Legal

Data protection

Most of this page is about data DChat does not hold, because the architecture removes it rather than promising not to look. The blockchain is the honest exception and it is stated plainly.

Last updated 31 July 20269 sections

The starting point

Most of this document is about data DChat does not hold. That is the design, not a policy choice, and it is the reason several rights below are satisfied trivially while one of them cannot be satisfied at all.

There is no account database. Your identity is a key pair generated on your device, and no server holds a credential, a profile, or a copy of your messages in readable form. There is nothing to hand over because there is nothing to hold.

The honest exception is the blockchain, and it is a real one. Section 5 states it plainly.

What is processed, and by whom

DataWho sees itWhyRetention
Message contentOnly the participantsNot processed by anyone else. It is encrypted before it leaves the deviceOn your devices, until you delete it
Undelivered ciphertextRelay operators, as unreadable bytesSo a message reaches someone whose phone was off14 days, 30 for configuration messages
IP addressThe relay you connect toUnavoidable consequence of making a network connectionConnection lifetime plus operator logs
Envelope routing fieldsRelay operatorsDelivery. A relay must know where to send a message it cannot readWith the message
Address, username, DIDEveryonePublic identity registry, so names resolve without a central directoryPermanent
TransactionsEveryonePublic ledgerPermanent
Website analyticsDChatCounting page viewsSee the cookie policy
Contact form messagesDChatAnswering youUntil resolved, then deleted on request

What is never collected

Not asked for, ever
  • Phone number
  • Email address
  • Real name or date of birth
  • Contact list upload
  • Location, unless you deliberately send it in a message
  • Advertising or device identifiers
Not obtainable by anyone
  • Your recovery phrase, which never leaves your device
  • Your private keys
  • Message plaintext, which no operator can produce
  • Group membership, which is held by members' devices

Why the processing is lawful

Performance of a contract. Holding undelivered ciphertext and accepting a connection is what delivering a message requires. Without it the service does not work.

Legitimate interests. Counting page views to understand which documentation gets read, and answering messages you send through the contact form. The analytics are anonymous, honour Do Not Track, and are described field by field on the cookie policy so the balancing test is checkable rather than asserted.

Your own action. Registering a username publishes it. The application requires a username at setup, so this is unavoidable if you use DChat at all, which is precisely why it is stated in the app, in the whitepaper and here rather than buried.

Erasure, and the limit of it

A public blockchain cannot be edited. Any right to erasure stops at the ledger boundary, and no operator, court order or governance vote changes that.

What can be removed: your identity record, your username reservation, your published chat key, and the associated profile and reward records. The chain has a purge mechanism for exactly this, gated behind governance so no single operator can erase someone unilaterally.

What cannot be removed: historical ledger entries. Transactions that have been written are permanent and are replicated across every node in the network. If your username has been associated with an address, that association may persist in third-party copies of the chain even after the registry entry is purged.

The practical consequence, stated once and clearly: choose a username you are content to have permanently public, and treat the wallet attached to it as public.

Your other rights

Access. Almost everything is already yours or already public. Your messages are on your device, your keys are on your device, and your chain records are readable by anyone with a node. For website analytics or contact form messages, ask and you will be told what is held.

Rectification. Display names and profile data are changed in the app. Chain history cannot be rewritten.

Objection and restriction. Turn on Do Not Track and the analytics stop entirely. There is no other profiling to object to, and no automated decision-making.

Portability. The app exports an encrypted backup you control, and your keys derive from a standard BIP-39 phrase, so your identity is portable by construction rather than by request.

Complaint. You may complain to your local data protection authority. Raising it with us first is faster and usually resolves it.

Where the data is

Relay nodes are operated by independent parties and can be anywhere in the world. Which node holds a copy of a message is not something DChat controls, and by design a message may be replicated across many of them until it is collected.

Because the content is encrypted before it leaves your device and no operator holds a key, the location of a node does not determine who can read your messages. What a node in any jurisdiction can produce is ciphertext, connection metadata and nothing else.

Children

DChat is not directed at children under 13, or under the age of digital consent in your jurisdiction where that is higher. No age verification is possible on a system that collects no identifying information, which is a genuine limitation rather than an oversight.

Changes and contact

Material changes to this page will be recorded here with a date. It was last updated on 31 July 2026.

For any request under this page, use the contact form. Messages are read by a person.

Questions about this page?

A person reads every message. If something here is unclear or looks wrong, say so and it gets fixed.