PRIVACY

Privacy Policy

Last updated 26 August 2026

The short version: we never see or store your conversations. Video and audio go straight from your device to the other person's. We keep the account you made, the profile you wrote, and the record that a conversation happened — because that is what a rating, a friendship and a report are built on. We do not sell anything, we run no advertising, and we set no tracking cookies — the only counting that happens is aggregate page views, with nothing stored on your device.

1. Who is responsible

The controller under Art. 4(7) GDPR is:
A7-24 Aumann GmbH, Geschäftsbereich Veste Software, Ketschendorfer Str. 54, 96450 Coburg, Germany
Email:[email protected]

Full company register details are in the imprint. We have not appointed a data protection officer, because we are below the threshold in §38 BDSG; the address above reaches the people who decide these things.

2. What we collect, why, and under what legal basis

Every processing operation needs a legal basis under Art. 6(1) GDPR. Here is each one we rely on and what it covers.

To give you an account — Art. 6(1)(b), performance of a contract

  • Your email address. Stored in a canonical form, so that the aliases
    of one mailbox cannot quietly become several accounts.
  • No password. Sign-in is a link emailed to you, or a social login.
    There is no password to store, leak or reuse.
  • Your profile: display name, handle, bio, languages and how well you
    speak them, interests, timezone, language, and — if you add them — a city, a country,
    an avatar and a cover image. All of it optional except a name and a handle, and all
    of it visible to other members according to the setting you choose.
  • Sessions: a session token, plus the IP address and browser string
    that created it, so you can see and end a sign-in you do not recognise.
  • That a conversation happened: who, when, how long, and in which
    channel — never a recording, never a transcript, never the words. See §4.
  • What you write to other people: direct messages, posts and event
    descriptions.
  • Your ratings, friendships, events and game scores.

To keep the network safe — Art. 6(1)(f), legitimate interests

Our legitimate interest is preventing harassment, abuse and fraud on a service that puts strangers on camera together; we consider it to override the limited privacy impact of the items below, and you may object under Art. 21 at any time (§7).

  • Reports you file or that are filed about you, including who filed
    them. Reporter identity is visible only to moderators, never to the person reported.
  • Suspensions, appeals and moderation decisions, in an append-only log.
  • Your trust score, computed from peer ratings over time.
  • Your IP address at sign-up, checked against a short-lived counter to
    stop scripted account creation. It is held in memory, never written to the database,
    and disappears when the server restarts.
  • A bot check on the sign-in form, run by Cloudflare Turnstile, which
    builds no cross-site profile and, per Cloudflare, stores nothing in cookies.
  • Server logs — IP address, time, URL, status, user agent — kept 14
    days for fault diagnosis and abuse.

Because you asked for it — Art. 6(1)(a), consent

  • Push notifications for events you said you would attend. Only after
    you agree, in our own interface before the browser's. Withdraw in Settings or in
    your browser.
  • The weekly digest and other optional email. Every type is a separate
    switch in Settings, and every message carries a one-click unsubscribe.
  • Listing your profile in search engines. Off by default. A profile is
    a person, and putting one in front of Google is your decision, not a growth setting.

Withdrawing consent is as easy as giving it and does not affect what was lawful before you withdrew it (Art. 7(3)).

Because the law requires it — Art. 6(1)(c)

Retention of accounting records where any payment is ever involved (§147 AO, §257 HGB), and responding to lawful orders from a competent authority.

3. What we store on your device, and why there is no cookie banner

§25 TDDDG — the German implementation of the ePrivacy rules, renamed from TTDSG in May 2024 — governs anything stored on or read from your device, not only cookies. So this section covers all of it. Everything below is exempt under §25(2) as strictly necessary for a service you asked for, which is why you are not shown a consent banner. There is nothing here to consent to: no analytics, no advertising, no third-party trackers, and no profiling of any kind.

  • A session cookie, so you stay signed in. HttpOnly, Secure,
    SameSite=Lax. Expires after 90 days or when you sign out.
  • An invite cookie, set only if you arrive by clicking
    somebody's invite link, so that the person who invited you can be credited when
    you finish signing up. It holds their invite code and where the link was pointing,
    nothing else. It is read exactly once, at the end of onboarding, and deleted there.
    Nothing else ever reads it, nothing is tracked with it, nobody is paid for it, and
    it expires by itself after 30 days.
  • A few small preferences in your browser's own storage, once you
    are signed in: the topics you recently searched for, whether you like the video
    window shown during a game, and which event card you have dismissed this session.
    They never leave your device and we cannot read them.
  • An offline cache (a service worker), so the site still opens on a
    bad connection and can be installed to a home screen. It stores pages, not people.

On the sign-in page only, Cloudflare Turnstile checks you are not a bot. Cloudflare states that Turnstile does not use cookies to collect or store information, and it builds no cross-site profile; it is here on the legitimate-interest basis in §2, and is the reason automated sign-ups are not filling this network with scripts.

We run no analytics product of our own, and there is no Google Analytics, no advertising pixel and no cross-site tracker anywhere on this site. Cloudflare, which serves the site, counts page views for us in aggregate — pages, referrers and countries, without cookies and without retaining your IP address, so it cannot recognise you on a second visit or on anybody else's site. Our fonts are served from our own server rather than from Google Fonts, so loading a page sends your IP address to nobody.

4. Your conversations

Video and audio are peer-to-peer (WebRTC). They travel directly between the two browsers and are never recorded, stored or transcribed by us, and never pass through a server that can read them.

One exception, and it is a technical one: when two networks cannot reach each other directly — roughly one call in five, typically behind a strict corporate firewall — the encrypted stream is bounced through a relay (TURN). The relay forwards packets it cannot decrypt. It sees that two addresses are exchanging data, and nothing about what.

Text you send inside a room is stored, because a conversation you can scroll back through is the point of it.

5. Who else sees your data

We do not sell personal data and we never will. It reaches the following recipients and no others. Each processor works under a contract meeting Art. 28 GDPR.

WhoWhat forWhat they getOutside the EU?
OVHcloudHosts the virtual server that runs the application, the database and the TURN relay.Everything stored, plus server logs.No — stays in the EU/EEA.
Cloudflare, Inc.DNS, TLS, reverse proxy and DDoS protection; aggregate page-view counts (Cloudflare Web Analytics — cookieless, no IP retention, no cross-site profile); the Turnstile bot check on sign-in; optionally a fallback TURN relay for calls that cannot connect directly.IP address, request metadata, and — for Turnstile — a bot-check token. Turnstile builds no cross-site profile.USA — EU Standard Contractual Clauses, and Cloudflare is certified under the EU–US Data Privacy Framework.
Resend / SMTP providerDelivers sign-in links, notifications and the weekly digest.Email address and the content of the message sent to it.USA — EU Standard Contractual Clauses.
Google, Apple, Facebook or MicrosoftOnly if you choose to sign in with one of them.They tell us your email address and display name; we tell them nothing about you.USA — their own terms apply to what they do with the fact that you signed in.
Push notification services (Apple, Google, Mozilla, Microsoft)Only if you turn on event reminders. Delivers the reminder to your device.An anonymous endpoint URL for your browser, plus the reminder text.Depends on your browser vendor.

Where a transfer to the United States is involved, it rests on the European Commission's Standard Contractual Clauses under Art. 46(2)(c), and where the recipient is certified, additionally on the EU–US Data Privacy Framework adequacy decision under Art. 45.

Other members see what your privacy setting allows: your profile, your
rating, and — with someone you have actually talked to — that the two of you have
spoken before. Nobody ever sees anything about a conversation they were not in.

6. How long we keep things

WhatHow longWhy
Your account and profileUntil you delete it. Deletion is immediate and in Settings.It is the account.
Sign-in links and sessionsLinks expire after 15 minutes; a session after 90 days, or immediately when you sign out.Security.
Conversation recordsThe fact that a conversation happened, with whom and for how long, for 24 months. Never its audio, video or the words spoken.It is what the trust score, your shared history and a later report are computed from.
When you started looking for a conversation3 hours.So that somebody searching on a quiet evening can be told how recently anyone else was here, and how often people come — as counts and a clock, never as names or topics.
Direct messagesUntil either person deletes their account.They are correspondence between two people.
Reports, suspensions and moderation decisions36 months, and they survive the reported account being deleted — with the deleted person reduced to an internal identifier.Art. 17(3)(e) GDPR — establishing and defending legal claims, and stopping a ban being erased by deleting and re-registering.
Server and delivery logs14 days.Diagnosing faults and abuse.
Invoices, if you ever pay for anything10 years.§147 AO and §257 HGB. Not our choice.

7. Your rights

Under the GDPR you have the right to:

  • Access (Art. 15) — get a copy of everything we hold about you.
  • Portability (Art. 20) — get it in a machine-readable format. Settings gives you a JSON download immediately.
  • Rectification (Art. 16) — correct anything wrong. Most of it you can
    edit yourself.
  • Erasure (Art. 17) — delete your account. Settings does it immediately and permanently. What survives is listed there and in §6: moderation records, with you reduced to an internal identifier, under Art. 17(3)(e).
  • Restriction (Art. 18) and objection (Art. 21) — in
    particular, you may object at any time to anything we base on legitimate interests.
  • Withdraw consent (Art. 7(3)) — for email, push and search-engine
    listing, in Settings.

Write to [email protected] for anything the interface does not do for you. We answer within one month (Art. 12(3)).

You also have the right to complain to a supervisory authority (Art. 77). Ours is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 27, 91522 Ansbach, Germany. You may also complain to the authority where you live.

8. Automated decisions

Your trust tier is computed automatically from peer ratings, and a low one limits how much a brand-new account can do. It never produces a legal or similarly significant effect within the meaning of Art. 22(1), and a human reviews every suspension and every appeal. Matching is automated and is based on the topic and languages you chose.

9. Security

Everything travels over TLS. Conversations are end-to-end encrypted between browsers by WebRTC's mandatory DTLS-SRTP. Sign-in links are single-use and expire in 15 minutes. Sessions are HttpOnly cookies a script cannot read. The database is not reachable from the internet. Backups are encrypted and held off-site.

10. Children

ChatFederation is for adults: you must be 18 or older. We do not knowingly collect data from anyone younger, and an account we learn belongs to someone under 18 is deleted. If you believe a child is using the service, tell us at [email protected].

11. Changes

If we change this policy in a way that matters, we will say so on the site and email you before it takes effect. The date at the top always reflects the current version.

See also the terms of service, the imprint, and how reporting works.