Terms of Service
Effective October 7, 2026 · CryptoChat is operated by Black Cipher
These terms are an agreement between you and Black Cipher ("we", "us") about your use of CryptoChat, the messenger available at this website (the "Service"). By creating an account or using the Service you agree to them. If you don't agree, please don't use CryptoChat.
The short version
Be decent, keep your password and encryption key safe, don't abuse the Service, and know that we can restrict accounts that break the rules. We can't recover a lost encryption key or read your end-to-end encrypted messages.
1. Your account
- You must be at least 13 years old (or the minimum age of digital consent in your country, if higher) to use CryptoChat.
- Give us a real email address that you control. We use it to verify your account and to send security and account notices.
- You are responsible for your password and for everything done through your account. Tell us promptly if you think it was compromised. You can sign out other devices from Settings at any time.
- One person, one account. Don't impersonate others or create accounts to evade a restriction.
2. Acceptable use
You agree not to use the Service to:
- harass, threaten, bully or abuse anyone, or send spam, scams or unsolicited bulk messages;
- share illegal content, including any sexual content involving minors, or content that promotes violence or exploitation;
- distribute malware or try to gain unauthorized access to accounts, systems or data;
- probe, scrape, overload or interfere with the Service, or work around its rate limits and security measures;
- infringe other people's rights, including intellectual property and privacy.
3. Your content
You keep ownership of the messages, photos, voice messages and files you send. You give us only the limited permission needed to store, transmit and deliver them to the people you send them to, and to operate the Service. We don't use your content for advertising.
You are responsible for what you send. Because end-to-end encrypted content can't be read by us, we generally can't see it unless someone in the conversation chooses to share it with us, for example by attaching messages to a report.
4. Encryption and your keys
- When end-to-end encryption is on for both people in a chat, message contents are encrypted on your device. Your private key is stored only on your device. We cannot recover it. If you lose the device without a key backup, or forget your backup passphrase, encrypted messages can't be read again.
- Messages in a chat where encryption is off for either person are stored on our servers in readable form. The app shows when a chat is encrypted.
- Secret chats are optional, tied to one browser and one sign-in, locked by a passphrase you choose, and have no backup. Signing out, revoking the session or clearing site data erases them permanently.
- No security system is perfect. Verify security codes with the people you talk to, and keep your devices and software up to date.
5. Reports, moderation and enforcement
You can report a user and optionally attach part of your chat with them. Our moderators may issue warnings, mute, suspend or ban accounts, remove content, or take other reasonable action when these terms are broken, when the law requires it, or to protect people and the Service. Restricted users can still sign in to read their messages and contact support from Settings. Moderator actions are recorded in an internal audit log.
If you think a decision was a mistake, write to us through Settings → Support.
6. Limits and fair use
To keep the Service fast and safe we apply limits, such as how quickly you can send messages and uploads, the maximum file size, group size, and how long a message can be edited. We may change these limits, and we may pause sending for maintenance.
7. Ending your account
You can delete your account at any time from Settings. Deletion is permanent. See the Privacy Policy below for what is removed. We may suspend or end accounts that break these terms.
8. The Service is provided "as is"
We work hard to keep CryptoChat reliable and secure, but we provide it "as is" and "as available", without warranties of any kind, to the extent the law allows. We don't guarantee that the Service will be uninterrupted, error-free, or that messages will always be delivered.
To the maximum extent permitted by law, Black Cipher is not liable for indirect or consequential losses, lost data (including lost encryption keys) or lost profits arising from your use of the Service. Nothing in these terms limits liability that can't be limited by law.
9. Changes to these terms
We may update these terms from time to time. If a change is significant we will tell you in the app or by email before it takes effect. Continuing to use CryptoChat after a change means you accept it.
10. Contact
Questions about these terms? Contact us through Settings → Support after signing in. If you can't sign in, use the contact details published on this website.
Privacy Policy
Effective October 7, 2026 · Black Cipher
This policy explains what CryptoChat collects, why, who sees it, and the choices you have. We collect only what we need to run a messenger.
The short version
We don't sell your data and we don't show ads. End-to-end encrypted messages and files are unreadable to us. Everything else you send is stored on our server until you or the other person delete it. You can delete your whole account in Settings.
1. What we collect
| Data | Details |
| Account | Email, username, display name, optional profile photo and bio. Your password is stored only as a salted hash (PBKDF2), never in plain text. |
| Messages and files | Direct and group messages, photos, voice messages and files, with timestamps, delivery/read status, replies, reactions and edits. For end-to-end encrypted content we store only ciphertext. |
| Encryption public keys | Your public key, so others can encrypt to you. Your private key stays on your device. For secret chats we store public keys and temporarily relay ciphertext. |
| Sign-in sessions | For each signed-in device: a hashed session token, approximate device name from the browser's user agent, IP address, and when it was created and last used. This powers the "Devices" list and security protections. |
| Presence | Whether you're online and your "last seen" time. Only people you have messaged can see it, never people you blocked, and you can hide it from specific people. |
| Notifications | If you allow push notifications, your browser's push subscription (endpoint and keys). Notifications for encrypted messages never contain message text. |
| Safety and support | Reports you make (and any messages you choose to attach), blocks, mute settings, moderation actions taken on accounts, support requests and replies. |
| Temporary security data | Hashed email verification codes and password reset tokens, and short-lived rate-limit counters kept in memory. |
We do not collect your contacts, location, or device identifiers beyond what is listed above.
2. How we use it
- To provide the Service: deliver messages, sync your chats, show profiles and presence, and send notifications.
- To keep it secure: verify your email, protect sign-ins, limit abuse and spam, show you your active devices, and investigate reports.
- To communicate with you: verification codes, password and security notices, and account notices such as a ban, suspension or verification change.
- To meet legal obligations and enforce our terms.
We do not use your messages for advertising, profiling or training models.
3. End-to-end encryption: what we can and can't see
- Encryption on for both people: message text, voice messages, photos and files are encrypted on your device. We can see that a message exists, who it's between, its size and when it was sent, but not its contents or file names.
- Encryption off for either person: messages are stored readable on our server and could be viewed by authorized staff when handling a report or a legal request.
- Groups: in a group, each member's own encryption setting decides whether their messages are encrypted. Members with encryption off cannot read encrypted messages.
- Secret chats: relayed only as ciphertext between two specific devices. Undelivered ciphertext and files are deleted once delivered, or after 14 days, and everything is erased when the session ends.
- Reports: if you attach messages to a report, the selected messages are decrypted on your device and sent to our moderators in readable form. Nothing else from the chat is shared. Messages from encrypted chats are marked as unverified because we can't confirm their exact wording.
4. Who we share data with
We don't sell your personal data. We share it only with:
- The people you talk to, who receive what you send, your name, photo, bio and (subject to your settings) presence.
- Service providers that help us run CryptoChat:
- Cloudflare Turnstile, to tell humans from bots on sign-up, password reset, reports and admin sign-in. It processes technical signals such as your IP address and browser details.
- An email delivery provider (SMTP), which receives your email address and the message we send.
- Your browser vendor's push service (for example Google, Mozilla or Apple), which delivers push notifications.
- Our hosting and database infrastructure providers.
- Authorities, when required by valid legal process, or to protect someone's safety. We can only hand over what we have; we can't provide the contents of end-to-end encrypted messages.
5. Cookies and local storage
- A single
sid cookie keeps you signed in. It is HttpOnly, SameSite=Strict and secure over HTTPS, and lasts up to 30 days or until you sign out. Staff use a separate cookie for the admin panel.
- Your browser's IndexedDB holds your encryption keys, key-backup status and, for secret chats, locally encrypted history and files. A few small settings and drafts use local or session storage.
- We use no advertising or analytics cookies.
6. How long we keep data
- Messages and files: until deleted. "Delete for everyone" removes a message and its file from our server. "Delete for me" hides it for you, and the file is erased once both people have deleted it. Clearing a chat works the same way.
- Sessions: until they expire, you sign out, or you revoke them. Push subscriptions are removed when their session ends.
- Verification codes and reset links: a few minutes to under an hour.
- Reports, moderation records and the staff audit log: kept as long as needed for safety, abuse prevention and legal reasons.
- Account deletion: when you delete your account we permanently remove your profile, photo, sessions, keys, the messages you sent and received (including in groups) and the files you shared. Conversations with you disappear for the other people too. Groups you own pass to another member, or are deleted if nobody is left. Backups and moderation or legal records may persist for a limited period.
7. Your choices and rights
- Access and update: edit your name, username, bio and photo in Settings.
- Control who sees your status: hide your online status from specific people, block users, and mute chats.
- Security: view and sign out devices, change your password, and manage or back up your encryption key.
- Delete: delete your account and data from Settings.
- Other rights: depending on where you live (for example under the GDPR) you may have the right to access, correct, export, restrict or object to the processing of your data. Contact us through Settings → Support and we'll respond.
8. Security
We protect data with HTTPS, hashed passwords, rate limiting, signed-in device controls, mandatory two-factor authentication for staff, and strict access controls for administrators. No system is perfectly secure, and encrypted content can only be as safe as your device and key backup.
9. Children
CryptoChat isn't intended for children under 13. If you believe a child has created an account, contact us and we'll remove it.
10. International transfers
Your data may be processed in countries other than your own, including where our providers operate. We rely on appropriate safeguards where required by law.
11. Changes and contact
We'll post updates to this policy on this page and notify you of significant changes. For privacy questions or requests, contact us through Settings → Support after signing in.