SamaChatSamaChat

Privacy Policy

Last updated: 23 July 2026

SamaChat ("SamaChat", "we", "us", "our") operates the end-to-end encrypted messaging membership service at www.samachat.co.uk. This Privacy Policy explains what personal data we process, why, how long we keep it, who we share it with, and the rights you have under the UK GDPR, the EU GDPR and the Data Protection Act 2018. SamaChat is a members-only, paid service for users aged 18 and over. Registration requires proof of age (self-declaration) and an active subscription.

1. Data controller

SamaChat is the data controller for personal data processed through the service. Contact our privacy team at hello@samachat.co.uk — this address reaches both our support and Data Protection responsibilities.

2. Data we process

Account & identity

  • Email address (verified) — used for sign-in, account recovery, billing receipts and mandatory service notices.
  • Password — never stored in plaintext; salted-and-hashed by our authentication provider.
  • Display name & optional avatar — visible to your contacts and to anyone you share your SAMA ID with.
  • SAMA ID — an 11-digit identifier (077 + 8 digits) auto-generated on first sign-in.
  • 18+ age confirmation — recorded at sign-up to satisfy our UK regulatory obligations.

Cryptography

  • Curve25519 public keys — published so others can encrypt to you.
  • Private keys — deterministically derived on your device from your password (PBKDF2-SHA256, 210,000 iterations, per-user salt) and cached only in your browser's local storage. They are never transmitted to our servers.

Message data

  • Ciphertext + nonce — the encrypted payload of every message. We cannot decrypt it.
  • Delivery metadata — conversation ID, sender ID, recipient(s), and server timestamps needed to route and order messages.

Calls

  • Signalling metadata (start/end time, participants, media type).
  • Media streams are peer-to-peer via an SFU (Cloudflare Calls) with DTLS-SRTP encryption. Content is not recorded and is not stored on our servers.

Billing

  • Stripe Customer ID, subscription ID, plan, status, period dates, and cancellation feedback (if you provide it). Payment card details are handled directly by Stripe — we never see or store your card number.

Safety & abuse

  • User reports you submit (reason, optional details, timestamps) and moderation status.
  • Blocks you create.

Diagnostics

  • Transient IP address at the network edge, browser/device type, and minimal error logs — retained no longer than 30 days and used strictly for security, reliability and fraud prevention.

3. Data we do NOT process

  • Message content in a readable form — we cannot decrypt your chats.
  • Phone numbers, SMS history, or your device's address book.
  • Advertising identifiers, third-party trackers, cross-site cookies or behavioural profiles.
  • Call recordings.
  • Location data.

4. Lawful bases (UK & EU GDPR Article 6)

  • Contract (6(1)(b)) — to provide the messaging, calling and membership services you subscribe to.
  • Legal obligation (6(1)(c)) — 18+ verification, safeguarding responses under the UK Online Safety Act 2023, tax/accounting.
  • Legitimate interests (6(1)(f)) — service security, abuse prevention, fraud detection. We balance these interests against your rights and freedoms.
  • Consent (6(1)(a)) — where separately requested (e.g. optional notifications).

5. Retention

  • Account: retained until you delete it or we terminate for breach.
  • Encrypted messages: retained until delivered and until you or your recipient deletes them. Deletion is immediate and irreversible on our side.
  • Call history metadata: 90 days.
  • Billing records: 7 years (UK tax law).
  • Safety reports: up to 2 years after resolution to detect repeat offenders.
  • Diagnostics: rotated within 30 days.

6. Sub-processors

We use a small number of vetted infrastructure providers, all bound by data-processing agreements with UK-approved Standard Contractual Clauses where transfers occur:

  • Supabase — managed Postgres, authentication, realtime (EU/UK region).
  • Cloudflare — CDN, TURN/SFU media relay, edge functions.
  • Stripe — payments & subscription billing.
  • Resend / transactional email provider — verification and billing emails.

7. International transfers

Primary data storage is in the UK/EU. Where a sub-processor operates outside the UK/EEA, we rely on UK IDTA or EU SCCs and, where applicable, Adequacy Regulations.

8. Your rights

  • Access, rectification, erasure, restriction, portability and objection.
  • Right to withdraw consent where processing relies on consent.
  • Right not to be subject to solely automated decision-making with legal or similarly significant effects — we do not conduct such processing.

Email hello@samachat.co.uk to exercise any right. We respond within 30 days. You may complain to the UK Information Commissioner's Office (ICO) at any time.

9. Security

SamaChat uses NaCl / Curve25519 end-to-end encryption for all messages. Private keys are derived on your device and never leave it. See the Security page for the full architecture.

10. Children

SamaChat is strictly for users aged 18 and over. Accounts believed to belong to minors are terminated and data erased.

11. Changes

Material changes will be notified in-app and by email at least 14 days before taking effect.

12. Contact

Email hello@samachat.co.uk.