Privacy Policy

Last updated: September 16, 2026

Hi Chat ("the app") is a social feed and messaging app. This page explains what data the app collects, how it is used, who processes it on our behalf, and how you can delete it.

Who we are

Hi Chat is operated by Cedric Häusermann, Adliswil, Switzerland.
Contact: [email protected]

Age requirement

You must be 18 years or older to use Hi Chat. If we become aware that a user is under 18, the account is removed.

Account and sign-in

To use the app you sign in with your Google account via Firebase Authentication. We receive and store your Google account ID, email address, name and profile picture URL. In the app you appear under an anonymous username; your name and picture are not shown to other users unless you choose to set them.

What we collect and store

  • Account data: Google account ID, email address, name, profile picture URL.
  • Content you create: posts (text and up to three photos), replies, reactions and private messages. This content is stored on our servers so it can be shown to other users and so you can see it later.
  • Photos: uploaded photos are stored on DigitalOcean Spaces (Singapore region) and delivered through a content delivery network. Photos are shown pixelated in the feed and revealed inside private chats according to the rules you set when posting.
  • Push notification token (Firebase Cloud Messaging), if you allow notifications, so we can notify you about replies and messages.
  • Device and usage data: app opens, crashes and basic usage events via Firebase Analytics and Crashlytics; the advertising ID via the Meta SDK, used only to measure whether our app-install ads work.
  • Reports: if you report a post, user or message, we store the report and the reported content for review.

Sharing posts outside the app

Any user can share a public post using their phone's share menu. Sharing sends a link to a page on our servers that shows that post, so the person receiving it can read it without the app and without an account.

  • Only what the public feed already shows is on that page: the text of the post and, for a post with photos, the same pixelated version everyone sees in the feed. The revealed photo is never shown there — it stays inside private chats.
  • Neither the link nor the page says who wrote the post or who shared it. Posts are shown as "Anonymous", exactly as in the app.
  • The page asks search engines not to list it, so shared posts are not meant to appear in search results. A link that has been sent, however, can be forwarded by anyone who received it.
  • If you delete your post, or it is removed, the link stops showing it.
  • We count how often these pages are opened, so we can tell whether sharing works. For visitors of a shared link we store no IP address, no browser identifier and no cookies.
  • If someone installs the app after following a shared link, Google Play tells the app which link that was. We store this together with your device identifier in order to know which posts bring new users.

Automated content screening

To keep the app safe, every post, photo and private message is automatically screened before it becomes visible to others. Text is analysed by Google Cloud Natural Language API and photos by Google Cloud Vision API (SafeSearch). Content that is sexual, violent, harassing or otherwise against our rules is blocked, and repeated violations lead to temporary or permanent restrictions. Content flagged by the system or reported by users may be reviewed by the operator. We do not read private conversations beyond this.

Emails

We use Brevo (Sendinblue SAS, France) to send account emails: a welcome email, notifications about replies or messages when push notifications cannot reach you, and confirmations when you request account deletion. These emails relate to your account and activity; we do not send newsletters or marketing emails.

Who processes your data

  • Google (Firebase Authentication, Cloud Messaging, Analytics, Crashlytics; Cloud Natural Language and Cloud Vision for content screening)
  • DigitalOcean (app hosting, database, photo storage)
  • Brevo (transactional emails)
  • Meta Platforms (ad attribution via the Meta SDK)

These providers process data only to provide their service to us. We do not sell your data and we do not share it with third parties for their own marketing.

What we don't do

  • We do not collect your precise location or your contacts.
  • We do not show third-party ads inside the app.
  • We do not sell your data.

How long data is kept

Your account and content are kept until you delete them. Individual posts and chats can be deleted in the app at any time. When you request account deletion, your account is scheduled for deletion and permanently removed after 30 days; logging in during that period cancels the request. Reports and content blocked by moderation may be kept for up to 90 days for safety review. Server logs are kept for up to 30 days.

Deleting your account

Open the app → Profile → Settings → Delete account. Your account, posts, photos, chats and reactions are removed after the 30-day period described above. You can also request deletion by emailing [email protected] from the address linked to your account.

Child safety

We do not allow users under 18. Any attempt to contact, groom or exploit minors results in a permanent ban and is reported to the relevant authorities. You can report such behaviour directly in the app or by email.

Your rights

You can ask us for a copy of your data, ask us to correct it, or ask us to delete it by writing to [email protected]. We answer within 30 days.

Changes to this policy

If this policy changes, the update will be posted on this page with a new "last updated" date.