voice message & transcription data — voice messages and, where the feature is used, their text transcriptions (see Section 5.2).

Call data — when you make or receive a call, we store a record of the call itself, not the conversation in it: who called whom and in which chat, whether it was audio or video, when it started, was answered and ended, how long it lasted, who hung up, the device you took it on, and how it ended (answered, declined, missed, or failed to connect). The same record appears as an entry in your conversation, visible to both of you. We do not record, listen to, or store the audio or video of your calls.

On Apple devices, calls are handled through the system call interface (CallKit), so an AmeChat call rings and behaves like a phone call. Because of that, the call is also written to your device's own Recents list, together with the other person's name, the time, the duration and whether it was video. That entry belongs to the operating system rather than to us: we do not send it anywhere, but if you use iCloud, Apple may sync your device's call history to your other Apple devices under Apple's own privacy terms. You can delete these entries in the Phone app. On other platforms no such system entry is created.

Presence data — online status, typing indicators, and "last seen". Online status and typing are processed transiently (held briefly in memory, not accumulated into a history). "Last seen" stores only your most recent value, updated when you go offline, and is shown according to your visibility settings (see Section 8.1).

2.3 Your AI

AI interaction data — the conversation content you choose to share with the AI when you invoke it, the AI's responses, and the AI memory you enable (see Section 5.1).

Usage & credits data — the number of AI requests or credits you consume, your remaining balance, and which model was used. We use this to provide and meter the Service.

2.4 Technical and support data

Technical & usage data — device and app information, IP address, the approximate (country-level) location we derive from it via our CDN, and connection and session logs and diagnostic data. We use these to operate, secure, and troubleshoot the Service, to route your data to the correct region (see Section 4), and to meet our legal and sanctions obligations. We do not derive precise or GPS-level location from your IP address.

Crash & diagnostic reports — when the app crashes or hits a serious error, it sends us a technical report: where in our code the failure happened (the stack trace), the app version and build, your device model and operating system version, and a short trail of the technical events leading up to it. These reports are for finding and fixing faults. They are not designed to carry the content of your conversations, and we filter them before they are sent so that message text, your email address, and access tokens are not included.

Support data — information you provide when you contact us for support.

2.5 Your settings

Settings & preferences — the choices you make in the app, which we store on our servers so that they follow you across your devices: your privacy settings (who can see your "last seen", profile photo and bio, who can add you to groups, who can message you, and who can call you), your interface language, your block list, the conversations you have muted together with your other per-conversation preferences, the AI settings of conversations you administer, and the messages you have pinned for yourself. Your block list necessarily records whom you have blocked, so it also contains data about that person. Your app appearance (light or dark theme) is kept on your device and is not sent to us.


3. How and why we use your data

PurposeData usedLegal basis
Creating and managing your accountAccount & identity dataPerformance of a contract — Art. 6(1)(b) GDPR
Transmitting, storing, and syncing your messages between peopleMessage content & communications dataPerformance of a contract — Art. 6(1)(b) GDPR
Showing presence (online status, last seen, typing) to people you communicate withPresence dataPerformance of a contract — Art. 6(1)(b) GDPR
Setting up and connecting your callsCall dataPerformance of a contract — Art. 6(1)(b) GDPR
Providing the AI assistant when you invoke itAI interaction dataPerformance of a contract — Art. 6(1)(b) GDPR (the AI feature you requested)
Metering usage and managing creditsUsage & credits dataPerformance of a contract — Art. 6(1)(b); abuse/fair-use enforcement — Art. 6(1)(f)
Transcribing voice messagesVoice & transcription dataPerformance of a contract — Art. 6(1)(b) GDPR
Keeping the Service secure, preventing abuse/fraud/spam, ensuring stabilityTechnical & usage data, reportsLegitimate interests — Art. 6(1)(f) GDPR
Diagnosing crashes and errors so we can fix themCrash & diagnostic reportsLegitimate interests — Art. 6(1)(f) GDPR
Responding to support requestsSupport dataPerformance of a contract / legitimate interests — Art. 6(1)(b)/(f)
Keeping minors off the Service (adults-only age requirement)Age assurance data (the minimum age in force when the account was created — no data about your age is collected)Legal obligation — Art. 6(1)(c); legitimate interests — Art. 6(1)(f) GDPR
Complying with legal obligations (e.g. lawful requests, retention duties)As requiredLegal obligation — Art. 6(1)(c) GDPR

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You can object to such processing (see Section 9.1).

You are not legally obliged to provide personal data, but without certain data (for example your account details and basic technical/log data) we cannot provide the Service.

3.2 Special category data

Because messages are written freely by users, they may occasionally contain information that GDPR treats as sensitive (for example data revealing health, religion, or political opinions). Our position is:

  • For person-to-person messaging, AmeChat acts only as a technical conduit: we transmit and store this content to deliver the Service and do not analyse, scan, or profile it. The user who writes the message determines its content.
  • The AI processes conversation content only where it has been switched on — in a direct chat with the consent of both participants, and in a group by its admin — and only for messages sent after that point (see Section 5.1). When the AI is invoked, the relevant context, which can include messages from other participants, is sent to the AI provider.
  • We never profile, segment, or target users on the basis of sensitive attributes.

4. Where and how we keep your data

4.1 Where your data is stored

Your account, messages, conversation metadata, and AI memory are kept in our own databases hosted in the EU and replicated across three data centres for resilience — Nuremberg and Falkenstein in Germany, and Helsinki in Finland (all in the EU). Media you send — photos, files, and voice messages — is stored in Cloudflare R2 configured with EU jurisdiction, so it also stays in the EU. At rest, your data is stored in the EU, and delivery runs over Cloudflare's global network. Some processing takes place outside the EU/EEA — most notably when you use the AI or voice features — under the safeguards in Section 6.

Your connection reaches us through Cloudflare's network, which acts as our content delivery network (CDN) and entry point. Cloudflare routes the connection and can see connection metadata such as your IP address, and TLS terminates at this edge — but your message content stays encrypted under the Noise Protocol all the way to our servers (see Section 4.2), so it is never readable at the edge. Media — photos, files, and voice messages — is delivered through the CDN instead, over standard HTTPS.

4.2 Encryption

  • In transit: your connection is protected by the Noise Protocol (the Noise_IK handshake — X25519 key exchange, ChaCha20-Poly1305 authenticated encryption, SHA-256). This is an encryption layer on top of standard TLS, not a replacement for it: TLS can terminate at our network edge, but the Noise channel stays encrypted from your device all the way to our gateway, so your traffic is never exposed in plain text at the edge. This covers your messaging connection; media transfers use standard HTTPS.
  • At rest: data is encrypted with AES-256 — full-volume (LUKS) encryption for our databases and storage, server-side AES-256 for media held in Cloudflare R2, and backups encrypted client-side with AES-256 before they leave the machine.
  • Calls: the audio and video of a call are encrypted end-to-end between the participants' devices using DTLS-SRTP, the standard for real-time media — the keys never leave your devices, and we cannot listen in. The app shows an emoji key for each call: if it matches on both screens, no one is in the middle. Every call is relayed through our own TURN servers in the EU rather than connecting your devices directly. We do this deliberately: it means the person you are talking to never learns your IP address, which a direct connection would reveal. The relay forwards the encrypted packets and sees the IP addresses of both sides, but cannot decrypt what flows through it. Our servers otherwise handle only the signalling needed to set the call up.

AmeChat is not an end-to-end encrypted messenger. Your messages are encrypted in transit and at rest, but — so the built-in AI can work and your chats sync across devices — they are processed on our servers, which can technically access their content (see Section 4.3). If you need end-to-end encryption, where no one but the participants can ever access message content, AmeChat is not the right tool for you.

4.3 Server-side processing

Because AmeChat includes a built-in, server-side AI assistant, message content is processed on our servers, and our infrastructure can technically access content in order to deliver these features. We do not read your private person-to-person conversations to analyse, profile, or advertise to you; for ordinary messaging between people, AmeChat acts purely as a conduit that transmits and stores your messages so you can use them across devices. The AI receives the content of a conversation only when it is enabled and invoked (see Section 5.1).

4.4 Security measures and data breaches

We apply organisational and technical measures appropriate to the risk, including access controls and secrets management. We maintain procedures to detect and handle personal-data breaches and will notify the competent supervisory authority and affected users where the GDPR requires it (Art. 33–34).


5. The AI and voice features

5.1 The AI assistant

The AI is a built-in participant in AmeChat, but it does not silently read your conversations.

  • Where the AI is active. The AI takes part in your conversations in three ways:

    • In a personal AI chat — a chat you open directly with one or more AI models — the AI is the other party and is always active.
    • In a direct (one-to-one) chat with another person, the AI is off until both participants consent; either of you can turn it off at any time (switching it back on requires fresh consent from both).
    • In a group or channel, the admin turns the AI on or off.
  • What the AI sees. In a personal AI chat, the AI sees the messages you send it. In a chat with other people, once the AI is turned on it can see only messages sent after that point — never your earlier conversation; if it is turned off and on again, it starts afresh from the later point. When the AI is invoked in a group, the context can include messages from other participants, and members can see that the AI was invoked. The context passed to the model also includes emoji reactions on the messages in it and the display names of the participants whose messages and reactions it contains, so the AI can tell who said what.

  • Transparency. In line with the EU AI Act (Art. 50, applicable from 2 August 2026), it is always made clear to you when you are interacting with an AI rather than a human.

  • What the AI can access. When invoked, the AI may process the relevant context shared with it — this can include not only text messages but also images and documents that are part of that context, together with any custom AI instructions you have set. The AI assistant can also perform web searches to answer your request.

  • Image generation. When you ask the AI to generate an image, or generate one directly with an image model, the image prompt and the reference photos you choose are sent to the provider of the selected image model (OpenAI or Google). Generated images are stored by us as ordinary chat media; the no-training and retention commitments below apply to these requests as well.

  • Smart mode. In chats where the AI is already enabled, you (in a direct chat) or an admin (in a group) can put the assistant in Smart mode, where it decides on its own when to join in. To make that call, recent messages in the conversation are analyzed automatically — including by a lightweight AI model — for the sole purpose of deciding whether the assistant should reply. This happens only in chats where AI presence was consented to as described above; the analysis creates no additional stored copy of your messages and is never used to train models.

  • How the AI accesses your data (privacy by design). The model has no standing access to our databases, your stored message history, or your files. Each time the AI is invoked, we assemble only the context needed for that single request — which, where AI memory is on, may include relevant facts retrieved from your own memory — and pass it to the model. Neither the model nor any external AI provider can query or pull data from our systems on its own.

  • AI memory. Memory is on by default, and it is yours to control: you can turn it off at any time in the AI settings, and view, edit or delete what it holds (see below). When on, the AI remembers facts from the conversation, stored in our EU database (Section 4) as a knowledge graph (the facts, the people and things they refer to, and the links between them), each with a vector embedding. The embedding vectors are computed by OpenAI from the text, but the memory itself is held by us — not by the AI provider. There are two kinds:

    • Personal memory — your own memory, used only in your direct (one-to-one) chats. It is private to you.
    • Shared chat memory — memory that belongs to a specific chat. In a direct chat, if it is turned on it is shared with and visible to both participants and works only within that chat. In a group chat, the admin controls whether it is on; when it is, facts are drawn from the group conversation and shared within that group.

    Memory updates over time — newer facts supersede older ones, and facts you stop referring to fade. You can view your memory and delete individual facts, or clear it, at any time; deletions are honoured under Art. 17 GDPR.

  • Models and providers. AmeChat offers models from Anthropic (Claude), OpenAI (GPT), and Google (Gemini). Model inference takes place partly outside the EU, so when you use the AI your content is transferred internationally under the safeguards in Section 6. The provider, region, and transfer mechanism for each model are listed in our sub-processor list.

  • No training, limited retention. We require, by contract (Art. 28 DPA), that AI providers do not use your prompts, outputs, embeddings, or conversation content to train or improve their models, and do not disclose them to third parties. For abuse-monitoring purposes a provider may retain inputs and outputs for a short period — currently up to 30 days — after which they are deleted.

5.2 Voice messages and transcription

When voice messages are transcribed to text:

  • Transcription is performed by OpenAI; only the audio is sent for that purpose. Because the processing takes place partly outside the EU, the audio is transferred under Section 6, subject to our no-training requirement.
  • We perform speech-to-text transcription only. We do not create voiceprints, perform speaker identification, or otherwise process your voice as biometric data. Pure transcription is not biometric/special-category data under Art. 9 GDPR.
  • Transcribing a voice message you have received is part of providing the Service to you (Art. 6(1)(b) GDPR). We consider that the separate consent of the sender is not required, because they chose to send the message to you.
  • The resulting transcribed text is treated as ordinary message content.

6. Who we share data with and international transfers

6.1 Recipients and processors

People you communicate with

When you send messages or share information, it is delivered to the people and groups you choose. They can store or re-share what you send them; we cannot control what recipients do with it.

Service providers (processors)

We use carefully selected providers ("processors") who process data on our behalf under a data processing agreement (Art. 28 GDPR). For each processor we record its full legal name, address, function, server location, and transfer mechanism in our sub-processor list. Our current processors include:

  • Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany — cloud hosting and infrastructure. Data centres in Nuremberg and Falkenstein (Germany) and Helsinki (Finland) — all within the EU. Data processing agreement (AVV) in place.

  • Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA — media storage (R2), backups, content delivery, and network/ingress. Our R2 buckets are configured with EU jurisdiction, so your media is stored and processed in the EU. Cloudflare's DPA is in place; for any processing outside the EU it relies on the EU–US Data Privacy Framework (Cloudflare is certified) and SCCs.

  • Plus Five Five, Inc. (operating as Resend), 2261 Market Street #5039, San Francisco, CA 94114, USA — transactional email (account verification, password reset, delivery notifications). Transfer via the EU–US Data Privacy Framework (certified) and SCCs.

  • Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland — payment processing for subscriptions and credit packs bought on our website. Your card details go directly to Stripe; Stripe processes them as an independent controller for payment execution and fraud prevention under its own privacy policy. Transfers within the Stripe group are covered by the EU–US Data Privacy Framework and SCCs.

  • Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland — purchases made inside our iOS app. Apple is the merchant of record: it takes the payment, issues the receipt, and handles refunds and billing enquiries as an independent controller under its own privacy policy. We never see your payment details; Apple passes us only the transaction and subscription status we need to activate your plan. Transfers within the Apple group are covered by the EU–US Data Privacy Framework and SCCs.

  • Functional Software, Inc. d/b/a Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA — crash and error reporting for our apps (see Section 2.4). Report data is stored in Sentry's EU region (Frankfurt, Germany); our own account and organisation metadata are held in the USA. Data processing agreement in place; transfers via the EU–US Data Privacy Framework (certified) and SCCs.

  • AI inference providers — when you invoke the AI (see Section 5.1), the relevant context is sent to the provider of the model you use:

    • Anthropic, PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, USA (Claude) — transfer via SCCs (incorporated in Anthropic's DPA).
    • OpenAI OpCo, LLC, 1455 3rd Street, San Francisco, CA 94158, USA (GPT models and image generation) — transfer via SCCs (incorporated in OpenAI's DPA). OpenAI also processes voice audio for transcription (Section 5.2) and generates the embeddings used for AI memory (Section 5.1).
    • Google (Gemini models and image generation) — transfer via the EU–US Data Privacy Framework and SCCs.

    All under a contractual no-training / no-disclosure commitment (see Section 5.1).

  • Push notification providersGoogle (Firebase Cloud Messaging) delivers notifications to your device, and Apple Push Notification service (APNs) delivers them on Apple devices. Transfer via the EU–US Data Privacy Framework and/or SCCs. Push payloads are encrypted and carry no message content or sender name — only an encrypted envelope and a generic "New message" fallback; your device decrypts the notification locally.

  • Google Workspace — our business email and the mailbox behind [email protected]; it processes correspondence you send us (e.g. support or data-protection requests). Transfer via the EU–US Data Privacy Framework and/or SCCs.

A current, itemised list of our processors and sub-processors is maintained at /subprocessors.

Categories of recipients

Your data may be shared with three kinds of recipients:

  • Processors (Art. 28 GDPR) who act only on our instructions — for example our hosting, storage, AI inference, and transcription providers (listed above).
  • Independent controllers who decide on their own processing — for example app stores (when you download our apps) and third-party login providers (Google or Apple) when you choose to sign in with them.
  • Joint controllers (Art. 26 GDPR) with whom we determine the purposes of a specific, limited processing operation — the advertising platforms we use to measure our advertising on our website (Google Ads, Meta). This runs only with your consent (see Section 9.2) and never involves the content of your conversations.

We may also disclose data to professional advisors (e.g. our tax accountant or lawyers, for bookkeeping or to establish or defend legal claims) and to public authorities where legally required (see Section 6.3). We never sell your data.

6.2 International transfers

Your data is stored in the EU (see Section 4). Some processing takes place outside the EU/EEA — most notably when you use the AI or voice features, where the content you send is transferred to providers outside the EU/EEA (currently in the US). Where that happens we rely on:

  • an adequacy decision (the EU–US Data Privacy Framework) where the provider is certified — currently Cloudflare, Google, Apple, Stripe, Resend, Sentry, and Meta; and/or
  • Standard Contractual Clauses (SCCs) approved by the European Commission, on which we rely for providers that are not DPF-certified — currently Anthropic and OpenAI.

This is always subject to our no-training and retention requirements (Section 5.1). The provider, region, and transfer mechanism for each model are recorded in our sub-processor list. You may request a copy of the relevant safeguards.

We may access, preserve, and disclose your data to public authorities or other parties where we have a good-faith belief that it is necessary to:

  • comply with applicable law or a valid legal request, after a legal review of the request;
  • enforce our Terms or investigate potential violations;
  • detect, prevent, or address fraud, security, or technical issues; or
  • protect the rights, property, or safety of our users, the public, or AmeChat — including emergency disclosure to prevent a risk of death or serious harm.

We disclose the minimum necessary. Note that providers located outside the EU may themselves be subject to legal process in their own jurisdiction (see Section 6).

6.4 Business transfers / change of control

If AmeChat is involved in a merger, acquisition, restructuring, insolvency, or sale of assets, your personal data may be transferred to the successor or acquiring entity. We will do so in accordance with applicable data protection law and will inform you of any material change to who controls your data.


7. How long we keep your data

Account deletion. When you delete your account, we ask you to confirm it with a code sent to your email address. Once you confirm, the deletion is immediate and irreversible: there is no grace period, it cannot be cancelled, and neither your account nor your data can be restored — not by you, and not by us. Your profile disappears for other users and all sessions are signed out at once; the permanent erasure of your data is then completed without undue delay, and at the latest within one month (Art. 12(3), 17 GDPR).

What erasure destroys. Your profile and everything in it, your credentials and key material, your AI memory and AI consents, your private conversations (saved messages, notes to yourself, the service chat, and your chats with the AI) together with the attachments in them, and your membership of groups and channels. Your settings and preferences, including your privacy settings and block list, are erased with it.

What remains. Messages and attachments you sent in shared conversations, and the reactions you left there, stay with the people you were talking to: deleting them would rewrite other people's conversations, removing content they still see and rely on. What we destroy is the link to you — your authorship is replaced with a deleted account, so the content no longer identifies you. Also kept:

  • billing records, for the statutory periods listed below;

  • a keyed cryptographic hash of your email address (not the address itself), together with the date and count of deletions, to enforce anti-abuse cooldowns when the same address is used to register again (legitimate interests — Art. 6(1)(f) GDPR).

  • Account data: kept while your account is active; erased after account deletion as described above, subject to any legal retention obligations.

  • Messages & media: kept until you delete them. There is no automatic deletion. If you delete a message, copies may remain with the recipients until they delete them too. Deleting your account does not remove what you sent in shared conversations — see above.

  • Call records: kept for 12 months, then deleted automatically. The entry in your conversation stays until you delete it, like any other message.

  • AI memory: kept while the feature is enabled; deletable on request.

  • Settings & preferences: kept while your account is active; erased with your account.

  • Usage & credits records: kept while your account is active.

  • Billing records: kept for the statutory commercial and tax retention periods (up to 10 years), then deleted.

  • Presence data: online status and typing are transient; "last seen" stores only your most recent value, overwritten as you go offline.

  • Crash & diagnostic reports: kept for 90 days, then deleted automatically.

  • Server logs: kept for 30 days, then deleted automatically.

  • Backups: encrypted backups rotate on a fixed cycle and age out within about 35 days — data erased from our live systems disappears from backups as they rotate. Backups are used only for disaster recovery, never to restore data you have deleted.

  • Security & abuse-prevention logs: kept for up to 90 days where needed to detect, investigate, and act on abuse, fraud, or security incidents (including handling reports under the DSA), then deleted or irreversibly anonymised.

Where no specific period is stated above, we keep personal data only for as long as necessary for the purpose, then delete or irreversibly anonymise it, unless a legal retention obligation requires us to keep it longer.


8. You and other people

8.1 What others can see about you

Some information is, by design, visible to other people on AmeChat.

Your public profile — visible to people you communicate with (and to anyone who finds you by username, see "Discoverability" below):

  • your username (your public identifier);
  • your display name (this does not need to be your real name);
  • your profile photo if you set one — or, if you don't, an avatar generated from the initials of your display name;
  • your bio / "about" text, if you add one.

Other users can set a private nickname for you in their own contacts (for example "Mom"). This is only for their own view and does not change your public profile.

Your activity — visible to people you communicate with:

  • Presence — your online status and "last seen". You can turn this off, and choose how precise it is, from a vague "recently" up to an exact time.
  • Typing indicators — shown to the people you are chatting with while you type.
  • Delivery and read receipts — you can disable read receipts; if you do, you will no longer see other people's read receipts either (it works both ways).

Discoverability Other people can find and add you by your username only — not by your email address.

Your contacts are yours We do not upload or scan your device address book. Your AmeChat contacts are only the people you have actively chosen to add.

Visibility controls You can restrict who sees your presence/"last seen" and profile photo — for example, to your contacts only.

Groups and channels

  • In groups, other members can see your public profile and that you are a member.
  • In channels (one-to-many broadcast), your membership/subscription is not visible to other subscribers — only to the channel's admins and creators.

Forwarding You can forward messages to other chats, including to AI chats. A forwarded message shows the original author's display name and username.

Location Your location is shared only if you choose to send it in a chat, where it is delivered like any other message.

Screenshots Other users can capture screenshots or copies of your messages and profile. We cannot prevent this and are not responsible for what recipients do with content you share with them.

8.2 Information we receive from others

We may receive information about you from other people, for example when another user sends you a message or adds you to a group.

We do not ingest other users' device address books, so other people cannot expose your contact details to us by syncing their contacts.

We rely on the people who provide such information having the right to share it.

8.3 Reporting and moderation

To keep AmeChat safe and to meet our obligations as a digital service (including under the EU Digital Services Act / German DDG), users can report messages or accounts.

  • When you report content, or when another user reports you, we process the reported content and information about both the reporting and reported accounts in order to review the report and take appropriate action.
  • Legal basis: legitimate interests in safety and abuse prevention (Art. 6(1)(f)) and, where applicable, compliance with a legal obligation (Art. 6(1)(c)).
  • The rules on what is prohibited, how reports are handled, and your options to appeal are set out in our Terms of Service.

9. Your rights and choices

9.1 Your rights

Under the GDPR you have the right to:

  • Access your personal data (Art. 15)
  • Rectify inaccurate data (Art. 16)
  • Erase your data (Art. 17)
  • Restrict processing (Art. 18)
  • Data portability (Art. 20)
  • Object to processing based on legitimate interests (Art. 21)
  • Withdraw consent at any time, without affecting prior processing (Art. 7(3))
  • Not be subject to solely automated decisions producing legal or similarly significant effects (Art. 22).

We use automated measures to prevent abuse — for example, temporarily blocking an IP address that shows abusive request patterns. These are short-lived technical safeguards that do not produce legal or similarly significant effects, and rely on our legitimate interest in security (Art. 6(1)(f)).

To exercise any right — including deleting your account and erasing your data — contact us at [email protected]. We respond within the statutory time limits (generally one month).

You also have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI)
Alt-Moabit 59–61, 10555 Berlin, Germany
https://www.datenschutz-berlin.de

9.2 Cookies and similar technologies

We use cookies and similar technologies (such as local storage and pixels) in the following categories:

  • Strictly necessary — required to operate the Service: authentication and session, security and anti-abuse, load balancing, and remembering your cookie choice. These do not require consent under § 25(2) TDDDG and are always active.
  • Analytics — help us understand how our website and app are used (pages viewed, traffic sources, aggregate behavior) so we can improve them.
  • Marketing — let us measure and improve our advertising and show you relevant AmeChat ads on other sites.
  • Preferences — remember non-essential choices such as language and theme.

Analytics, marketing and preference cookies are only set with your consent, which we ask for through our cookie banner on your first visit (Art. 6(1)(a) GDPR and § 25(1) TDDDG). Until you consent, no non-essential cookies are set and no analytics or advertising tags run — we apply this technically through Google Consent Mode, which starts in a denied state by default.

Separately, we use a privacy-preserving, cookieless analytics service (Cloudflare Web Analytics) that measures aggregate traffic and page performance without any cookies, local storage or device identifiers. Because it neither stores nor accesses information on your device, it does not require consent under § 25 TDDDG; it processes only aggregate and truncated technical data on the basis of our legitimate interest in understanding and improving the Service (Art. 6(1)(f) GDPR), and therefore runs regardless of your cookie choice.

You can give, change or withdraw your consent at any time via the “Cookie settings” link in the website footer, without affecting the lawfulness of processing before withdrawal. Where these technologies are provided by processors or involve transfers outside the EU/EEA, the relevant recipients and safeguards are listed in our Sub-processors page.

For marketing cookies, the advertising providers named there (such as Google and Meta) act as independent or joint controllers of the data they receive for their own advertising purposes under their respective terms — not solely as our processors. Where such a provider is a joint controller with us, that role is limited to the collection and onward transmission of the event data; their subsequent use is governed by their own privacy policy.

9.3 Minimum age

The Service is intended for adults aged 18 and over. By creating an account you confirm that you meet this requirement, as set out in our Terms of Service; we do not ask for or store your date or year of birth (see Section 2.1). We do not knowingly process the personal data of anyone under 18; if we learn that we have, we will delete it.


10. About this policy

10.1 Changes to this policy

We may update this policy to reflect changes to the Service or the law. We will post the updated version with a new "Last updated" date and, for material changes, notify you within the Service.

10.2 Contact

For any question about this policy or your data:

AmeChat UG (haftungsbeschränkt)
Werderstraße 30, 12103 Berlin, Germany
Email: [email protected]