Who we are
2016Chat is a mobile app for nearby social discovery and messaging. The app is operated by an individual developer (a sole trader), referred to in this policy as "the Operator", "we", "us", or "our".
For the purposes of UK and EU data protection law, the Operator is the "data controller" for personal information processed through 2016Chat.
- Operator: Josh (sole trader), United Kingdom
- Privacy contact: privacy@2016chat.com
Who this applies to and where
2016Chat is available to people in the United Kingdom, the European Economic Area (EEA), the United States, and other regions. Your local data protection law applies to you automatically: if you are in the UK or EEA, UK GDPR / EU GDPR rights apply; if you are in California, the CCPA/CPRA applies. This policy is written to cover all of these. Region-specific rights are described in the sections below.
Minimum age (13+) and younger users
2016Chat is intended for people aged 13 and over. The app asks for your date of birth during sign-up and blocks anyone under 13 from creating an account. The service is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If we learn that we hold information about a child under 13, we will delete it.
If you are between 13 and 17, please use 2016Chat with the involvement of a parent or guardian where appropriate. We apply extra care to users under 18: we minimise the data we use about them, we do not use their data for behavioural advertising (we do not run advertising at all), and we do not surface age-restricted (for example, nightlife) recommendations to under-18 accounts.
Information we collect
We only collect what we need to run the service. The main categories are:
- Account information — your email address (for email/password sign-in, or supplied by Apple or Google when you use social sign-in), a unique account identifier, your chosen username, and your account status.
- Profile information — the display name, short bio, and profile photo you choose, and whether your profile is set to be discoverable. When your profile is discoverable, this information is visible to other signed-in users. When it is private, it is still visible to people you have a one-to-one chat with, unless you removed their chat request or blocked them.
- Date of birth / age — collected at sign-up to confirm you meet the minimum age and to apply age-appropriate protections.
- Precise location — if you grant location permission, your device's GPS location is used to power nearby discovery and location-based content. Your precise location and your location history are stored privately and are only accessible to you (and to our backend systems that operate the feature). Raw location history is kept for up to 12 months and is then deleted automatically (see Retention).
- Approximate location — a deliberately coarsened version of your location (rounded to roughly a 1 km area) and your general city. This approximate location is what other discoverable users may see for "people nearby" features — never your exact position.
- Messages and content — the messages you send in direct and group chats, which are visible to the members of those chats, and any content you submit (such as your profile photo).
- Derived interest signals — to personalise suggestions, the app works out a broad interest category from the messages in your chats — both the ones you send and the ones you receive — on your device (for example "food", "nightlife", or "events"). Only the resulting category and the matched keyword are stored under your account, under the account of the person whose app did the reading. The text of your messages is not stored or sent for this purpose.
- Suggestion cards in chats — in a chat where everyone is 18 or over and that has been going for a while (never a chat request), 2016Chat may post a card suggesting a place or event nearby. To decide, our servers check new messages for signs of a plan (for example “fancy a coffee?”); when there is one and two or more people are chatting at that moment, an AI model (an open-weight model run for us by OVHcloud in France) reads up to the last 200 messages of the chat — with members’ names replaced by letters and any phone numbers, email addresses, links and street addresses removed — and reports whether people are planning to meet, what, when and where, and whether the mood is right; the model’s judgement (never the text) is kept as an app activity event under the account of the person whose message prompted it. Our servers also check how many messages each member has sent and on how many days, members’ ages (from the date of birth given at sign-up) and members’ approximate locations. So that suggestions get better without anyone being asked, after a card is posted our servers also work out: whether you replied within a few minutes, whether the chat mentioned the suggested place, how busy the chat was in the hour before and after, whether you hid the chat or left it, and — from your location history — whether you were at the suggested place or event afterwards, and whether people from the chat were there together. Only these results are stored (for example “replied: yes”, “was there: likely”), as app activity events under your account for up to 90 days; message text and locations are never copied into them.
- Activity and usage data — in-app activity used to operate and improve the app, its features and its recommendations: which screens you open, which cards and places you view, tap or save, how long each card stays on your screen and whether you scroll past it, and aggregate behaviour counters. These records are linked to your account and carry coarse context only (such as city, hour, day, and platform), never your exact location or message text.
- Before you sign in — so we can see where people get stuck before an account exists, the app records a few steps before you sign in: that the app was opened, that the welcome screen was shown, which sign-in button you tapped, how far you got in sign-up, and any error you were shown. These are recorded against a random ID the app creates on your device — not your device’s own identifier — and carry no name, email or location. If you go on to create an account, that ID is linked to it, so the records are deleted with your account.
- Searches — the words you type into any search bar in the app, exactly as typed, including searches for places and for other people by name or username, together with the results you were shown, which result you tapped and what you did with it. We keep them, linked to your account, to understand what people look for and to improve search and recommendations. The people you recently opened from Search people are also listed on your phone only, so you can find them again; you can clear that list at any time.
- Other people you interact with — when you look at someone's profile, tap on them in search results or on the Discover feed, or tap to message them, we record which account it was (its account ID) alongside your own activity. We use this to understand how people find and connect with each other and to improve suggestions.
- Cards you share outside the app — when you send a card (a place, event, stay or spot) to WhatsApp, Messages, or another app, we create a link for it and keep: the card itself, that you made the link, which option you used (WhatsApp, Messages, Copy link or More), which app you picked from your phone’s share menu, and how many times the link was opened, previewed or opened in the app. Your location is never part of the link: it carries the place’s address, not where you were. The link works for up to 12 months. When your account is deleted, the record that you made the link is removed; the link itself keeps working because it may already be in someone’s chat.
- People who open a shared card — if you open a card someone shared with you, and you have 2016Chat, the app opens it and adds it to your Saved list as “Sent to you”. If you don’t have the app, the card opens as a web page (share.2016chat.com). That page records, without cookies and without storing any identifier on your device: that it was opened, your device type (iPhone, Android or computer), which app’s browser it opened in (for example Instagram or WhatsApp), your approximate country and city as worked out from your connection (your IP address itself is not stored), which buttons you tapped, whether you allowed location, and how long the page was open. If you tap “Get there”, your browser may ask for your location to show how far away the place is; that calculation happens on your device and your location is never sent to us. When a link is pasted into an app such as WhatsApp or iMessage, that app fetches it to draw a preview, and we record which app it was.
- Referral / invite information — if you join after a friend shares an invite link, we record which existing user invited you (their username and your new account) so we can understand how 2016Chat grows by word of mouth. This is stored privately, is not shown on your profile or to other users, and does not involve accessing your contacts or address book.
- Your phone number (optional) — if you choose to let friends who have your number find you, you confirm your number with a code sent by text through Firebase Authentication (Google). We then keep only a one-way code made from your number with a secret key, plus its last four digits — not the number itself — and remove the number from your sign-in details straight away, so a phone number is never used to sign up or sign in. It is not shown on your profile. You can turn it off or remove it at any time, and it is deleted with your account.
- Chat codes and chat requests — every account has a chat code, shown as a code, a QR code and a link (2016chat.com/m/…), that lets someone start a chat with you — even if your profile is private. We store your current code, when it was made and when it changes, and your choices for it (how often it changes, whether people can use it, and “Ask me first”). A code is deleted when it is replaced or runs out, or when your account is deleted. With “Ask me first” on (the default, and always on if you are under 18), a chat that anyone new starts with you — with your code, from Discover or from search — waits as a request: we record when you first saw it and whether you started the chat or removed it. The person asking cannot see whether you have read their message until you start the chat, and is not told if you remove it. Codes themselves are never recorded in analytics or with your searches; we record only that a code was shown, shared, scanned or used. If you scan a code in the app, your camera is used on your device only while the scan screen is open — no image is stored or sent to us. The web page behind a code link records its visits like the rest of this website, without the code.
- Notification token — if you enable notifications, a device messaging token so we can deliver chat notifications. It is stored privately and cleared on a best-effort basis when you sign out or request deletion. A chat notification shows the sender's name and a preview of the message, and on some devices the sender's profile photo, in the same way as most messaging apps — so message content can appear on your lock screen, depending on your device settings. You can change what notifications reveal, or turn them off entirely, in your device settings at any time.
- Device, diagnostic, and security data — technical information needed to keep the service reliable and secure, including app integrity (App Check) signals and rate-limiting records used to prevent abuse. If the app crashes, a crash report (the error details, your device model, and operating-system version) is sent to us through Firebase Crashlytics so we can find and fix problems. These reports are used only to keep the app stable, are not used to track you, and are not linked to your identity.
We do not ask for or intentionally collect special-category data (such as health, religious, or political information). Please do not put such information in your profile or messages if you do not want it processed.
Why we use your information, and our legal basis
Under UK/EU GDPR we must have a "lawful basis" for each use. Ours are:
- To provide the service you ask for — creating your account, showing nearby people and places, and delivering your chats. Legal basis: performance of a contract with you.
- Location and notifications — using your device location for nearby features and sending push notifications. Legal basis: your consent, given through your device's permission settings, which you can withdraw at any time in your device settings.
- Safety, moderation, and security — handling reports, blocking, automated and manual moderation, preventing spam, fraud, and abuse, and protecting the service and its users. Legal basis: our legitimate interests in keeping the service safe (and, where relevant, our legal obligations).
- Improving the service and personalising recommendations — using activity data and derived interests to make suggestions more relevant and to improve features. Legal basis: our legitimate interests in operating and improving the product. You can limit this by limiting your in-app activity, and you can object (see Your rights).
- Understanding how 2016Chat grows — recording which existing user invited a new user, to measure word-of-mouth growth. Legal basis: our legitimate interests in understanding and growing the service. We do not access your contacts or address book for this.
- Support and legal compliance — responding to your requests and complying with applicable law, lawful requests, and dispute handling. Legal basis: legitimate interests and legal obligation.
Automated decisions about your account
To protect users at scale, an account may be automatically suspended if a high number of different users report it within a set period. This is designed to be hard to trigger and is always reversible. If your account is suspended and you believe it was a mistake, you can ask us to review it by emailing support@2016chat.com, and a person will review your appeal. We do not use automated decision-making with legal or similarly significant effects without offering this human review.
International data transfers
2016Chat's database is hosted in the European Union, and the backend functions that serve the app run in the European Union too. Some processing still happens in the United States — for example providers such as Google, Apple, Ticketmaster, SeatGeek, NewsData.io and Resend, and a small number of background functions that must run alongside the storage they read. Where personal information is transferred outside the UK/EEA, it is protected by appropriate safeguards such as the providers' Standard Contractual Clauses and the UK International Data Transfer Addendum, together with their own technical and organisational measures.
How long we keep information (retention)
- Raw location history — kept for up to 12 months, then deleted automatically. We keep it this long so the app can learn the places and times that suit you and make its recommendations genuinely personal; a few days is not long enough to learn anything useful. Deletion is enforced by the database itself rather than by a scheduled clean-up, so it happens on time regardless of how busy the service is.
- Account and profile data — kept for the life of your account. When you request deletion, your account enters a 30-day grace period (so you can change your mind by signing back in), after which private personal data is deleted or anonymised. See the Account Deletion page.
- Messages — chat history may remain visible to the other members of a chat. When your account is deleted, your identity in shared chats is anonymised.
- Operational data — short-lived caches and rate-limit records expire automatically.
- Shared-card links — kept for up to 12 months, then deleted automatically. What happens on a shared card’s web page is kept like the rest of our usage analytics (below).
- Usage analytics and searches — the records of how you use the app and what you search for (never message text, never your precise coordinates) are deleted from our live database automatically after 90 days. A copy is kept in our private analytics store (Google BigQuery, in the EU) so we can understand how the app is used over time; it stays linked to your account.
- Safety, security, and legal records — kept only for as long as needed for safety, fraud prevention, dispute handling, and legal compliance.
Where we no longer need information to identify you, we may keep it in anonymous or aggregated form.
Your rights (UK and EEA)
If you are in the UK or EEA, you have the right to: access your information; have inaccurate information corrected; have your information deleted; restrict or object to certain processing; data portability; and withdraw consent (for example, by turning off location or notifications in your device settings) at any time without affecting earlier processing.
To exercise any of these, email privacy@2016chat.com. You can also delete your account from within the app (Profile → Delete account).
If you are unhappy with how we handle your information, you have the right to complain to your data protection regulator. In the UK this is the Information Commissioner's Office (ICO) at ico.org.uk. In the EEA, you may complain to your local supervisory authority.
Your rights (California)
If you are a California resident, you have the right to know what personal information we collect and how we use it, to request access and deletion, to correct inaccurate information, and to not be discriminated against for exercising your rights. We do not sell your personal information and do not share it for cross-context behavioural advertising. To make a request, email privacy@2016chat.com.
Security
We use technical and organisational measures to protect your information, including app-integrity verification (App Check), encryption of data in transit, strict access rules that keep sensitive data (such as exact location, email, and notification tokens) private to you, and rate limiting to resist abuse. No system can be guaranteed perfectly secure, but we work to protect your information and to respond appropriately to any incident.
Cookies and the website
This website (2016chat.com) uses no cookies and no third-party scripts, and stores nothing on your device.
Website visits. When you open a page on this website, or use one of its links (such as “Download the app”, the App Store and Google Play buttons, 2016chat.com/get or an invite link), our server records the visit so we can see how people find 2016Chat and make it better. It is worked out from the request your browser already sends, and records: the page or link, and where a link sent you; the website you came from and any campaign tag in the link (for example “?src=reddit”); your approximate location (country, region and city) and time zone, estimated from your IP address; your type of device, operating system and browser, including whether it is an app’s built-in browser; and your browser’s language. To tell visits apart without cookies, your IP address and browser details are combined with a secret and the date into a one-way code that changes every day and cannot be turned back into your IP address. Your IP address itself is not stored. Visit records are kept for 90 days and then deleted automatically. We do this on the basis of our legitimate interest in understanding and improving the website and the app; you can object by contacting us. The website is hosted by Cloudflare, which handles these requests for us.
Pages for cards shared from the app (share.2016chat.com) record visits and taps as described under “People who open a shared card” above — without cookies and without storing anything on your device. The 2016Chat app stores some data on your device (such as sign-in state and cached content) so the app can function.
Changes to this policy
We may update this policy from time to time. We will change the "Last updated" date above, and where changes are material we will take reasonable steps to make them known.
Contact us
- Privacy: privacy@2016chat.com
- Support: support@2016chat.com
- Legal: legal@2016chat.com