Privacy policy
1. Introduction
Your messages are end-to-end encrypted and can be read only by you and the people you chat with – not even we can read them. This privacy policy describes how we ("we", "us") handle personal data in the chat service (the "Service").
We are the controller for the processing described here and comply with the EU General Data Protection Regulation (GDPR) and supplementary Swedish legislation. By using the Service you confirm that you have read this policy.
2. What data we collect
We collect only what is needed for the Service to work.
| Category | Example | Why |
|---|---|---|
| Account data | Username, email address or telephone number, profile picture (optional) | To create and identify your account |
| Encryption keys | Public keys | So that others can send you encrypted messages. Private keys never leave your device |
| Technical data | IP address, device type, operating system, app version | For operation, troubleshooting and protection against misuse |
| Metadata | Time of login, delivery status for messages | To deliver messages and detect security incidents |
| Support cases | What you write to our support yourself | To help you |
What we do not collect: the content of your messages, pictures, files or voice messages. All such content is encrypted on your device before it is sent and can be decrypted only by the recipient.
3. End-to-end encryption
- Messages are encrypted on the sender's device and decrypted only on the recipient's device.
- Our servers only forward encrypted data and have no access to the keys.
- Encrypted messages that could not be delivered are stored temporarily for no more than 30 days and are then deleted automatically.
- Delivered messages are deleted from our servers immediately after delivery.
- You can verify a contact's security code to confirm that no unauthorised party is between you.
4. Legal basis
- Contract (art. 6(1)(b) GDPR): account data and the processing required to deliver the Service.
- Legitimate interests (art. 6(1)(f)): security, fraud prevention and improvement of the Service.
- Legal obligation (art. 6(1)(c)): where the law requires us to store or disclose data.
- Consent (art. 6(1)(a)): for example voluntary analytics or marketing. You can withdraw your consent at any time.
5. How long we keep data
| Data | Retention period |
|---|---|
| Account data | For as long as the account is active, erased within 30 days after the account has been closed |
| Undelivered encrypted messages | No more than 30 days |
| Technical logs | No more than 90 days |
| Support cases | 12 months after the case has been closed |
| Data we are required to keep by law | For as long as the law requires |
6. Sharing of data
We never sell your personal data. We share it only with:
- Processors that help us run the Service, for example cloud providers and email or SMS services for verification. They may only process the data in accordance with our instructions.
- Authorities where we are required to by law. Because messages are encrypted, we cannot disclose message content.
- In the event of a business transfer, where the recipient becomes bound by this policy.
We aim to store data within the EU/EEA. If data is transferred outside the EU/EEA, this is done on the basis of the European Commission's standard contractual clauses or another valid safeguard.
7. Your rights
Under the GDPR you have the right to:
- obtain access to the data we hold about you (a register extract),
- have inaccurate data rectified,
- have your data erased (the "right to be forgotten"),
- restrict or object to certain processing,
- receive your data in a machine-readable format (data portability),
- withdraw consent at any time,
- lodge a complaint with Integritetsskyddsmyndigheten (IMY, the Swedish Authority for Privacy Protection), www.imy.se.
Contact us to exercise your rights. We reply within one month.
8. Security
- All traffic between the app and the server is protected with TLS.
- Content is protected with end-to-end encryption.
- Access to systems and logs is limited to authorised personnel.
- We recommend that you activate two-step verification and a screen lock on your device.
In the event of a personal data breach that may entail a risk to you, we report it to IMY within 72 hours and inform the users concerned.
9. Cookies and analytics
Our website uses necessary cookies for login and security. Analytics and marketing cookies are used only if you consent.
10. Children
The Service is not intended for persons under the age of 18. If we discover that an account belongs to someone below the age limit, it is deleted.
11. Changes to the policy
We may update the privacy policy. Material changes are notified in the service or by email at least 30 days before they take effect.
12. Contact
Questions about privacy or your rights are sent to us through support. If you want the company details, including who the controller is, write to info@xdately.com.
Last updated: 26 September 2026