ChatMeet — last updated: August 31, 2026
ChatMeet is a brand of and operated by URSCHILD UG (haftungsbeschränkt), Nordstrandweg 2, 22047 Hamburg, Germany ("we", "us"), represented by its Managing Director Said Abdullah SADAT. We are the data controller for the personal data processed in the ChatMeet app. Contact for all privacy matters: privacy@chatmeet.app.
ChatMeet is a mobile app for meeting new people nearby — for dating, friendship, networking, studying, or exploring. It is intended exclusively for adults (18+).
Account data (e-mail address, password, phone number if you log in by SMS): to create and secure your account. Legal basis: performance of contract (Art. 6(1)(b) GDPR). Your password is stored only as a cryptographic hash.
Profile data (name, photo, gender, custom gender if provided, birth date, bio, purposes, interests): to present your profile to other users — this is the point of the service. Legal basis: performance of contract. Your birth date is used to verify you are 18 or older; other users see only your age.
Location (precise GPS position): only if you explicitly enable "people nearby" discovery in the app. While the discovery screen is active, your position is transmitted to our server to find users around you. Other users never see your position — only an approximate distance. Location is not collected in the background, and we retain only your most recent position, not a movement history. Legal basis: your consent (Art. 6(1)(a) GDPR), revocable at any time in the app; without it, discovery simply stays off.
Messages and message requests: delivered and stored on our server so your conversations work across sessions. Legal basis: performance of contract. You can delete individual messages; deleting your account deletes your conversations.
Face-scan verification: the liveness check (short head movements in front of your camera) is processed entirely on your device using on-device face detection (Google ML Kit). No photo or video of your face is uploaded or stored; the server only receives the yes/no fact that you completed the step. ID-card (NFC) step: currently the app only detects the presence of an ID-capable chip; no data is read from the chip or transmitted. If this changes in the future, we will update this policy and ask for your explicit consent first.
Device and technical data (device model, OS version, app version, a device identifier, push token, IP address as part of normal network traffic): to deliver push notifications, secure sessions, and keep the service working. Legal basis: performance of contract and our legitimate interest in service security (Art. 6(1)(f) GDPR).
Our hosting provider: Hetzner Online GmbH (Gunzenhausen, Germany), data-center location Germany (EU), operating our server under a data-processing agreement.
Google Firebase (Google Ireland Ltd. / Google LLC, USA): push notifications (Cloud Messaging), sign-in with Google, and delivery of account-verification e-mails. Transfers to the USA are covered by the EU–US Data Privacy Framework and standard contractual clauses. Face detection (ML Kit) runs on your device only; nothing is sent to Google for it.
Other users: your profile information (name, age, photo, bio, interests, approximate distance) is visible to users you can discover or chat with — that is the service. We never sell your data, and we show no advertising.
Your data is kept while your account exists. When you delete your account (Settings → Delete account) your profile, photos, messages, requests and location data are deleted or irreversibly anonymized immediately, including removal from routine server backups within the backup rotation of 7 days. Some minimal records may be retained longer where the law requires it.
You have the right to access your data (Art. 15 GDPR), correct it (Art. 16 — largely possible directly in the app), delete it (Art. 17 — the in-app account deletion, or write to us), restrict processing (Art. 18), data portability (Art. 20), and to object to processing based on legitimate interest (Art. 21). Where processing rests on consent, you can withdraw it at any time with effect for the future (e.g. switch discovery off). You also have the right to complain to a data-protection supervisory authority — in Germany, for example, the authority of your federal state.
To exercise any right, e-mail privacy@chatmeet.app. We answer within one month.
All traffic between the app and our server is TLS-encrypted. Session credentials on your device are stored encrypted, with the key protected in your phone's secure keystore, and are excluded from cloud backups. Access to server data is restricted and logged.
ChatMeet is not directed at persons under 18. Registration requires a birth date indicating 18+; we may add identity verification. If we learn that a minor uses the service, we delete the account.
We will update this policy when the service changes (for example, if server-side identity verification or voice messages launch) and inform you in the app of significant changes.