Privacy Policy

Chatch · Last updated September 29, 2026
Chatch helps adults compose messages using AI. This policy covers the Chatch app, its iOS keyboard extension, and the services that power them.

1. Who is responsible

ARCTICS GROUP, registered in France under SIREN 930 474 473, is the publisher and data controller for Chatch. You can contact us at contact@arcticsgroup.com or write to 21 Boulevard Delessert, 75016 Paris, France.

2. Information you choose to send

When you request a reply, we process the message you paste or the screenshot you select, your chosen tone, language, and reply preferences. Wingman processes your message and up to ten recent messages for context. Inputs can contain information about you and other people. Please remove names and unnecessary personal details, and do not submit passwords, financial information, health information, intimate images, or other sensitive information. Only share content you are entitled to use.
The app does not require a named account. If you contact support, we receive your email address and the information you include. Sending content is optional, but AI features cannot work without the relevant input.

3. Keyboard, photos, and notifications

The iOS keyboard checks whether copied text is available without reading it. It reads the text only when you tap C to request a reply. It does not record ordinary keystrokes, read the conversation bubbles in another app, or continuously monitor your clipboard. Full Access enables its network connection and shared settings with Chatch; you can disable it or remove the keyboard in iOS Settings. The setup practice reply is generated locally from the supplied practice message.
We process only the screenshot you select, not your entire photo library. Before sending it, the app resizes and re-encodes it to remove photo metadata. You can remove the selected image before generation or revoke photo permission in device settings. Optional trial reminders are local device notifications; this feature does not register a remote push token. You can turn notifications off in device settings.

4. Device and service information

Chatch creates a random installation identifier and a secret credential to authenticate requests, administer free allowances, and check subscription access. These are pseudonymous identifiers, not anonymous data. Credentials are stored in the device's secure storage on iOS and Android; a web version uses browser storage. The iOS app shares a short-lived session token and preferences with its keyboard in a protected app container.
Our infrastructure receives connection information, including your IP address. Application rate limits use a keyed hash of the IP address. Technical logs contain request identifiers, model names, timing, token counts, success or error status, and a shortened keyed installation identifier. Application logging excludes message text, screenshots, generated replies, credentials, and raw IP addresses.

5. Purposes and legal bases

We process requested inputs and subscription information to provide the service under our contract with you. We use limited identifiers and technical information for our legitimate interests in securing the service, preventing abuse, administering allowances, and resolving faults. Support correspondence is processed to respond to your request. We also process information when needed to comply with legal obligations. Where consent is required for an optional activity, that activity requires your consent; consent can be withdrawn without affecting earlier lawful processing. Device permissions can be changed in device settings.
AI produces suggestions that you decide whether to use. Chatch does not use them to make decisions about you with legal or similarly significant effects.

6. Service providers and AI

Cloudflare hosts the backend and usage records. OpenAI processes the content submitted for AI replies and coaching. Requests are encrypted in transit. Our backend does not maintain a conversation or screenshot archive, and requests disable storage of retrievable AI responses. This is not a promise of zero retention by the AI provider: OpenAI's default abuse monitoring may retain inputs and outputs for up to 30 days, with longer retention for legal or safety reasons. Model caching and image safety review can also involve temporary retention. OpenAI's API data controls are described at https://developers.openai.com/api/docs/guides/your-data.
Apple or Google processes purchases. RevenueCat receives the random installation identifier and purchase history, including transaction and subscription entitlement information. We use these records to validate purchases, provide and restore Pro access, prevent purchase fraud, and understand subscription performance through RevenueCat's customer history and analytics. Purchase history is linked to the installation identifier; it is not anonymous. Chatch does not receive your full payment card details. These providers also process information under their own applicable terms and privacy policies.
PostHog feature analytics and Sentry error reporting are disabled in Chatch 1.2.0. RevenueCat subscription analytics and the operational records described in this policy remain in use. We will update our disclosures before enabling additional analytics or diagnostics. Information may also be disclosed when required by law or necessary to protect users and the service.
When remote feature controls are enabled, PostHog supplies settings that determine which app sections are shown. Fetching these settings sends a pseudonymous SDK identifier, limited app and device information, and connection information to PostHog. Feature-use event capture, flag-evaluation analytics events, advertising attribution, and session replay remain disabled in this configuration. Conversation text, screenshots, and generated replies are not sent to PostHog.

6.1. Advertising and tracking

Chatch does not track you across other companies' apps or websites. We do not combine purchase history, installation identifiers, conversation content, or other app data with third-party data for targeted advertising or advertising measurement. We do not access Apple's advertising identifier (IDFA), sell personal data, or share it with data brokers. Purchase history and installation identifiers are used for the app functionality and subscription analytics described above, not for advertising tracking. This applies to the Chatch app and its iOS keyboard in every country and region where they are offered.

7. Storage and retention

Up to 30 recent Wingman messages stay in app memory for the current session and are not saved to device storage. Earlier saved Wingman history is removed when this app version starts. Reply drafts and results are also held temporarily in app memory. The app deletes the processed screenshot file after preparation and keeps its preview in app memory until you remove or replace it or clear conversations. The photo picker or device may leave other temporary files in its cache until the operating system clears them. Your original photo is not deleted.
The backend processes message and image content in memory for the request and does not write it to its database. Installation credentials and cumulative usage counters persist to administer lifetime free allowances and secure access; they do not automatically expire when you delete local conversations or uninstall. Contact us to request deletion of associated server records. Rate-limit records are short-lived, while request-deduplication entries are pruned on subsequent activity. Operational, support, subscription, and any enabled diagnostic records are kept only as needed for their purpose, resolving disputes, security, and applicable legal obligations. Provider retention and device backups can differ from local app deletion.

8. International processing and security

Our providers may process data outside your country, including in the United States. Transfers from the European Economic Area are subject to the protections required by applicable law, such as an adequacy decision or standard contractual clauses where applicable. Contact us for information about the safeguards relevant to your data. We use encrypted connections, protected credentials, and access controls, but no service can guarantee absolute security.

9. Your choices and rights

Settings → Delete conversations clears the app's current inputs, prepared preview, and Wingman messages from the current session. It does not cancel a subscription or erase server usage records. You can use the app without enabling the keyboard, and can revoke device permissions at any time.
Depending on applicable law, you can request access, correction, deletion, restriction, or portability of your personal data, object to processing based on legitimate interests, and withdraw consent where processing relies on it. Email contact@arcticsgroup.com with “Chatch privacy” and describe your request. Because Chatch uses installation identifiers rather than named accounts, we may need limited information to locate your records and verify the request. Never email your secret credential or unneeded conversation content. We respond within the period required by law, normally one month under the GDPR, and explain any permitted extension or exception. You can complain to your local data protection authority, including the CNIL in France at https://www.cnil.fr.

10. Adults, updates, and contact

Chatch is intended for people aged 18 or older. We do not knowingly collect children's personal data; contact us if you believe a child has provided it. We will address the report and delete information where appropriate.
We will update this policy when practices change and provide additional notice of material changes where required. The date above identifies this version. Questions and privacy requests: contact@arcticsgroup.com. The public copy is at https://arcticsgroup.com/privacy-policy-chatch.
Publisher: Arctics Group SARL, France · SIREN 930 474 473 · contact@arcticsgroup.com