Paradise Chat Privacy Policy
DRAFT — NEEDS A LAWYER'S REVIEW BEFORE PUBLICATION
Effective date: July 29, 2026
Controller/operator: [LEGAL ENTITY]
Contact address: [CONTACT ADDRESS]
Jurisdiction: [JURISDICTION]
This Policy explains how [LEGAL ENTITY] processes personal information when you use Paradise Chat.
1. Information we collect
Account and eligibility information
We receive your name, email address, and sign-in provider from Google or Apple. We support Apple private-relay email addresses. Paradise Chat has no password. We also collect your date of birth once at sign-up to enforce the 18+ requirement. You cannot edit the date of birth yourself.
Workspace and communication information
We process your role, official accounts, group memberships, join requests, messages, reactions, reports, moderation outcomes, and activity timestamps. Staff replies are stored with the staff member's name and role because members must be able to see who spoke for an official account or in a group.
Members cannot contact one another directly. Paradise Chat has no member directory, friend requests, contact list, or member search.
Media and technical information
We process media and files you choose to send, subject to limits configured by the administrator. Upload limits are enforced while bytes are received, and images may be recompressed when the workspace setting is enabled. We also process session records, an app-generated installation identifier, push tokens, app version, connection and delivery information, and security events needed to operate and protect the service.
If you choose to record a voice message, recording starts on your device only after you tap the microphone. The recording stays on the device for review until you tap Send. It is then uploaded, linked to you as its sender, and delivered to the chat you selected. Paradise Chat does not use the microphone for background or continuous recording.
2. Information we do not collect
Paradise Chat never reads your phone's address book and never asks for contacts permission. We do not build a contact graph from your device.
Chat backgrounds are local to each chat and device and are not synchronized through the service.
3. How we use information
We use personal information to:
- authenticate accounts through Google or Apple;
- verify eligibility and enforce the one-time age gate;
- deliver official-account and group messages;
- manage groups, roles, join requests, and notifications;
- attribute staff replies by name and role;
- enforce media rules and the administrator's retention settings;
- review reports, moderate content, investigate abuse, and maintain an audit trail;
- provide support, maintain security, and diagnose service problems; and
- meet legal obligations and respond to valid requests.
The lawful bases and any region-specific notices for [JURISDICTION] must be confirmed by counsel before publication.
4. How information is shared
Information is visible within the workspace as needed for the product to work. For example, group members see messages and staff bylines, and authorized staff see queues and member information needed for administration or moderation.
We receive identity information from Google or Apple when you choose that provider. Firebase Cloud Messaging, a Google service, processes device push tokens and notification payloads on our instructions so notifications can reach your device. We may use other service providers acting on our instructions for infrastructure or operational support. A final provider list and any international-transfer terms must be supplied by [LEGAL ENTITY] before publication.
We may disclose information when required by law or reasonably necessary to protect users, the public, the Operator, or the service.
5. Media storage and retention
Message attachments are stored on the Operator's own server. Administrators configure allowed media types, per-type size and duration limits, photo batch limits, and a retention window. The upload endpoint stops accepting bytes when a file exceeds its active limit. A daily server job deletes attachment bytes older than the active retention window; profile, official-account, and group avatars are not removed by that attachment-retention job. When enabled, eligible images are recompressed in their original format only when that makes the file smaller. Sticker messages are stored as pack references rather than separate uploaded media.
Voice messages are message attachments under the same retention rule. The administrator can choose 30 days, 90 days, one year, or forever. A voice message is also deleted with the sender's account as described in Section 9.
Reports and audit records are retained for 12 months. Audit records are append-only and cannot be edited or deleted, including by an administrator. They include panel actions and in-app moderator actions. When an account is deleted, the name is replaced with “deleted member” or detached from retained reports. Anonymous aggregate usage counts may be kept.
Other retention periods, backups, and legal-hold rules must be documented by [LEGAL ENTITY] before publication.
6. Notifications
If you allow notifications, we use Firebase Cloud Messaging and a push token to deliver them. You can control message categories, sound, and preview text. When preview text is off, neither the message body nor the sender's name enters the notification payload; it contains only opaque routing identifiers and generic “New message” text.
7. Sessions
Access tokens are short-lived. Refresh tokens also expire and are rotated when used; only a cryptographic hash of a refresh token is stored by the service. Signing out revokes that session and removes its push token so the signed-out device does not continue receiving notifications. Signing out of all sessions revokes every session and removes every push token for the account.
8. Your choices and rights
You can change supported notification settings, leave groups that are allowed to be left, block or unblock another member, report content, and request access to or deletion of your data. Applicable law may provide additional rights to access, correct, restrict, object to, or receive a copy of personal information.
Blocking privately hides that person's messages from your view in groups you share. It does not tell the blocked person, remove either person from a group, or prevent staff from moderating either person's content. Official-account replies remain visible. Staff announcements in a read-only announcement group also remain visible, while older messages sent there when the sender was a plain member remain hidden. Blocking is not a report and sends nothing to moderators; use the report action when you want staff to review possible abuse.
Contact [CONTACT ADDRESS] to exercise a right or question a decision. Identity verification may be required.
9. Account deletion
Deletion can be requested inside Paradise Chat or at the public account-deletion URL. A request has a seven-day grace window, and signing in during that window cancels it. If not cancelled, deletion completes within 30 days.
If you can no longer access the Google or Apple account used to sign in, use the support contact published on the public site. Include the email address on the Paradise Chat account and roughly when you last used it. A person reviews the request and may ask for more information before accepting it, so this route takes longer than self-service sign-in. Once accepted, the same grace and completion periods apply.
The profile, messages, media, group memberships, sessions, push tokens, chat settings, and other account settings are deleted. Reports and audit records are kept for 12 months with the name detached or replaced by “deleted member.” Anonymous usage counts may remain. A request may be delayed only where a valid legal hold requires it, and the person will be told why.
10. Security, children, and changes
We use administrative, technical, and organizational safeguards appropriate to the service. No system can guarantee absolute security.
Paradise Chat is not designed for children and is limited to people aged 18 or older. An under-18 sign-up attempt does not create an account.
We may update this Policy and will publish a new effective date and provide any notice required by law.
11. Contact
Privacy questions and requests may be sent to [CONTACT ADDRESS].
Paradise Chat
Public information