Privacy
Last updated 3 October 2026
Beta draft: operator details are being finalised and this text is pending legal review.
Zhat is designed to know as little about you as possible. This page explains exactly what is processed, why, and for how long.
Who is responsible
The controller is [Operator legal name], [Registered address] (registry code [Company registry code]). Contact: hello@zhat.chat.
Posts, replies and photos
- Posts, replies, photos and reactions are stored by the server that runs your area's room (Cloudflare), only so people can read and reply to them while they're live.
- They are deleted automatically when they expire: 24 hours after a topic is posted in local rooms (its replies go with it), or as set by an event room. We keep no copies or backups of them.
- Before a message or photo is shown, it is sent to Google's Gemini API for automated safety screening. We use the paid API, under which Google doesn't use the content to train its models; Google may keep it for a limited time to detect abuse of its service.
- If someone reports a message, a copy (text, photo, the room and the sender's random ID) is kept for up to 30 days so a person can review it, then deleted.
- Photos are re-encoded on your device before sending, which removes hidden metadata such as GPS coordinates.
Your passkey and identity
- Your passkey is created and kept by your device (and, if you use one, your password manager or iCloud/Google account). Face ID, fingerprints and PINs are checked by your device; we never receive them.
- We store the passkey's public key and its ID so you can use it again on another device. Your display name and avatar are derived from that ID. We don't ask for, or store, your name, email or phone number.
Location
Your device converts your position into an area code (a “geohash” cell about 150 m across at the smallest). Only that code is sent, to connect you to the right room and to show local business posts for your area. It isn't stored.
Business posts
If you post for a business, we store the business details and posts you submit, the area they're shown in, and the review decision. Posts and their photos are deleted 30 days after they end or are withdrawn.
Technical data
Our host, Cloudflare, processes IP addresses to deliver the service, protect it from attacks and enforce rate limits. Operational logs contain request metadata and errors, never message content, and are kept for a short time. We use no analytics, advertising trackers or third-party cookies. Your browser stores your passkey certificate, theme and blocked list locally.
Legal bases
- Providing the service you ask for (Art. 6(1)(b) GDPR).
- Keeping it safe and lawful: moderation, reports, abuse prevention (Art. 6(1)(f) and 6(1)(c) GDPR).
Processors
- Cloudflare, Inc. — hosting, storage and security.
- Google LLC — automated content screening via the Gemini API.
Your rights
You can ask for access, correction, deletion or restriction of your data, object to processing, and complain to your data protection authority. Because we don't know who you are, include your Zhat ID (shown on the passkey page) when you contact us.