Who we are
TAKEMADE PTY LTD operates ChatShyld. Our contact is support@qxottic.com; postal address: 11 Paringa Blvd, Meadow Heights VIC 3048, Australia. This policy applies to the new non-end-to-end-encrypted Firebase version and this legal website. Features may include phone-based registration, messaging, private attachments, groups, voice/video calls and optional Assist. We process the information needed for enabled features you use. Public availability and individual features may be restricted by platform, telephone market or provider support.
Information we collect
- Account and profile: phone number, internal account identifier, optional username, name, photo, bio, preferences and records of the legal versions accepted. Your phone number is kept separate from publicly discoverable profile records.
- Communications: messages, attachments, voice messages, recipients, group memberships, reactions, delivery/read information and related timestamps needed to provide the features you use.
- Calls: participants, timing, connection/quality information and audio/video processed to connect a call. This version does not offer a built-in call-recording feature. Other participants may independently record or capture a call.
- Optional Assist: the prompt, exact message excerpts you choose and review, and generated result. We do not automatically submit every conversation to Assist.
- Device and service information: app/device identifiers, push tokens, app-integrity signals, network/IP information, diagnostic and security events, rate-limit records and sign-in/session activity.
- Support and safety: your communications with support, reports, submitted evidence and actions taken to resolve complaints or abuse.
We receive information directly from you, through your use of the app, from people communicating with or reporting to us about you, and from providers supporting the requested feature. We collect what is reasonably needed for these purposes. Without required account information, we cannot register you; declining an optional permission may restrict that feature without requiring you to grant unrelated access.
Permissions and visibility
Camera, microphone, photo-library, contacts and notification permissions are requested in context where the feature needs them. You can change permissions in device settings. Contact matching is opt-in. Normalised phone numbers selected for matching are processed transiently; we do not retain a raw address book. Contacts are not collected merely by registering. Phone discovery and username discovery have independent controls and default off. Photos and files are shared with the people or groups you choose. Public-facing profile fields and username discovery have separate controls. Turning username search off prevents that discovery route; it does not erase information already shared or prevent members of an existing conversation recognising you.
Notifications may reveal sender information or previews on your device, depending on your preferences and operating-system settings. Group members can see information relevant to their membership. Blocking stops supported direct interactions and discovery but does not automatically remove existing shared-group visibility.
How information is used
We use information to verify phone access, maintain accounts and sessions, deliver and synchronise communications, connect calls, provide optional Assist, apply your preferences, handle support and deletion, detect abuse, protect service integrity and meet legal obligations. We do not sell personal information or use private message content for targeted advertising in this product. Changes to those practices would require updated disclosure and any consent required by law.
Providers and disclosure
Google Firebase/Google Cloud provides authentication, database, private media storage, backend processing, app-integrity services and notifications. Phone numbers supplied for authentication are sent to and stored by Google for spam and abuse prevention across Google services, as well as sign-in verification.
Agora carries voice/video call media and processes connection, device and quality information. ChatShyld does not enable call recording. For its RTC service, Agora publishes default retention of up to 30 days for dynamic IP and network information, up to 30 days for session identifiers, and up to 365 days for device diagnostics. Live RTC media is streamed without storage. Different customer agreements can change these defaults. Provider operational records are distinct from call content and do not necessarily disappear when a call ends.
OpenAI processes only the text you explicitly review and choose to share with Assist. Our integration uses the Responses API with response storage disabled, no background mode and no model tools. This does not disable provider abuse monitoring. OpenAI describes default abuse-monitoring retention of up to 30 days, with longer retention for legal or safety exceptions. Provider-side prompt caching is separate from response storage; its retention depends on the model and provider settings. We do not claim Zero Data Retention, an approved retention exception, or Australia-only OpenAI processing. Account-specific data-sharing and retention settings must remain consistent with this disclosure. Apple and Google process push-delivery and platform information as needed for their operating systems.
Vercel hosts the legal website and processes requests such as your IP address, browser/request information and security logs to deliver and protect it. These pages do not add advertising, analytics scripts or third-party fonts. Opening an external provider link takes you to that provider’s site and privacy practices.
We disclose content and profile information to recipients you select, and relevant information to authorised staff and providers performing these functions. We may disclose information to comply with valid legal requirements, protect rights or safety, investigate abuse, or support a business transfer with appropriate safeguards and notices. We do not claim that only conversation participants can access server-held content.
Security and international processing
ChatShyld is not end-to-end encrypted. We use access controls and encrypted transport/storage provided by our infrastructure, but authorised server-side processing remains possible. No service can guarantee absolute security. Keep your device and verification codes secure and tell us promptly about suspected misuse.
The selected primary Firestore database, media bucket and backend Functions region is Sydney, Australia. Firebase Authentication processes authentication data in the United States. Vercel website processing can involve the United States and its worldwide delivery network. Google’s other services may use global infrastructure, including facilities in the Americas, Europe and Asia-Pacific; a specific request’s route is not controlled by the Sydney database setting. We identify Australia and the United States as current known processing locations, and refer to the providers’ current location information below where individual global delivery locations cannot be specified in advance. This is not an Australian-only data-residency promise.
Agora calling, OpenAI Assist and ordinary notifications use their configured provider infrastructure and may involve international processing. The Sydney database setting does not determine where those providers process every request. We take reasonable steps and apply the safeguards required by applicable privacy law for overseas disclosures. Contact us for information about the providers relevant to your use.
Retention and deletion
We retain account information and server-held communications while needed to provide your account and the features you use, subject to your deletion requests and applicable obligations. Operational, security, complaint and transaction records are kept only as needed for their purposes, legal requirements and dispute handling. Retention is reviewed; different categories can have different periods.
Firebase Authentication retains account information until deletion is initiated; Google states that removal from its live and backup authentication systems can take up to 180 days after that. Authentication IP logs are kept for a few weeks. The configured private media bucket has a seven-day soft-delete recovery period once an object is deleted; this does not mean all account information or recipient copies disappear in seven days. Objects are made unavailable to new delivery grants before their recovery retention expires. Previously issued delivery grants may remain usable for up to 60 seconds. We cannot recall a delivered file.
Firestore database backups are scheduled daily and retained for seven days from creation. Restore operations remain isolated until account-deletion requests have been reapplied and old sessions have been invalidated. We retain a minimal separate deletion ledger containing an internal user identifier, a hash of that identifier, deletion request identifiers, timestamps and receipt-verification information, with no phone number, profile or message content. It has no automatic expiry while it is needed to prevent restoration from exposing deleted accounts or files.
Application operational logs exclude message text, phone numbers and credentials and are retained for 30 days. Google Cloud mandatory administration/system audit logs have a separate 400-day retention. Assist results become unavailable in ChatShyld after one hour; database TTL cleanup is asynchronous, and recovery backups can retain earlier copies. Verification proof records and rate counters generally expire after one day; idempotency records after seven days; completed phone-change recovery records after 30 days. These expiry targets do not promise instantaneous physical erasure.
Restricted records about a complaint made by another user, and operator audit trails, may remain for safety, legal obligations and dispute handling even after a subject account is deleted. We remove the deleted account’s authored content from retained report evidence. The retention period for these exceptional records is subject to a documented purpose and review, and applicable legal holds; contact us for the basis and scope of a particular retention.
Deleted information may persist temporarily in restricted recovery copies, backups or provider security systems until the applicable retention cycle ends. Deleting an account is separate from clearing local cache or uninstalling. We cannot erase independent copies retained by recipients. The Account Deletion page explains requests, ownership checks and exceptions. We will provide a practical response about the scope and timing of your request, rather than promise immediate removal from every backup.
Your choices, access and complaints
Contact support@qxottic.com to request access, correction or deletion, ask about a processing activity, or complain about privacy. Include the request and enough information to locate your account; do not send a password, SMS code or identity document unless we explain a necessary secure verification method. We may verify ownership before disclosing or changing personal information. We will respond within a reasonable time and any applicable legal deadline; if a request cannot be met, we will explain why and available review options where required.
If your privacy complaint remains unresolved, you may contact the Office of the Australian Information Commissioner at oaic.gov.au or the competent authority where you live. Your statutory rights are not limited by this policy. Publication of this policy does not imply that ChatShyld has received privacy certification or approval in any country.
Age and changes
ChatShyld is for people aged 18 and over. Contact us if you believe an underage person has registered so we can investigate and take appropriate action. We will date and version policy updates and provide notice of material changes as required. The version shown above identifies this published policy. Historical E2EE product descriptions do not describe this Firebase version.