We hold zero data. Not even WE can read your messages. That's not a promise โ it's mathematics.
Last updated: March 22, 2026 ยท Grid BV ยท Dutch registered company ยท KvK 12345678
GridChat uses a Privacy Tier model โ we collect the absolute minimum data necessary to operate the service. We hold only what is strictly required.
| Data | Stored | Why |
|---|---|---|
| Username | Yes | Account identification |
| Password (hashed) | Yes | Authentication (PBKDF2, 50k iterations) |
| PRO/subscription status | Yes | Feature access control |
| Chat messages | No* | End-to-end encrypted, server never sees plaintext |
| Contacts | No* | Stored locally on your device only |
| Location data | No* | Encrypted and routed, not stored |
| Email address | No | Not collected โ ever |
| Phone number | No | Not collected โ ever |
| Real name | No | Not collected โ ever |
| IP address (logged) | Briefly | Abuse prevention, not stored long-term |
* Under Privacy Tier, these are technically stored but encrypted with your private key โ only accessible to you and your intended recipient.
The following data is never collected, stored, or processed by Grid BV:
Not even Grid BV can read your messages, see your contacts, or track your location. This is architecturally enforced by the GP Encryption Engine โ it is mathematically impossible for us to access your private data.
GridChat uses the GP Encryption Engine for all private communications:
Encryption and decryption happen exclusively on your device. Our servers route encrypted ciphertext without ever being able to decrypt it. The GP Engine is open in concept โ the implementation is proprietary.
We retain data only as long as necessary:
Upon account deletion (GDPR Article 17), all data is permanently and irreversibly erased.
As an EU data subject, you have the following rights under GDPR:
Grid BV ยท Amsterdam, Netherlands ยท KvK 12345678 ยท privacy@gridchat.app
For account deletion, use the in-app "Delete Account" function (Profile โ Delete Account). This executes GDPR Article 17 erasure automatically.
We implement industry-standard and proprietary security measures:
GridChat uses minimal cookies:
You can disable cookies in your browser, but this will log you out of GridChat on next visit.
We use the following third-party services:
We do not sell, share, or transfer your data to any third parties beyond the above service providers, each of which is GDPR-compliant.
GridChat is not intended for use by children under 16. We do not knowingly collect personal data from children under 16. If you believe a child's data has been collected, contact us immediately at privacy@gridchat.app.
In the event of a data breach that poses a risk to your rights, we will:
Given our Privacy Tier architecture โ where we store only encrypted ciphertext and usernames โ a breach of our servers would not expose message content or contacts.
GridChat is hosted exclusively within the European Union. No data is transferred outside the EU. Our use of Firebase and Stripe involves EU-based data centers only.
If we ever need to transfer data outside the EU, we will ensure appropriate safeguards (Standard Contractual Clauses, adequacy decisions) are in place in accordance with GDPR Chapter V.
We may update this Privacy Policy from time to time. Material changes will be communicated:
Continued use of GridChat after changes constitutes acceptance. If you do not agree with changes, you may delete your account.
Contact: Grid BV ยท Amsterdam ยท privacy@gridchat.app