Privacy Policy
LighChat Privacy Policy
Last updated: 2026-08-03 Version: 2 Applies to: web/PWA (lighchat.online), mobile apps (iOS, Android) and desktop apps. Contact: privacy@lighchat.online
1. Who we are
This Policy explains what personal data KDS Consulting Inc ("LighChat", "we", "us") collects and processes when you use the LighChat messenger (the "Service"), and what rights you have.
Controller details:
- Legal name: KDS Consulting, Inc. (a Florida corporation)
- Address: 1730 S Federal Hwy, Suite 160, Delray Beach, FL 33483, United States
- Phone: +1 561-702-9557
- Registration: Florida profit corporation, State of Florida document number P02000081666
- Privacy enquiries: privacy@lighchat.online
- Legal enquiries: legal@lighchat.online
By using the Service you confirm that you have read this Policy. If you disagree with it, do not use the Service.
2. Laws that apply
We process personal data in accordance with:
- the General Data Protection Regulation (EU) 2016/679 (GDPR) and the UK GDPR — for users in the EEA, Switzerland and the United Kingdom;
- the California Consumer Privacy Act as amended by the CPRA (CCPA) and comparable U.S. state privacy laws (Virginia, Colorado, Connecticut, Texas, Utah, Oregon, Montana, Florida and others) — for U.S. residents;
- the Children's Online Privacy Protection Act (COPPA) — see the Children Policy;
- Canadian PIPEDA, Brazilian LGPD and other local data-protection laws where they apply to us.
The Service is operated from the United States and is not directed at users located in the Russian Federation.
3. Data we collect
3.1 Account data
- name, display name, username;
- email address;
- phone number (optional — for verification and contact discovery);
- confirmation that you are 16 or older (mandatory self-declaration at sign-up);
- date of birth (optional, for profile features — not used for age verification);
- avatar, bio;
- interface preferences (language, theme, notification and privacy settings).
3.2 Content and communications
- messages (text, media, files, reactions, voice notes);
- message metadata (sender, recipient, timestamp, delivery/read status);
- call and meeting data (duration, participants, technical quality metrics);
- starred messages, contacts, block list.
End-to-end encrypted chats. When E2EE is enabled, message content is encrypted on your device. We hold only ciphertext and transport metadata and cannot read those messages, provide them in readable form to anyone, or restore them if you lose your keys.
3.3 Technical data
- IP address (used transiently for security and abuse prevention; we store derived country/city rather than the raw address where feasible);
- device type, model, operating system and version, build identifier;
- push tokens (Firebase Cloud Messaging, Apple Push Notification service);
- crash and error reports (Crashlytics);
- diagnostic events that do not contain message content.
3.4 Meetings and guest sessions
- meeting identifier, guest display name, join/leave timestamps;
- WebRTC technical data (ICE candidates, quality metrics);
- guest-session data is deleted automatically within 24 hours after the meeting ends.
3.5 Security data
- sign-in history with device information (Settings → Devices);
- E2EE material: public device keys are stored on our servers; private keys never leave your device;
- QR-login and device-pairing parameters.
3.6 Payment data
The Service is currently free of charge. If paid subscriptions are introduced, purchases will be processed by Apple, Google or another payment provider under the Billing Terms. We do not receive or store your card number; we receive only a transaction identifier and subscription status.
4. Why we process data, and on what legal basis
| Purpose | Categories | Legal basis (GDPR) |
|---|---|---|
| Creating your account, authentication | Account data, phone/email | Contract, Art. 6(1)(b) |
| Operating the messenger (delivery, sync, storage) | Content, metadata | Contract, Art. 6(1)(b) |
| Push notifications | Push tokens, events | Contract, Art. 6(1)(b) |
| Security, anti-fraud, anti-abuse | Devices, IP, logs | Legitimate interests, Art. 6(1)(f) |
| Responding to your requests and reports | Correspondence | Contract; legitimate interests |
| Legal compliance (including lawful requests) | As applicable | Legal obligation, Art. 6(1)(c) |
| Product analytics | Pseudonymised technical events | Consent, Art. 6(1)(a) (cookie banner / in-app setting) |
| Billing (when paid features exist) | Subscription status, transaction id | Contract; legal obligation (tax records) |
We do not use your messages for advertising, profiling or training machine-learning models.
5. Sharing with third parties
We share data only with service providers (processors) acting on our instructions. The full, current list — with data categories, purposes and jurisdictions — is in the **Subprocessor Registry**. The main categories are:
- Google LLC / Firebase — authentication, databases, storage, serverless functions, push delivery, crash reporting, hosting;
- Apple Inc. — push and VoIP notifications (APNs), app distribution;
- WebRTC infrastructure — TURN relay and media servers for calls and meetings;
- communication providers — transactional email and phone-verification codes;
- sign-in providers — Google, Apple and Telegram, when you choose to sign in through them.
We also disclose data where legally required — see the Law Enforcement Guidelines — and, in the event of a merger, acquisition or reorganisation, to the legal successor on the same terms.
We do not sell your personal data, and we do not share it for cross-context behavioural advertising as those terms are defined in the CCPA and other U.S. state privacy laws.
6. International transfers
We are established in the United States, and our providers operate globally; your data will be processed in the United States and in other countries, including regions of Google Cloud outside your own.
For personal data transferred out of the EEA, the UK or Switzerland, we rely on the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914) together with the UK Addendum, plus supplementary technical measures (encryption in transit and at rest, E2EE for secret chats). A copy of the relevant clauses is available on request at privacy@lighchat.online.
7. Retention
| Data | Retention |
|---|---|
| Active account (profile, messages, media) | For as long as the account exists |
| Deleted account | Messages and media removed within 30 days |
| Security and access logs | Up to 12 months |
| Guest meeting sessions | 24 hours after the meeting ends |
| Crash and error logs | Up to 90 days |
| Abuse reports and moderation records | Up to 24 months |
| Financial and tax records (if paid features exist) | 7 years (U.S. tax law) |
Backups are rotated on a rolling basis, so deleted data may persist in encrypted backups for up to 90 days after removal from production systems.
8. Your rights
Everyone may: access their data, export it in a machine-readable form (Settings → Privacy → Export data), correct it, delete their account (Settings → Account → Delete account), and object to specific processing.
If you are in the EEA, the UK or Switzerland (GDPR): access, rectification, erasure, restriction, portability, objection (including to processing based on legitimate interests), withdrawal of consent at any time, and the right to lodge a complaint with your national supervisory authority.
If you are a U.S. resident (CCPA/CPRA and comparable state laws): the right to know what we collect and why, to delete, to correct, to opt out of sale/sharing (we do neither), to limit use of sensitive personal information, and to be free from discrimination for exercising these rights. You may use an authorised agent; we will verify the request through your account.
Send requests to privacy@lighchat.online. We respond within 30 days (extendable by a further 60 days for complex requests, with notice). Appeals of a refused request: legal@lighchat.online.
9. Cookies and similar technologies
The web version uses cookies, localStorage, sessionStorage and IndexedDB. Analytics run only with your consent. See the Cookie Policy.
10. Security
- TLS 1.2+ for all network connections; encryption at rest on the provider side;
- optional end-to-end encryption (Signal-style protocol) for chats and calls;
- credentials hashed by Firebase Authentication — we never see your password;
- least-privilege access controls, audited Firestore and Storage rules, server-side logic in Cloud Functions;
- vulnerability reporting: see the Security Policy.
In the event of a personal-data breach we notify supervisory authorities within 72 hours (GDPR Art. 33) and affected users without undue delay, in accordance with GDPR and applicable U.S. state breach-notification laws.
11. Children
The Service is intended for users aged 16 and over, and is not directed at children. We do not knowingly collect data from anyone under 16. See the Children Policy.
12. Automated decision-making
We do not make decisions producing legal or similarly significant effects solely by automated means. Automated anti-abuse systems may restrict an account; you can always request human review at legal@lighchat.online.
13. Changes
We may update this Policy. Material changes are announced in the app or by email at least 14 days before they take effect, and the previous version remains available on request. Continued use after the effective date means you accept the updated Policy.
14. Contact
- Privacy: privacy@lighchat.online
- Legal: legal@lighchat.online
- Abuse: abuse@lighchat.online
- Postal: KDS Consulting Inc, 1730 S Federal Hwy, Suite 160, Delray Beach, FL 33483, USA
