Paradise Chat Privacy Policy
Effective date: September 6, 2026
Controller/operator: Paradise Chat
Contact address: contact@paradisechat.app
Jurisdiction: Thailand
This Policy explains how Paradise Chat processes personal information when you use the service.
1. Information we collect
Account and eligibility information
We receive your name, email address, and sign-in provider from Google or Apple. We support Apple private-relay email addresses. Paradise Chat has no password. We also collect your date of birth once at sign-up to enforce the 18+ requirement. You cannot edit the date of birth yourself.
Messages and membership
We process your role, official accounts, group memberships, join requests, messages, reactions, reports, moderation outcomes, and activity timestamps. Staff replies are stored with the staff member's name and role because members must be able to see who spoke for an official account or in a group.
Members cannot contact one another directly. Paradise Chat has no member directory, friend requests, contact list, or member search.
Media and technical information
We process media and files you choose to send, subject to limits configured by the administrator. Upload limits are enforced while bytes are received, and images may be recompressed when an administrator has enabled that setting. We also process session records, an app-generated installation identifier, push tokens, app version, connection and delivery information, and security events needed to operate and protect the service.
If you choose to record a voice message, recording starts on your device only after you tap the microphone. The recording stays on the device for review until you tap Send. It is then uploaded, linked to you as its sender, and delivered to the chat you selected. Paradise Chat does not use the microphone for background or continuous recording.
2. Information we do not collect
Paradise Chat never reads your phone's address book and never asks for contacts permission. We do not build a contact graph from your device.
Chat backgrounds are local to each chat and device and are not synchronized through the service.
3. How we use information
We use personal information to:
- authenticate accounts through Google or Apple;
- verify eligibility and enforce the one-time age gate;
- deliver official-account and group messages;
- manage groups, roles, join requests, and notifications;
- attribute staff replies by name and role;
- enforce media rules and the administrator's retention settings;
- review reports, moderate content, investigate abuse, and maintain an audit trail;
- provide support, maintain security, and diagnose service problems; and
- meet legal obligations and respond to valid requests.
Paradise Chat is operated from Thailand, and this Policy is written to the Personal Data Protection Act B.E. 2562 (2019). The bases we rely on are:
- Performance of a contract, for everything the product must do to work at all: creating and authenticating your account, delivering messages, managing groups and roles, and sending the notifications you have allowed.
- Legal obligation, for the 18+ age gate, for keeping the audit trail, and for answering lawful requests.
- Legitimate interests, for security, abuse investigation, moderation, and diagnosing service problems. Those interests are weighed against yours, and they do not extend to advertising or profiling — the service does neither.
- Consent, which you give on the device, for notifications, the microphone, the camera, and access to your photo library. You can withdraw any of these in your phone's settings, and withdrawing one costs only the feature it belongs to.
We do not sell personal data, and we do not use it to build advertising profiles.
4. How information is shared
Information is visible within Paradise Chat as needed for the product to work. For example, group members see messages and staff bylines, and authorized staff see queues and member information needed for administration or moderation.
We receive identity information from Google or Apple when you choose that provider. Firebase Cloud Messaging, a Google service, processes device push tokens and notification payloads on our instructions so notifications can reach your device. Every service provider that handles personal data on our instructions is listed here, and there are no others:
- Google LLC — Google sign-in, and Firebase Cloud Messaging for push notifications.
- Apple Inc. — Sign in with Apple, including private-relay addresses.
- Server hosting — the company the Operator rents its server from, which holds the live database and the media described in Section 5. This one is listed by what it does rather than by name.
- Backblaze, Inc. — the off-site backup described in Section 5. It is encrypted on our own server before it is sent, so Backblaze holds ciphertext and never holds the key.
- Cloudflare, Inc. — domain registration and DNS. Cloudflare resolves the name and does not carry, terminate, or inspect traffic to the service.
There is no advertising network, no analytics service, and no data broker on that list.
Your information leaves Thailand. The Operator's server and every provider above are outside Thailand, mostly in the United States, so using Paradise Chat means your information is stored and processed abroad. We rely on each provider's own data-protection terms for that transfer, and creating an account is your acceptance of it.
We may disclose information when required by law or reasonably necessary to protect users, the public, the Operator, or the service.
5. Media storage and retention
Message attachments are stored on the Operator's own server. Administrators configure allowed media types, per-type size and duration limits, photo batch limits, and a retention window. The upload endpoint stops accepting bytes when a file exceeds its active limit. A daily server job deletes attachment bytes older than the active retention window; profile, official-account, and group avatars are not removed by that attachment-retention job. When enabled, eligible images are recompressed in their original format only when that makes the file smaller. Sticker messages are stored as pack references rather than separate uploaded media.
Voice messages are message attachments under the same retention rule. The administrator can choose 30 days, 90 days, one year, or forever. A voice message is also deleted with the sender's account as described in Section 9.
Reports and audit records are retained for 12 months. Audit records are append-only and cannot be edited or deleted, including by an administrator. They include panel actions and in-app moderator actions. When an account is deleted, the name is replaced with “deleted member” or detached from retained reports. Anonymous aggregate usage counts may be kept.
Backups. The database and the media directory are backed up nightly. A local dump stays on the server for seven days. The off-site copy is encrypted on our server before it leaves it, and is kept under a schedule of seven daily, four weekly, and six monthly snapshots — so a backup can still hold a copy of your information for up to six months after the live records are gone. A restore is a recovery from failure and not a way to bring a deleted account back: whatever a restore returns is deleted again by the same jobs described here and in Section 9.
Everything else. Account records, messages, and memberships are kept for as long as the account exists, and go on deletion as described in Section 9. Server logs roll by size rather than by date — each service keeps roughly its last 30 MB and discards older lines automatically — and they are used to operate and protect the service, never to build a profile of you.
Legal hold. A deletion is delayed only where a valid legal requirement makes us keep the records, only for as long as that requirement lasts, and the person is told why.
6. Notifications
If you allow notifications, we use Firebase Cloud Messaging and a push token to deliver them. You can control message categories, sound, and preview text. When preview text is off, neither the message body nor the sender's name enters the notification payload; it contains only opaque routing identifiers and generic “New message” text.
7. Sessions
Access tokens are short-lived. Refresh tokens also expire and are rotated when used; only a cryptographic hash of a refresh token is stored by the service. Signing out revokes that session and removes its push token so the signed-out device does not continue receiving notifications. Signing out of all sessions revokes every session and removes every push token for the account.
8. Your choices and rights
You can change supported notification settings, leave groups that are allowed to be left, block or unblock another member, report content, and request access to or deletion of your data.
Under the Personal Data Protection Act you may also ask us for a copy of your personal data or ask that it be sent to someone else, correct it, delete it, restrict or stop a particular use of it, or object to a use we base on our legitimate interests; and you may withdraw at any time a consent you gave on the device. We answer within 30 days. If our answer does not satisfy you, you may complain to the Office of the Personal Data Protection Committee in Thailand.
Blocking privately hides that person's messages from your view in groups you share. It does not tell the blocked person, remove either person from a group, or prevent staff from moderating either person's content. Official-account replies remain visible. Staff announcements in a read-only announcement group also remain visible, while older messages sent there when the sender was a plain member remain hidden. Blocking is not a report and sends nothing to moderators; use the report action when you want staff to review possible abuse.
Contact contact@paradisechat.app to exercise a right or question a decision. Identity verification may be required.
9. Account deletion
Deletion can be requested inside Paradise Chat or at the public account-deletion URL. A request has a seven-day grace window, and signing in during that window cancels it. If not cancelled, deletion completes within 30 days.
If you can no longer access the Google or Apple account used to sign in, use the support contact published on the public site. Include the email address on the Paradise Chat account and roughly when you last used it. A person reviews the request and may ask for more information before accepting it, so this route takes longer than self-service sign-in. Once accepted, the same grace and completion periods apply.
The profile, messages, media, group memberships, sessions, push tokens, chat settings, and other account settings are deleted. Reports and audit records are kept for 12 months with the name detached or replaced by “deleted member.” Anonymous usage counts may remain. A request may be delayed only where a valid legal hold requires it, and the person will be told why.
10. Security, children, and changes
We use administrative, technical, and organizational safeguards appropriate to the service. No system can guarantee absolute security.
Paradise Chat is not designed for children and is limited to people aged 18 or older. An under-18 sign-up attempt does not create an account.
We may update this Policy and will publish a new effective date and provide any notice required by law.
11. Contact
Privacy questions and requests may be sent to contact@paradisechat.app.
Paradise Chat
Public information