← Back to home Terms of Service for the United Kingdom
United Kingdom • Privacy Notice

StrawberryChat Privacy Notice for users in the United Kingdom

This Privacy Notice explains how StrawberryChat collects, uses, stores and protects personal information for the English-language interface intended for users in the United Kingdom. It is structured with the UK GDPR and Data Protection Act 2018 transparency requirements in mind.

Contact for privacy requests

Email: support@strawberrychat.com

Effective date

7 August 2026

1. Personal data we collect

  • account details such as username, email address, password hash, date of birth for the 18+ age check, gender, login records and a Google or GitHub sign-in identifier where you choose that method;
  • profile data such as names, photos, biography, interests, preferences, approximate or precise location depending on the feature you choose, and visibility settings;
  • communications data such as text messages, voice messages, video messages, attachments, reactions, moderation actions and service metadata;
  • technical data such as IP address, cookies, device/browser information, session identifiers, local preferences, diagnostic logs and a device token used for push notifications;
  • subscription and payment-related metadata, including package status and provider transaction references.

2. Why we use personal data

  • to create and manage user accounts;
  • to provide chat, private messaging, calls, watch together, profile and moderation functionality;
  • to process subscriptions, billing workflows and service administration;
  • to keep the service secure, investigate abuse, enforce rules and prevent fraud or spam;
  • to respond to user requests, complaints and legal obligations.

3. Lawful bases

Depending on the activity, we rely on one or more of the following lawful bases under the UK GDPR: performance of a contract, compliance with a legal obligation, consent where required, and legitimate interests in running, securing and improving the service and protecting users from abuse.

4. Who we share information with

  • hosting, infrastructure, email and storage providers acting on our behalf;
  • Google Firebase Cloud Messaging for the device token and technical data needed to deliver push notifications; Google and GitHub for OAuth data only when you choose that sign-in method;
  • Stripe for payment references from website purchases; the Android app distributed through Google Play does not offer Stripe checkout for digital goods;
  • Google reCAPTCHA for form-abuse prevention; DeepL for text you explicitly ask to translate; YouTube, Google Drive and other embedded services only when you open or connect the corresponding feature;
  • service providers needed to deliver media handling, account recovery or payment processing;
  • public authorities or law enforcement where legally required;
  • other users only to the extent necessary for the features you choose to use and your privacy settings.

5. International transfers

Some providers or infrastructure may be located outside the UK. Where personal data is transferred internationally, we aim to use appropriate safeguards and limit transfers to what is reasonably necessary for providing the service.

6. Retention

  • account data is kept while the account is active; after confirmed deletion the active profile and associated service data are deleted;
  • messages and uploaded content are retained while they remain part of the service record, unless deleted earlier by the user or through moderation;
  • local payment records are removed with the account; a payment provider may independently retain a legally required transaction record for its mandatory period;
  • technical logs are removed with the account; a de-identified deleted-message marker containing no participant, content or content hash is kept for no more than 30 days so a backup cannot restore deleted content;
  • specific reported evidence or legal records are retained only while a review, lawful preservation restriction or mandatory period applies, then deleted or de-identified.

7. Security

We use reasonable technical and organisational measures designed to protect personal data, including access controls, authentication, password hashing, session protection, logging of critical actions, restricted administrator access, backups, moderation and anti-abuse tooling, and provider-side security safeguards. No internet-based service can guarantee absolute security, but we work to reduce risk to a reasonable level.

Private and group conversation content is transmitted as end-to-end encrypted text or files: the server normally stores ciphertext and delivery metadata, while decryption keys remain on participants’ trusted devices. Participant names, timestamps, delivery identifiers and similar metadata are not necessarily end-to-end encrypted. When a user deliberately submits a report, their device may disclose the selected content as moderation evidence; that evidence is handled separately for safety and legal purposes. Public rooms should not be treated as a private E2E channel.

8. Your rights

Subject to the UK GDPR, you may have the right to access, rectify, erase, restrict, object to processing, request portability, and withdraw consent where consent is the lawful basis. You also have the right to complain to the Information Commissioner’s Office (ICO).

You can permanently delete your account and associated service data from your profile or by following our public account deletion instructions. Records that we are legally required to retain, such as specified financial records, are isolated and kept only for the mandatory period.

9. Cookies and browser storage

The site uses cookies, session data and local browser storage for authentication, language preferences, interface settings, fraud prevention and core functionality. If you disable these tools, some parts of the service may not work properly.

10. Android permissions

Camera and microphone access is used only after you act to take media or make a call; location is used only when you choose a location feature; notification access is requested after a separate explanation and your consent. You can refuse or revoke these permissions in Android settings. They are not requested without context on first launch.

11. Age restriction and safety

The service is only for adults aged 18 or older. Our prohibitions, reporting process and safety contact are set out in the public Child Safety Standards.

12. Contact us

For privacy requests or questions, contact us at support@strawberrychat.com.

13. Complaints

If you are not satisfied with how we handle your personal data, you may complain to the Information Commissioner’s Office (ICO). Current guidance and complaint routes are available at: https://ico.org.uk/make-a-complaint/data-protection-complaints/