ChatatiChatati
  • How it works
  • Meet Safely

Privacy Policy

Last updated: February 2026

This translation is provided for convenience. In case of conflict, the English version prevails.

1. Introduction

Chatati ("we", "us", "our") operates the website chatati.de. This privacy policy explains how we collect, use, and protect your personal data when you use our service. We are committed to protecting your privacy in accordance with the EU General Data Protection Regulation (GDPR) and applicable German data protection laws.

2. Data Controller

The data controller responsible for this website is:

Michiel Van de Vyver

c/o IP-Management #8874, Ludwig-Erhard-Str. 18, 20459 Hamburg, Germany

Email: privacy@chatati.de

3. What Data We Collect

We collect the following personal data when you register and use Chatati:

  • Account data: First name, last name, email address, and password (stored in hashed form only).
  • Profile data: Gender, date of birth, bio, languages you speak, languages you want to learn, interests, availability, preferred districts, and your district in Hamburg.
  • Profile picture: An optional profile picture you upload.
  • Technical data: IP address and user agent (browser information), collected automatically when you log in and stored with your session.
  • Usage data: Contact requests you send or receive (including messages), your connection inbox messages, your saved Chatatis, user reports, and blocked users. Invitation and inbox message text is stored encrypted at rest.

4. How and Why We Use Your Data

We use your data for the following purposes:

  • To create and manage your account (legal basis: contract performance, Art. 6(1)(b) GDPR).
  • To display your profile to other users and enable language exchange connections (legal basis: contract performance, Art. 6(1)(b) GDPR).
  • To create and run a private connection inbox when both users accept an invitation, so they can coordinate their meetup safely. Invitation and inbox message text is decrypted only when needed for permitted app features, such as participant display and report review emails (legal basis: contract performance, Art. 6(1)(b) GDPR).
  • To send you verification emails, password reset emails, and invitation notifications (legal basis: contract performance, Art. 6(1)(b) GDPR).
  • To protect the platform from abuse through rate limiting and user reports (legal basis: legitimate interest, Art. 6(1)(f) GDPR).
  • To detect and fix technical errors (legal basis: legitimate interest, Art. 6(1)(f) GDPR).

5. Data Sharing Between Users

Chatati is a language exchange platform. By creating a profile, you understand that:

  • Your profile information (name, languages, interests, availability, district, bio, profile picture, age range) is visible to other registered users when they search for Chatatis.
  • Your email address is not shared with other users through the connection flow. After mutual acceptance, both users get a private connection inbox on Chatati instead.
  • Your profile is not publicly accessible to unregistered visitors or search engines.

6. Third-Party Services

We use the following third-party service providers to operate Chatati:

  • Resend (email delivery): We use Resend to send transactional emails (verification, password reset, notifications). Your email address is shared with Resend for this purpose. Resend processes data in accordance with their privacy policy.
  • Cloudflare R2 (image storage): Profile pictures are stored on Cloudflare R2. Cloudflare is a US-based company that complies with EU data protection standards.
  • Sentry (error tracking): We use Sentry to monitor and fix technical errors. Sentry does not collect personally identifiable information from our app (PII collection is disabled).
  • Upstash Redis (rate limiting): We use Upstash Redis to enforce rate limits and prevent abuse. Only anonymized request metadata is processed.
  • Umami (web analytics): We use Umami for privacy-friendly web analytics. Umami does not use cookies, does not collect personal data, and does not track users across websites. Only aggregate, anonymous data is collected (page views, referral sources, countries, devices).
  • Hosting and database: Our application and database are hosted on infrastructure within the EU. Your data may be processed by our hosting provider as part of providing the service.

7. Cookies and Analytics

Chatati uses only strictly necessary cookies. We do not use any advertising or tracking cookies.

  • Session cookie: Used to authenticate your session. Expires after 7 days of inactivity.
  • Locale cookie: Used to remember your language preference (English, German, French, Spanish, or Dutch).

Web Analytics

We use Umami, a privacy-friendly analytics tool, to understand how our website is used (e.g., page views, referral sources, countries). Umami does not use cookies, does not collect personal data, and does not track you across websites. No consent is required for this type of analytics under GDPR.

8. Data Retention

We retain your personal data for as long as your account is active. When you delete your account, all your personal data is permanently removed, including your profile, contact requests, connection inbox data, saved Chatatis, reports, and sessions. In enforcement cases (for example severe terms violations), we may retain a one-way cryptographic hash of the deleted account email to prevent re-registration with the same address (legal basis: legitimate interest, Art. 6(1)(f) GDPR). Deactivating your account hides your profile but retains your data so you can reactivate later.

9. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access: You can request a copy of all personal data we hold about you.
  • Right to rectification: You can update your profile information at any time through your account settings.
  • Right to erasure: You can permanently delete your account and all associated data through the account settings page.
  • Right to restriction: You can deactivate your account to restrict processing of your profile data.
  • Right to data portability: You can request your data in a machine-readable format.
  • Right to object: You can object to processing based on legitimate interests by contacting us.
  • Right to lodge a complaint: You have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence.

10. Children

Chatati is not intended for use by children under the age of 16. We do not knowingly collect personal data from children under 16.

11. Changes to This Policy

We may update this privacy policy from time to time. If we make significant changes, we will notify you by updating the date at the top of this page. We encourage you to review this policy periodically.

12. Contact

If you have any questions about this privacy policy or wish to exercise your data protection rights, please contact us at:

privacy@chatati.de

© 2026 ChatatiCreated by MitchCreates

Platform

Sign upSign in

Info

How it worksMeet Safely

Legal

Privacy PolicyImpressumTerms of Service