Data protection
Most of this page is about data DChat does not hold, because the architecture removes it rather than promising not to look. The blockchain is the honest exception and it is stated plainly.
The starting point
There is no account database. Your identity is a key pair generated on your device, and no server holds a credential, a profile, or a copy of your messages in readable form. There is nothing to hand over because there is nothing to hold.
The honest exception is the blockchain, and it is a real one. Section 5 states it plainly.
What is processed, and by whom
| Data | Who sees it | Why | Retention |
|---|---|---|---|
| Message content | Only the participants | Not processed by anyone else. It is encrypted before it leaves the device | On your devices, until you delete it |
| Undelivered ciphertext | Relay operators, as unreadable bytes | So a message reaches someone whose phone was off | 14 days, 30 for configuration messages |
| IP address | The relay you connect to | Unavoidable consequence of making a network connection | Connection lifetime plus operator logs |
| Envelope routing fields | Relay operators | Delivery. A relay must know where to send a message it cannot read | With the message |
| Address, username, DID | Everyone | Public identity registry, so names resolve without a central directory | Permanent |
| Transactions | Everyone | Public ledger | Permanent |
| Website analytics | DChat | Counting page views | See the cookie policy |
| Contact form messages | DChat | Answering you | Until resolved, then deleted on request |
What is never collected
- Phone number
- Email address
- Real name or date of birth
- Contact list upload
- Location, unless you deliberately send it in a message
- Advertising or device identifiers
- Your recovery phrase, which never leaves your device
- Your private keys
- Message plaintext, which no operator can produce
- Group membership, which is held by members' devices
Why the processing is lawful
Performance of a contract. Holding undelivered ciphertext and accepting a connection is what delivering a message requires. Without it the service does not work.
Legitimate interests. Counting page views to understand which documentation gets read, and answering messages you send through the contact form. The analytics are anonymous, honour Do Not Track, and are described field by field on the cookie policy so the balancing test is checkable rather than asserted.
Your own action. Registering a username publishes it. The application requires a username at setup, so this is unavoidable if you use DChat at all, which is precisely why it is stated in the app, in the whitepaper and here rather than buried.
Erasure, and the limit of it
What can be removed: your identity record, your username reservation, your published chat key, and the associated profile and reward records. The chain has a purge mechanism for exactly this, gated behind governance so no single operator can erase someone unilaterally.
What cannot be removed: historical ledger entries. Transactions that have been written are permanent and are replicated across every node in the network. If your username has been associated with an address, that association may persist in third-party copies of the chain even after the registry entry is purged.
The practical consequence, stated once and clearly: choose a username you are content to have permanently public, and treat the wallet attached to it as public.
Your other rights
Access. Almost everything is already yours or already public. Your messages are on your device, your keys are on your device, and your chain records are readable by anyone with a node. For website analytics or contact form messages, ask and you will be told what is held.
Rectification. Display names and profile data are changed in the app. Chain history cannot be rewritten.
Objection and restriction. Turn on Do Not Track and the analytics stop entirely. There is no other profiling to object to, and no automated decision-making.
Portability. The app exports an encrypted backup you control, and your keys derive from a standard BIP-39 phrase, so your identity is portable by construction rather than by request.
Complaint. You may complain to your local data protection authority. Raising it with us first is faster and usually resolves it.
Where the data is
Relay nodes are operated by independent parties and can be anywhere in the world. Which node holds a copy of a message is not something DChat controls, and by design a message may be replicated across many of them until it is collected.
Because the content is encrypted before it leaves your device and no operator holds a key, the location of a node does not determine who can read your messages. What a node in any jurisdiction can produce is ciphertext, connection metadata and nothing else.
Children
DChat is not directed at children under 13, or under the age of digital consent in your jurisdiction where that is higher. No age verification is possible on a system that collects no identifying information, which is a genuine limitation rather than an oversight.
Changes and contact
Material changes to this page will be recorded here with a date. It was last updated on 31 July 2026.
For any request under this page, use the contact form. Messages are read by a person.
Questions about this page?
A person reads every message. If something here is unclear or looks wrong, say so and it gets fixed.