Privacy Policy
Parrot Chat ("we", "our", or "the Service") provides a mobile and web messaging platform with wallet-based access. The Service also offers a Mini App platform that lets users open third-party applications inside an in-app browser. This Privacy Policy explains what information we collect, how we use it, and the rights available to you. By using the Service, you agree to the practices described in this Policy.
1. Information We Collect
Parrot Chat collects only the minimum data necessary to operate the Service.
1.1 Wallet Public Address
We collect and store only your public wallet address for authentication and service operation. We do not collect or access private keys, mnemonics, or any wallet secrets. These remain fully on your device.
1.2 Display Name (Optional)
Users may optionally set a display name visible to others. It is used only for identification within the Service and not for analytics or marketing.
1.3 Messages & Media
Messages, images, videos, and files may be stored temporarily for delivery and synchronization. All such content:
- is encrypted at rest
- is transmitted securely (SSL/TLS)
- is automatically deleted within 30 days
- may be retained briefly if required for handling user reports or disputes (see Section 4)
We cannot delete data stored on recipient devices.
1.4 Technical Data
To maintain stability and security, we may process:
- server logs (including IP addresses for security and service improvement)
- device identifiers (mobile app only, for fraud prevention; stored only as an irreversible hash)
- error and crash reports
- operational performance data
- Firebase Cloud Messaging (FCM) device tokens for push notifications
- an approximate country derived from the IP address at sign-in, stored with your account and used for service analytics and security
We do not use this technical data to build advertising profiles or to track you across other companies’ apps and websites. Advertising in Mini Apps is described separately in Section 1.9.
1.5 Report & Safety Data
If you submit a report, the content and related logs are retained for review. Media submitted as evidence is kept while the report is under review and for a limited period after it is decided, so that the decision can be re-examined if it is challenged. The report record itself is kept while it is still needed for review and enforcement, and is removed by our moderation team once it is not.
1.6 Cookies (Web Only)
The mobile apps do not use cookies. The web version uses only essential, strictly functional cookies for session management. No tracking or cross-site analytics cookies are used.
1.7 Location Data
This Section is about the location-sharing features. It does not cover the approximate country derived from your sign-in IP address (Section 1.4) or the IP address the ad provider receives (Section 1.9). We collect location data through this feature only when you explicitly enable location sharing or real-time location sharing. That location data is:
- collected only with your explicit consent
- used solely for the location sharing feature you activated
- not stored permanently on our servers
- automatically deleted within 30 days
- not used for advertising or for any purpose other than the location-sharing feature you activated
You can revoke location permission at any time through your device settings or by disabling the location sharing feature in the app. When disabled, we immediately stop collecting location data.
1.8 Mini Apps
The Service can open approved third-party web apps inside an in-app browser. When you launch a Mini App:
- we share, only so the Mini App you opened can run, the data you approve in the in-app consent dialog (such as a pseudonymous identifier and the capabilities you grant)
- we do not share private keys, messages, contacts, or location
Mini App developers are responsible for any data you provide to them directly. You can revoke a Mini App's permissions at any time from its settings.
1.9 Advertising in Mini Apps
Mini Apps may display advertisements delivered by Google AdMob. We ask for non-personalised ads on every ad request, so an ad is chosen from the context of the Mini App rather than from a profile of you. We and Google receive different data:
- What we receive: only ad delivery events — that an ad was shown, tapped, or a full-screen ad was closed — with the Mini App it appeared in, the ad format, and the time. These records are linked to your account identifier so that ad activity can be classified by Mini App and checked for abuse such as automated or repeated views. We do not receive, store, or process any advertising identifier.
- What Google receives: the Google Mobile Ads SDK sends Google your IP address (which can be used to estimate a general location), your interactions with the ad such as taps and video views, advertising data such as which ads you were shown, performance and crash diagnostics, and device and account identifiers — including, on Android, the advertising ID (AAID). Because we request non-personalised ads, the advertising ID is used to deliver and measure ads, for example to limit how often the same ad is shown and to detect invalid activity, rather than to build an advertising profile of you; you can reset or delete it at any time in Android Settings > Privacy > Ads. On iOS the app cannot access the IDFA, because we do not implement App Tracking Transparency, but Google may still use app- and developer-scoped identifiers, and install attribution uses Apple SKAdNetwork, which is designed not to identify individual users.
- Consent (EEA, UK, and other applicable regions): where required, a Google User Messaging Platform consent form is shown before ads are requested, and it also names the advertising partners Google may share ad data with. Declining means your data is not used for personalised advertising; it does not stop ads, because we request only non-personalised ads in any case — and the same applies where the form cannot be presented. Where Google indicates that privacy options apply to you, an "Ad privacy options" entry point is available in the app under Settings > Privacy.
Because every ad request asks for non-personalised ads, ads are not selected from a profile built from your past behaviour. Google may still use the general location estimated from your IP address to keep ads relevant, and the advertising ID to limit repeated ads, report performance, and prevent fraud. We do not enable child-directed ad treatment, because the Service is not directed to children (see Section 11).
2. Information We Do Not Collect
We do not collect or store:
- email addresses, phone numbers, or legal names
- private keys, mnemonics, or wallet secrets
- contact lists
- photo library or file system contents (we receive only the files you choose to send)
- biometric identifiers
- the iOS advertising identifier (IDFA) — App Tracking Transparency is not implemented, so the app cannot access it. On Android, the advertising ID is collected by Google as our advertising provider and is not received by us (see Section 1.9)
- payment information
- permanent chat history
Location sharing stays off unless you turn it on. Apart from the approximate country derived from your sign-in IP address (see Section 1.4), we do not track your location.
If you delete the app or your on-device (self-custody) wallet, cryptographic keys stored on your device are permanently lost and cannot be recovered by us.
3. How We Use Information
We process information solely to:
- deliver and synchronize messages
- maintain wallet-based access
- provide location sharing when explicitly enabled by users
- ensure security and prevent abuse
- improve performance
- send push notifications where permitted
- deliver advertising in Mini Apps and measure how it performs in each Mini App (see Section 1.9)
- comply with applicable laws
We do not sell or rent personal information. Advertising data sharing is limited to what Section 1.9 describes, and we do not share your messages, contacts, wallet address, or the location you share through the location-sharing feature with any advertising partner.
4. Data Retention
We retain data only for the minimum period required:
- Messages & media: deleted within 30 days
- Location data from the location-sharing feature: deleted within 30 days (the approximate country in Section 1.4 is account data and follows the account line below)
- Report/dispute data: evidence media and the report record are kept while the report is under review, and for a limited period after it is decided, so that the decision can be re-examined if it is challenged
- Operational server data: retained only as required by law
- Ad delivery events: raw event records deleted within 180 days; only aggregated, non-identifying totals are kept after that
- Security and abuse-prevention records: access and audit records of Mini App launches, consent grants and withdrawals, and enforcement actions are kept for up to 180 days, including after account deletion, so that abuse can be investigated and prevented
- Account-related server data: deleted upon account deletion, except the data noted above as retained for longer
- Abuse-prevention data (an irreversible hash of the device identifier and the account-creation count): stored per device, not linked to any specific account, and retained even after account deletion to prevent service abuse. The original device identifier is not stored.
Deletion timelines may be subject to delays caused by technical requirements, system backups, or legal obligations.
5. Data Storage & International Transfers
We use cloud infrastructure such as AWS (Singapore region) and Firebase for secure service operation, and Google processes Mini App advertising as described in Section 1.9. Additional regions may be added in the future to support service scaling.
We apply reasonable safeguards to comply with applicable privacy laws.
We are not responsible for incidents, data loss, or outages caused by third-party infrastructure providers.
6. How We Share Information
We do not share personal data except:
- where required to comply with applicable law
- to investigate fraud, abuse, or platform safety issues
- with service providers (AWS, Firebase) operating strictly under our instruction
- with Google, as our advertising provider for Mini App ads, and the advertising partners named in Google’s consent form, limited to what Section 1.9 describes
- with Mini App developers, to run the Mini App you open, limited to the pseudonymous identifier and capability scopes you consent to at launch (see Section 1.8)
Apart from the advertising processing described in Section 1.9, we do not share personal data for marketing purposes, and we never sell it. We require every recipient listed above to protect your data to the same standard as this Policy, and we share only what each of them needs for the purpose described.
7. Device Permissions
The app may request access to:
- camera
- microphone
- photo/media library
- location
- notifications
These permissions are used only to provide user-initiated features, and none of them are used for tracking. On Android the app also declares the advertising ID permission, which shows no prompt and is used solely so that Google can deliver ads in Mini Apps (see Section 1.9).
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- request access, correction, or deletion
- limit processing
- withdraw permissions
- request data portability
- delete your account
You may exercise these rights by contacting us at the address below.
9. Account Deletion & Wallet Removal
If you delete your account:
- server-side data is removed, except the data that Section 4 identifies as retained for longer, such as security and abuse-prevention records
- wallet secrets on your device cannot be recovered
- delivered messages may remain available to recipients
- report/dispute-related data may be kept while it is still needed for review and enforcement
- You can delete your account in the app under Settings, or on the web at https://parrotchat.com/delete-account. If neither is available to you, contact us at the address in Section 14.
We cannot restore or recover any wallet information.
10. Security Disclaimer
We implement reasonable technical and organizational safeguards, but:
- we cannot guarantee protection against risks caused by user device compromise, malware, jailbreaking, or insecure networks
- we do not control, and are not responsible for, data stored on user devices
- uninterrupted availability or error-free operation is not guaranteed
You are responsible for maintaining the security of your device and wallet.
11. Children's Privacy
The Service is not intended for children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect data from children, and the Service is not directed to children for advertising purposes.
12. Child Sexual Abuse and Exploitation (CSAE) Policy
Our app strictly prohibits any content related to child sexual abuse or exploitation (CSAE). We do not allow the creation, upload, sharing, or distribution of such content. Any account found violating this policy will be permanently removed and may be reported to relevant law enforcement authorities. Users can report CSAE-related content through the in-app reporting feature or by contacting us at parrotchat.cs@gmail.com. We are committed to protecting minors and complying with all applicable laws and Google Play policies.
13. Changes to This Policy
If we make material changes, we will notify users through in-app notice or updated posting on this page.
14. Contact
For privacy-related questions, please contact: parrotchat.cs@gmail.com
This Policy is operated by Parrot Chat (Futurecode Co., Ltd.), the data controller for the Service.