Privacy policy
Last updated October 6, 2026
This policy explains which personal data SacketChatty processes, why, for how long, who receives it, and your rights under the EU General Data Protection Regulation (GDPR). It covers the SacketChatty app for iPhone and every server operated by the controller: the public test server and the personal servers set up on request, whose terms and costs are agreed separately.
Data controller
Francesco Sacco
95041 Caltagirone, CT, Italia
sacketchatty@proton.me
There is no data protection officer: write to the address above for any request about your data.
Data we process and how long we keep it
The server keeps only what it needs to deliver messages and keep the service safe.
| Data | Where | How long |
|---|---|---|
| Username and account identifier | Server | Until you delete the account. A username you give up stays reserved for 30 days. |
| Password, stored only as a bcrypt hash; the two-factor (TOTP) secret, if you enable it | Server | Until you delete the account |
| Public keys used for encryption, and device identifiers | Server | Until you delete the account or the device is removed |
| Profile photo and group photo | Server, visible to signed-in users (not end-to-end encrypted) | Until you replace it or delete the account |
| One-to-one messages and attachments, end-to-end encrypted | Server | Removed once a copy has not changed for 30 days and every device it was addressed to has connected since |
| Group messages, end-to-end encrypted | Server | As long as the group and the sender's account exist |
| History backup, encrypted with your passphrase | Server | Until you delete it or the account |
| Your lists: favourites, blocked users, archived and muted chats | Server | Until you delete the account |
| Contact record (who wrote to whom, without content), reports, and the message text a reporter chooses to attach | Server | Until one of the two accounts is deleted |
| Push token | Server and Apple | As long as the device keys exist: removed when the keys are reset, when inactive devices are cleaned up, and when the account is deleted |
| Notification content: sender name, kind of content, conversation identifier and, for groups, the group name | Apple (Apple Push Notification service) | According to Apple's terms |
What we do not collect
No phone number and no email address. No IP address on the servers the app talks to: they can only be reached as an onion service through Tor, so your connection arrives from the Tor network, not from you. No analytics, no advertising, no tracking, and no external error-reporting service.
End-to-end encryption
The content of messages, attachments and backups is encrypted on your device: the controller cannot read it. The only exception is the message text that a user chooses to attach to a report. Profile and group photos are not end-to-end encrypted.
Purposes and legal bases
Providing the service you signed up for: Article 6(1)(b) GDPR. Security and abuse prevention, including the contact record, reports and blocks: Article 6(1)(f), our legitimate interest in a safe service, which we balance by keeping no message content. Complying with legal obligations: Article 6(1)(c).
Who receives the data
Apple, through the Apple Push Notification service, receives the push token and each notification: the sender's name, the kind of content, a conversation identifier and, for groups, the group name, never the text. Apple Inc. is in the United States; the transfer relies on the safeguards Apple adopts, including the EU-U.S. Data Privacy Framework.
The servers run on private infrastructure or on cloud instances; any provider involved acts as a processor under Article 28 GDPR. We do not sell or share data with advertisers.
This website
This website is served by Amazon Web Services (Amazon CloudFront and Amazon S3), which acts as a processor. Like any web server, it keeps access logs: the IP address of the visitor, the browser, the page requested and the time. We use them only to keep the site running and secure (Article 6(1)(f)), and they are deleted after 90 days. The website sets no cookies and loads nothing from third parties.
Test server
The public test server processes the same data in the same way, but all of it is deleted every 10 days: accounts, messages, files and everything else.
Security
Tor with onion client authentication, passwords stored with bcrypt, access tokens that expire, an optional second factor, and encryption keys that stay on your device.
Your rights
Under Articles 15 to 22 GDPR you can ask for access, rectification, erasure, restriction, portability, and object to processing. You can delete your account from the app at any time: your data is erased from the server, except that your username stays reserved for 30 days, and in other people's chats your messages remain as placeholders with no content. For any other request, write to the address above.
You can also lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali (www.garanteprivacy.it), or with the authority of the country where you live.
Minimum age
SacketChatty is meant for people aged 16 or over. Accounts that turn out to belong to younger people are deleted.
Changes
Changes to this policy are published on this page with a new date.